| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Fee collection can render refunds insolvent during the refund window | no | — |
| low | codex | Implementation contract is not locked against direct initialization | no | — |
| low | codex | Refund receiver can drain refund tokens at any time | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 72fea1d0-3553-473a-9b2b-ea4b0146f4e1 | failed | crit 0 high 0 | 2 | 3 months ago |
| 73252535-2ea1-4a23-a722-3f8641951082 | failed | crit 0 high 0 | 5 | 3 months ago |