| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | codex | Auto‑liquidation signatures lack domain separation and replay protection | no | — |
| medium | detector | ETH value transfer possible | no | no |
| low | codex | Withdrawal lock can be bypassed by transferring vault tokens | no | — |
| info | codex | Unchecked ERC20 approve return value during migration | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| c1c4fe5b-a5df-4486-9cc2-7441001e618c | failed | crit 0 high 0 | 5 | 3 months ago |
| cb0d0890-71b6-43c1-9e9b-faffab747a65 | failed | crit 0 high 0 | 8 | 3 months ago |