| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Predictable/manipulable randomness for winner and jackpot selection | no | — |
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| high | slither | Reentrancy in RobTheBank._bigLottery(address) (contracts/Contract.sol#257-298): | no | — |
| high | slither | Reentrancy in RobTheBank._buy(uint256,uint256) (contracts/Contract.sol#193-232): | no | — |
| high | slither | RobTheBank._bigLottery(address) (contracts/Contract.sol#257-298) sends eth to arbitrary user | no | — |
| medium | codex | Service can call lottery before round end and without winKey set | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019c0ea9-09bb-708b-a5eb-c7330d8c9ab3 | complete | crit 0 high 0 | 8 | 2 months ago |
| 019b477e-b1b1-73f5-9a7f-d91c49dea272 | complete | crit 0 high 0 | 2 | 3 months ago |
| 019b3844-9006-726f-8970-8ab7c867827f | complete | crit 0 high 0 | 2 | 3 months ago |