Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»BitDCA Staking Agreement Audit Summary
HACKING NEWS

BitDCA Staking Agreement Audit Summary

By Crypto FlexsOctober 19, 20255 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
BitDCA Staking Agreement Audit Summary
Share
Facebook Twitter LinkedIn Pinterest Email

BitDCA is a protocol that enables automatic small savings when making card payments. The Staking Contract is a subcomponent of BitDCA that allows users to stake BDCA tokens and receive rewards.

The protocol implements a staking system with NFT-based positions and tiered rewards. This allows users to lock up their BDCA tokens for a predefined period of time in exchange for bonuses. USDT and BDCA also have additional bonus distribution options during the staking period.

BitDCA collaborated with Ackee Blockchain Security to conduct a security review of the BitDCA staking contract with a total time contribution of 6 engineering days between June 23 and July 3, 2025.

The second revision review was conducted between August 14 and August 15, 2025.

A third revision review was conducted through a one-day engineering time donation to address any issues not addressed in previous revisions.

methodology

  1. Technical specifications verification
    The scope of the audit is confirmed with the client and the auditor joins the project. Review the provided documentation and compare it to your audit system.
  2. Tool-based analysis
    In-depth scanning using the Solidity static analysis tool Wake, along with the Solidity (Wake) extension, is performed to flag potential vulnerabilities for further analysis early in the process.
  3. Manual code review
    Auditors manually check code line by line to identify vulnerabilities and code quality issues. The main focus is recognizing potential edge cases and project-specific risks.
  4. Local deployment and hacking
    The contract is deployed to the local Wake environment where targeted attempts to exploit the vulnerability are made. The resilience of the contract against various attack vectors is assessed.
  5. Unit and fuzzy testing
    Unit tests are run to verify expected system behavior. Once coverage gaps are identified, you can use the Wake Framework to write additional unit or fuzz tests. The goal is to verify the stability of the system under real-world conditions and ensure robustness to expected and unexpected inputs.

We began our review using static analysis tools, including Wake. We then took a closer look at the logic of the contract. Used Wake Framework for testing and fuzzing. The staking contract has been integrated with the out-of-scope contract (Presale.sol) has been black-boxed for review purposes. During the review process, we paid special attention to the following:

  • Verify that the system’s calculations are correct.
  • Verify the fairness of reward distribution.
  • Verify that the staking process matches expected behavior.
  • Detect possible reentrancy in your code.
  • Ensure access controls are neither too lax nor too strict. and
  • I’m looking for common problems like data validation.

range

An audit was performed at commit time. c62d3dd It’s in a private repository and has the following scope:

  • Staking.sol; and
  • StakingNFT.sol

Revision 1.1 was performed on commits between August 14 and August 15, 2025. 522ad96The scope is a revision of the previous revision.

Revision 2.0 was done on commit. c05674cScope is an issue unresolved in previous revisions.

The classification of security findings is determined by two levels: influence and something that could happen. This two-dimensional classification helps clarify the severity of individual problems. Problems that can be assessed as: middle Severity can only be discovered by the team, but is usually reduced by the likelihood factor. femaleAnning or meinformation provided Severity rating.

Here are the results of our review: 25 items foundSeverity levels range from Warning to High. The most serious findings include: H2The distribution of rewards may be incorrect. Full details by revision can be found in the Audit Report PDF linked below.

critical severity

No critical severity issues were found.

Severity High

H1: Inverted logic of NFT transfer hook

H2: distributeRewards The function is defective

H3: Project is not compatible with Smart Accounts

medium severity

M1: Hardcoded minority assumption

M2: You can bypass stake amount limits.

low severity

L1: Insecure ERC20 operations

L2: Inconsistent access control

L3: The maximum stake amount may be exceeded.

L4: Missing events for important state changes

L5: Missing pause modifier when distributing rewards.

L6: The mint function is performing a safe mint.

warning severity

W1: Affiliate Program Integration

W2: Insufficient data validation

W3: Possible lack of funds

W4: Potential re-entry due to NFT hook

W5: Uninitialized variables and roles

W6: Unknown swap condition

W7: Potential price manipulation of reward distribution

Information Severity

I1: Code replication

I2: Divide by 0 in reward calculations

I3: Ambiguous error message

I4: Use magic number

I5: Missing document

I6: Typo

I7: Unused variable

trust model

Administrators have excessive power across all contracts, creating a potential single point of failure. Administrators can change important parameters, pause/unpause as desired, modify layer parameters affecting user funds, and withdraw all tokens at any time by: rescueToken function. Contracts may also be upgraded to other implementations.

conclusion

Ackee Blockchain Security recommended BitDCA:

  • Write documentation for your code base.
  • We use an oracle for price calculation during reward distribution.
  • Define specifications for the distribution function and adjust the logic accordingly.
  • Create a comprehensive test suite.
  • Simulate deployment transactions before executing them. and
  • Address any identified issues.

Ackee Blockchain Security’s full BitDCA staking contract audit report can be found here.

We were delighted to audit BitDCA and look forward to working with them again.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cryptocurrency Wills and Trusts – Vault12

January 5, 2026

Automated wallet leaks raise new cryptocurrency security concerns across the EVM network.

January 3, 2026

ASTER price outlook as whale loses 3 million coins

January 1, 2026
Add A Comment

Comments are closed.

Recent Posts

BTC Forge Introduces A New Era Of Cloud Mining, Enabling To Earn Bitcoin Passively Without Hardware

January 7, 2026

Coinhub Exchange Brings A Bank-Like Crypto Experience To Las Vegas And Phoenix

January 6, 2026

Bybit’s 2026 Crypto Outlook Challenges The Four-Year Crypto Cycle

January 6, 2026

As a bullish reversal pattern is formed ahead of the Fermi hard fork, BNB price is targeting $1,000.

January 6, 2026

Phemex Catalyzes 2026 Market Momentum With Dual Strategic Initiatives For Trader Empowerment

January 6, 2026

Mixed signals for Ethereum: Technical milestones and growing adoption offset market pressure

January 6, 2026

AAVE price prediction: $185-195 recovery target in 2-4 weeks

January 6, 2026

Cryptocurrency Wills and Trusts – Vault12

January 5, 2026

Taisu Ventures And Keio FinTEK Center Launch Keio ChainHack 2026 Focused On Web3 Innovation

January 5, 2026

SlotGPT launches new AI slots platform that turns players into creators

January 5, 2026

Bitcoin price rises 1.5% as Bitcoiners celebrate Genesis Day

January 4, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

BTC Forge Introduces A New Era Of Cloud Mining, Enabling To Earn Bitcoin Passively Without Hardware

January 7, 2026

Coinhub Exchange Brings A Bank-Like Crypto Experience To Las Vegas And Phoenix

January 6, 2026

Bybit’s 2026 Crypto Outlook Challenges The Four-Year Crypto Cycle

January 6, 2026
Most Popular

io.net partners with Synesis One to accelerate AI development

May 17, 2024

Mantle Network Launches Mantle Learn via HackQuest to Onboard Web2 Developers to Web3

December 13, 2023

Financial Stability Oversight Board Reiterates Call for Legislation to Address Cryptocurrency Risks

December 15, 2023
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.