| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | detector | Untrusted DELEGATECALL target reachable | no | no |
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | KYC signature replay allows bypassing intended per-user limits | no | — |
| medium | cast | DELEGATECALL present | no | — |
| low | codex | KYC signature check can be bypassed if signerAddress is unset | no | — |
| low | codex | Refunded flag never set due to equality operator | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019be3d6-8355-7101-a9ce-9df439e1eb56 | failed | crit 0 high 0 | 9 | 2 months ago |
| 019b477e-ad7b-733a-8724-0953eb5eecbd | complete | crit 0 high 0 | 3 | 3 months ago |
| 019b3844-8d03-7230-b97c-163904e39908 | complete | crit 0 high 0 | 3 | 3 months ago |