| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | yes | yes |
| high | detector | ETH value transfer possible | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | codex | Public selector `0x1d2bca17` can assign arbitrary balance to the caller | no | — |
| medium | codex | Same unguarded runtime path appears able to rewrite token metadata (`name`/`symbol`/`decimals`) | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019b3836-3c1c-73f1-8d3d-ffdb519bf95c | complete | crit 0 high 2 | 4 | 3 months ago |