| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | codex | Multicall delegatecalls let callers spoof immutable args (token addresses/scales), enabling asset drainage | no | — |
| critical | detector | Untrusted DELEGATECALL target reachable | no | no |
| medium | cast | DELEGATECALL present | no | — |
| low | codex | `initialize` is permissionless and can be front‑run | no | — |
| info | cast | Likely proxy-like runtime | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 0b182317-6fc8-49be-9b05-708e9dfa9460 | complete | crit 0 high 0 | 5 | 3 months ago |