| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | yes | yes |
| high | detector | ETH value transfer possible | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Withdrawal paths send ETH to CALLER before clearing caller-specific accounting | no | — |
| low | codex | Fallback and unknown-selector paths appear to accept ETH without crediting any user state | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019b3831-b510-72f0-943d-9bb9b2a2899a | complete | crit 0 high 2 | 4 | 3 months ago |