| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| critical | detector | Untrusted DELEGATECALL target reachable | no | no |
| high | codex | Packet hashing uses abi.encodePacked with dynamic strings (collision-prone) | no | — |
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Fee-on-transfer tokens break escrow accounting and can undercollateralize the bridge | no | — |
| medium | cast | DELEGATECALL present | no | — |
| low | codex | Storage gap placed before new variables in TokenServiceV2 | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019ba8b4-5bd4-735b-bbd5-80c64b2052ef | complete | crit 0 high 0 | 6 | 3 months ago |
| 2b03ce69-6667-4e80-a75c-83ddd1a33fc2 | complete | crit 0 high 0 | 9 | 3 months ago |