| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Withdrawal signatures lack domain separation, enabling cross-contract/chain replay | no | — |
| medium | codex | Fee-on-transfer tokens can be over-credited during transit | no | — |
| low | codex | Signer can be set to zero address, weakening signature validation | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| ecbd4a63-528c-4904-a826-66055a86935c | complete | crit 0 high 0 | 5 | 3 months ago |