| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| high | codex | Public supply functions let anyone move assets off the tracked provider, blocking withdrawals | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| medium | codex | Deposit can mint zero shares when pool>0 and totalSupply==0, permanently bricking new deposits | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 25b64c9e-a9a5-474a-8faf-8e739aace6ae | complete | crit 0 high 0 | 7 | 3 months ago |