| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted DELEGATECALL target reachable | no | no |
| high | slither | KotoV3.bondLp(uint256) (src/KotoV3.sol#161-201) ignores return value by IERC20Minimal(pair).transferFrom(msg.sender,address(BOND_DEPOSITORY),_lpAmount) (src/KotoV3.sol#164) | no | — |
| medium | slither | Reentrancy in KotoV3.bondLp(uint256) (src/KotoV3.sol#161-201): | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | codex | Bond market parameters derived from manipulable Uniswap spot reserves | no | — |
| medium | cast | DELEGATECALL present | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | LP bonding does not verify LP token transfer success | no | — |
| low | cast | Contract creation opcode present | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019be3d6-8267-739c-b062-5f21bd63b2eb | complete | crit 0 high 0 | 10 | 2 months ago |
| 019b477e-d41d-71fa-af20-45865c075802 | complete | crit 0 high 0 | 4 | 3 months ago |
| 019b3844-ab21-71ea-9fbe-e052746044f5 | complete | crit 0 high 0 | 4 | 3 months ago |