| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| high | codex | YieldLimitExec hooks encode/decode mismatch can revert inbound mints and corrupt accounting | no | — |
| medium | codex | StakeEasy lets any caller spend contract-held tokens | no | — |
| medium | codex | Pending-share calculation uses pendingUnderlying instead of consumedUnderlying | no | — |
| low | codex | Unchecked ERC20 transfer/transferFrom can enable free unwrap or silent accounting drift | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 8334cc4c-d376-4cae-a657-bd2812b2b250 | complete | crit 0 high 0 | 7 | 3 months ago |