| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| medium | detector | Untrusted CALL target/value reachable | yes | yes |
| medium | detector | ETH value transfer possible | yes | yes |
| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | codex | Minter can be set by any address once, enabling unauthorized mint/reset | no | — |
| high | detector | Authorization based on tx.origin | no | — |
| medium | codex | Unchecked multiplication/division in trade and volume calculations can overflow | no | — |
| medium | codex | Order signatures lack proper domain separation and user binding in hash | no | — |
| low | codex | ERC20 approve race condition allows double-spend of allowance | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019bb377-69d5-7349-915e-9672d06739b0 | failed | crit 0 high 0 | 7 | 3 months ago |
| 019b477e-a852-706b-9832-6b7c8bee2189 | complete | crit 0 high 0 | 3 | 3 months ago |
| 019b3836-4fd3-719a-a6a4-24e11ccdb5c7 | complete | crit 0 high 0 | 3 | 3 months ago |