| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | yes | yes |
| high | detector | ETH value transfer possible | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Owner-only mint can arbitrarily inflate supply | no | — |
| high | codex | Owner can freeze arbitrary senders via a hidden boolean mapping | no | — |
| medium | codex | allowance() does not track remaining spend; transferFrom uses a separate spent-amount mapping | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019b3836-2d81-72b3-ba7f-1259b9b4588e | complete | crit 0 high 2 | 5 | 3 months ago |