| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted DELEGATECALL target reachable | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| medium | codex | Division-by-zero in `_withdrawToVault` when adapter net assets are zero | no | — |
| medium | codex | Chainlink price feeds used without freshness/positivity checks | no | — |
| medium | codex | Flashloan callback not restricted to Balancer vault | no | — |
| medium | cast | DELEGATECALL present | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | Delegatecall to adapter/swapper trusts upgradeable targets with full storage access | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019ba92a-2eeb-70f8-844a-5c395e4e1794 | complete | crit 0 high 1 | 9 | 3 months ago |