| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | codex | Cached yToken balances let new LPs capture unaccounted yield | no | — |
| medium | codex | Fee-on-transfer tokens break accounting and allow excess LP minting | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | initialize is reusable and mints LP tokens at a fixed 1:1 rate | no | — |
| low | cast | Contract creation opcode present | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 2f88829e-53ca-47fb-b751-06a2be25bd11 | failed | crit 0 high 0 | 7 | 3 months ago |
| 15ac169e-dc7f-43ef-b03e-7068b7fd1271 | failed | crit 0 high 0 | 10 | 3 months ago |