| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | slither | OwnbitMultiSig.spend(address,uint256,uint8[],bytes32[],bytes32[],bytes) (contracts/Contract.sol#116-123) sends eth to arbitrary user | no | — |
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | External call result ignored; nonce advances even on failed transfer | no | — |
| low | cast | Contract creation opcode present | no | — |
| info | codex | Signed message lacks chain-id domain separation | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019c0ea9-07ab-7229-8ea9-ef5c66ea8236 | complete | crit 0 high 0 | 8 | 2 months ago |