| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| medium | detector | Untrusted CALL target/value reachable | yes | yes |
| medium | detector | ETH value transfer possible | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| high | codex | Privileged path authenticates with tx.origin | no | — |
| medium | codex | Core identity and payout logic are bound to tx.origin rather than the actual caller | no | — |
| medium | codex | Low-level external calls ignore success and are followed by accounting writes | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019b3836-3d20-71d0-bbc3-03d9ecb53393 | complete | crit 0 high 0 | 6 | 3 months ago |