| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| medium | codex | Pending share accounting uses pendingUnderlying instead of consumedUnderlying, locking pending funds | no | — |
| low | codex | Unchecked ERC20 transfers when returning funds from strategy can desync accounting | no | — |
| low | codex | Permit signatures depend on mutable conversion rate, enabling front‑run invalidation | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 57893a6f-7c59-4454-928f-4e100bf02a14 | complete | crit 0 high 0 | 6 | 3 months ago |