| Severity | Tool | Title | Validated | Confirmed |
|---|---|---|---|---|
| high | detector | Authorization based on tx.origin | no | — |
| medium | codex | Authorization uses tx.origin (phishing-prone) | no | — |
| medium | detector | Untrusted CALL target/value reachable | no | no |
| medium | detector | CREATE/CREATE2 reachable | no | no |
| medium | detector | ETH value transfer possible | no | no |
| medium | codex | CALLCODE with computed targets (delegatecall-like execution) | no | — |
| low | cast | Contract creation opcode present | no | — |
| low | codex | Many external CALLs use computed target/value (untrusted call surface) | no | — |
| info | cast | Heavy EXTCODE*/BALANCE usage | no | — |
| info | cast | Heavy CALL-family usage | no | — |
| Run ID | Status | Validated | Total findings | Created |
|---|---|---|---|---|
| 019c0ea9-08d3-73c7-9a5b-cdbf6695439c | complete | crit 0 high 0 | 10 | 2 months ago |
| 019b477e-a7fa-7248-980f-edc2b8e482f4 | complete | crit 0 high 0 | 4 | 3 months ago |
| 019b3836-4115-703f-a8ce-579263144bfa | complete | crit 0 high 0 | 4 | 3 months ago |