| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | ETH value transfer possible | no | no |
| medium | codex | Uninitialized clones allow anyone to pass onlyOwner/ownerOrRoller checks | no | — |
| medium | codex | adjust() trusts caller-supplied collateral amount, enabling undercollateralized minting with fee-on-transfer tokens | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| low | codex | ERC20 transfer/transferFrom return values are unchecked | no | — |
| low | cast | Contract creation opcode present | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| aa5e9646-f351-4842-97ee-a8456d74c3fd | failed | crit 0 high 0 | 7 | 3 months ago |
| d1e28cbb-a34f-4498-94e3-2391c9e61ac5 | failed | crit 0 high 0 | 10 | 3 months ago |
| 6a86e7ae-30fc-4bd1-b436-7b9d4baa7340 | failed | crit 0 high 0 | 9 | 3 months ago |