| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| medium | codex | Reentrancy window in `deposit` can double-count pending rewards | no | — |
| medium | codex | Fee-on-transfer tokens break pool accounting and allow over-withdrawals | no | — |
| low | codex | ETH withdrawals use `transfer`, risking permanent withdrawal failures for contracts | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019be3d6-82ae-711f-8841-629b0c72d040 | failed | crit 0 high 0 | 6 | 2 months ago |
| 019b477e-bae5-7329-bd61-49f42c9ed79b | complete | crit 0 high 0 | 3 | 3 months ago |
| 019b3844-974e-7352-a502-186342ea3947 | complete | crit 0 high 0 | 3 | 3 months ago |