| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | slither | Plague.feeWithdraw() (contracts/Contract.sol#553-571) sends eth to arbitrary user | no | — |
| high | detector | Untrusted CALL target/value reachable | no | no |
| high | detector | ETH value transfer possible | no | no |
| low | codex | `onlyHuman` contract check is bypassable via constructor calls | no | — |
| low | codex | Game timing and price logic depend on block.timestamp manipulation | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019bab3b-ab84-72af-bef3-c28e12418fef | complete | crit 0 high 0 | 6 | 3 months ago |
| 019b477e-b19e-71cb-bb25-3c5f6a0740f4 | complete | crit 0 high 0 | 2 | 3 months ago |
| 019b3844-8ffe-71e7-a036-8890cd866e26 | complete | crit 0 high 0 | 2 | 3 months ago |