| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Whitelisted game can unilaterally drain any holder’s tokens/ETH via payWithToken | no | — |
| high | slither | HDX20.payWithToken(uint256,address) (contracts/Contract.sol#395-431) sends eth to arbitrary user | no | — |
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Owner can set migration target to arbitrary address, redirecting moveAccountOut funds | no | — |
| low | codex | Unbounded superReferrerRate can revert buys or wrap fee calculation | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019c0ea9-0729-710d-aaed-64fc4dafe23a | complete | crit 0 high 0 | 6 | 2 months ago |
| 019b477e-b269-72d6-94a1-ceefc33f2e36 | complete | crit 0 high 0 | 2 | 3 months ago |
| 019b3844-9079-70bf-b1a1-86c87233d8bb | complete | crit 0 high 0 | 2 | 3 months ago |