| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| high | detector | Untrusted DELEGATECALL target reachable | no | no |
| high | codex | HighWaterMark initialized with underlying decimals triggers performance fees immediately for <18-decimal assets | no | — |
| high | codex | Uninitialized lastFeeTime causes excessive management fees and can brick first settlement | no | — |
| medium | detector | ETH value transfer possible | no | no |
| medium | cast | DELEGATECALL present | no | — |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| low | cast | Contract creation opcode present | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| dc8ed28c-75fd-4afe-9da0-14fa0ea4b981 | failed | crit 0 high 0 | 9 | 3 months ago |
| 42f21ca1-82d3-426a-a45a-788b3a4f9d5b | failed | crit 0 high 0 | 11 | 3 months ago |