complete
bytecode
findings
The bundle includes embedded CREATE init/runtime blobs; selector inference is best-effort. One high-confidence issue affects the live top-level bytecode directly, and two additional issues affect a deployable child runti...
Top findings
-
high
Top-level accounting decrements user balances but creates child contracts with zero ETH
-
high
Deployable child runtime pays arbitrary recipients via CALL with no reentrancy guard
-
medium
Child payout loop ignores CALL failure, so recipients can be skipped and funds redistributed incorrectly