| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | detector | Untrusted DELEGATECALL target reachable | no | no |
| medium | cast | DELEGATECALL present | no | — |
| medium | codex | `withdraw_admin_fees` can be reentered via token callback before state is updated | no | — |
| low | codex | Admin fee withdrawal ignores ERC20 return values and can zero fees on failed transfer | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019bb004-7b45-70c7-adb3-d1c5cb2846d2 | failed | crit 0 high 0 | 5 | 3 months ago |