| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | cast | SELFDESTRUCT present | no | — |
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | SELFDESTRUCT reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| medium | codex | Pool initialization is permissionless and can be front-run | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| low | cast | Contract creation opcode present | no | — |
| low | codex | Permit domain separator is cached without chainId check, enabling fork replay | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 6f9be8c5-fdad-4ad0-9fe9-0312de932bb1 | failed | crit 0 high 0 | 8 | 3 months ago |
| 9a608d87-4d7f-4721-8bdf-dd60e7f10e20 | failed | crit 0 high 0 | 10 | 3 months ago |