| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | codex | Unprotected initialize allows proxy takeover and unlimited minting | no | — |
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | ETH value transfer possible | no | no |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | codex | initializeV2_1 lets anyone sweep the contract’s own token balance | no | — |
| low | cast | Contract creation opcode present | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019b477e-cf91-730e-8856-396d862ef873 | complete | crit 0 high 0 | 3 | 3 months ago |
| 019b3844-a693-73e1-8431-b022aaa4f320 | complete | crit 0 high 0 | 3 | 3 months ago |