| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted DELEGATECALL target reachable | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | ETH value transfer possible | no | no |
| medium | cast | DELEGATECALL present | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| low | codex | Unchecked ERC20 transfer/transferFrom return values may mask failed asset movements | no | — |
| low | codex | EtherFi withdrawal accounting can be double-decremented if claims are repeatable | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019c0eab-8298-737d-bd4e-4f8fa55370b4 | failed | crit 0 high 1 | 9 | 2 months ago |