Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»BitDCA Staking Agreement Audit Summary
HACKING NEWS

BitDCA Staking Agreement Audit Summary

By Crypto FlexsOctober 19, 20255 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
BitDCA Staking Agreement Audit Summary
Share
Facebook Twitter LinkedIn Pinterest Email

BitDCA is a protocol that enables automatic small savings when making card payments. The Staking Contract is a subcomponent of BitDCA that allows users to stake BDCA tokens and receive rewards.

The protocol implements a staking system with NFT-based positions and tiered rewards. This allows users to lock up their BDCA tokens for a predefined period of time in exchange for bonuses. USDT and BDCA also have additional bonus distribution options during the staking period.

BitDCA collaborated with Ackee Blockchain Security to conduct a security review of the BitDCA staking contract with a total time contribution of 6 engineering days between June 23 and July 3, 2025.

The second revision review was conducted between August 14 and August 15, 2025.

A third revision review was conducted through a one-day engineering time donation to address any issues not addressed in previous revisions.

methodology

  1. Technical specifications verification
    The scope of the audit is confirmed with the client and the auditor joins the project. Review the provided documentation and compare it to your audit system.
  2. Tool-based analysis
    In-depth scanning using the Solidity static analysis tool Wake, along with the Solidity (Wake) extension, is performed to flag potential vulnerabilities for further analysis early in the process.
  3. Manual code review
    Auditors manually check code line by line to identify vulnerabilities and code quality issues. The main focus is recognizing potential edge cases and project-specific risks.
  4. Local deployment and hacking
    The contract is deployed to the local Wake environment where targeted attempts to exploit the vulnerability are made. The resilience of the contract against various attack vectors is assessed.
  5. Unit and fuzzy testing
    Unit tests are run to verify expected system behavior. Once coverage gaps are identified, you can use the Wake Framework to write additional unit or fuzz tests. The goal is to verify the stability of the system under real-world conditions and ensure robustness to expected and unexpected inputs.

We began our review using static analysis tools, including Wake. We then took a closer look at the logic of the contract. Used Wake Framework for testing and fuzzing. The staking contract has been integrated with the out-of-scope contract (Presale.sol) has been black-boxed for review purposes. During the review process, we paid special attention to the following:

  • Verify that the system’s calculations are correct.
  • Verify the fairness of reward distribution.
  • Verify that the staking process matches expected behavior.
  • Detect possible reentrancy in your code.
  • Ensure access controls are neither too lax nor too strict. and
  • I’m looking for common problems like data validation.

range

An audit was performed at commit time. c62d3dd It’s in a private repository and has the following scope:

  • Staking.sol; and
  • StakingNFT.sol

Revision 1.1 was performed on commits between August 14 and August 15, 2025. 522ad96The scope is a revision of the previous revision.

Revision 2.0 was done on commit. c05674cScope is an issue unresolved in previous revisions.

The classification of security findings is determined by two levels: influence and something that could happen. This two-dimensional classification helps clarify the severity of individual problems. Problems that can be assessed as: middle Severity can only be discovered by the team, but is usually reduced by the likelihood factor. femaleAnning or meinformation provided Severity rating.

Here are the results of our review: 25 items foundSeverity levels range from Warning to High. The most serious findings include: H2The distribution of rewards may be incorrect. Full details by revision can be found in the Audit Report PDF linked below.

critical severity

No critical severity issues were found.

Severity High

H1: Inverted logic of NFT transfer hook

H2: distributeRewards The function is defective

H3: Project is not compatible with Smart Accounts

medium severity

M1: Hardcoded minority assumption

M2: You can bypass stake amount limits.

low severity

L1: Insecure ERC20 operations

L2: Inconsistent access control

L3: The maximum stake amount may be exceeded.

L4: Missing events for important state changes

L5: Missing pause modifier when distributing rewards.

L6: The mint function is performing a safe mint.

warning severity

W1: Affiliate Program Integration

W2: Insufficient data validation

W3: Possible lack of funds

W4: Potential re-entry due to NFT hook

W5: Uninitialized variables and roles

W6: Unknown swap condition

W7: Potential price manipulation of reward distribution

Information Severity

I1: Code replication

I2: Divide by 0 in reward calculations

I3: Ambiguous error message

I4: Use magic number

I5: Missing document

I6: Typo

I7: Unused variable

trust model

Administrators have excessive power across all contracts, creating a potential single point of failure. Administrators can change important parameters, pause/unpause as desired, modify layer parameters affecting user funds, and withdraw all tokens at any time by: rescueToken function. Contracts may also be upgraded to other implementations.

conclusion

Ackee Blockchain Security recommended BitDCA:

  • Write documentation for your code base.
  • We use an oracle for price calculation during reward distribution.
  • Define specifications for the distribution function and adjust the logic accordingly.
  • Create a comprehensive test suite.
  • Simulate deployment transactions before executing them. and
  • Address any identified issues.

Ackee Blockchain Security’s full BitDCA staking contract audit report can be found here.

We were delighted to audit BitDCA and look forward to working with them again.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

MakinaFi suffered a $4.1 million Ethereum hack amid suspected MEV tactics.

January 27, 2026

Uniswap Price Outlook As Ethereum’s Vitalik Buterin Offloads UNI Tokens

January 25, 2026

Everstake lump sum deposit contract audit

January 23, 2026
Add A Comment

Comments are closed.

Recent Posts

NVIDIA FastGen reduces AI video creation time by 100x with open source library

January 28, 2026

Nexura To Host Invite-Only Web3 Marketing Roundtable At ETHDenver

January 28, 2026

MakinaFi suffered a $4.1 million Ethereum hack amid suspected MEV tactics.

January 27, 2026

Bybit, Mantle, And Byreal Partner To Extend CeDeFi Access For $MNT On Solana Via Mantle Super Portal

January 27, 2026

ZetaChain 2.0 Launches With Anuma, Bringing Private Memory And AI Interoperability To Creators

January 27, 2026

Phemex Introduces Elite Trader Recruitment Program Focused On Professional Copy Trading

January 27, 2026

Husky Inu AI (HINU) completed a conversion to $0.00025833 and the cryptocurrency market rebounded, but the stablecoin market cap fell by more than $2 billion.

January 27, 2026

Towards 2026 – How Multi-Currency Cloud Mining Can Build Sustainable Daily Settlement Returns Of 5000 XRP

January 26, 2026

BlackRock supports Ethereum gatekeeping tokenization despite market share being threatened.

January 26, 2026

Crypto.Casino Launches To Bring Transparency And Trust To Crypto Casinos

January 26, 2026

Why is SKY rising +8% while other cryptocurrencies are in the red?

January 25, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

NVIDIA FastGen reduces AI video creation time by 100x with open source library

January 28, 2026

Nexura To Host Invite-Only Web3 Marketing Roundtable At ETHDenver

January 28, 2026

MakinaFi suffered a $4.1 million Ethereum hack amid suspected MEV tactics.

January 27, 2026
Most Popular

Exploring Liquid Democracy in Blockchain Startups: Insights from a16z Crypto

November 1, 2024

Bitcoin decline extends — Markets are under pressure due to risk aversion.

November 2, 2025

BitTorrent’s Weekly Progress Report Highlights: Key Developments and Statistics

May 21, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.