Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · December 2025

Token

for BTCX

BTCX engaged Guardian to review the security of their BTCX Token. From the 15th of December to the 18th of December, an auditor reviewed the source code in scope.

Published
Review window
December 15 to 18, 2025
Language
Solidity
Chains
Ethereum
Sector
Tokens
  • 0 Critical
  • 0 High
  • 0 Medium
  • 0 Low
  • 4 Informational

2 resolved · 2 acknowledged

Scope

Overview

BTCX engaged Guardian to review the security of their BTCX Token. From the 15th of December to the 18th of December, an auditor reviewed the source code in scope.

Findings 4

  1. I-01 Informational Unfixed Pragma Best Practices Resolved
    Location
    BTCXDigitalCurrency.sol

    Description

    In order to clearly identify the Solidity version with which the contracts will be compiled, pragma directives should be fixed and consistent across files within a project.

    To avoid unexpected changes in bytecode across deployments the pragma version of the BTCXDigitalCurrency contract should be fixed instead of the current unfixed ^0.8.27 specification.

    Recommendation

    Fix the exact version of Solidity that will be used to deploy the BTCX token in the BTCXDigitalCurrency file.

    Resolution

    BTCX Team: Resolved.

  2. I-02 Informational Readability Improvements Best Practices Resolved
    Location
    BTCXDigitalCurrency.sol

    Description

    The initial supply for the BTCXDigitalCurrency contract is 1.2 Billion tokens and this is represented as 1200000000 * 10 ** decimals().

    However this formatting may prove not optimally readable for verifiers or readers.

    Recommendation

    Consider using underscores to clearly display the supply as 1.2 Billion as follows:

    1_200_000_000 * 10 ** decimals()

    Resolution

    BTCX Team: Resolved.

  3. I-03 Informational Unnecessary ERC20 Inheritance Warning Acknowledged
    Location
    BTCXDigitalCurrency.sol

    Description

    The BTCXDigitalCurrency inherits from ERC20 as well as ERC20Burnable and ERC20Permit.

    However, the direct is ERC20 inheritance is not strictly necessary since both the ERC20Burnable and ERC20Permit contracts inherit from ERC20 themselves.

    Recommendation

    Consider removing the direct is ERC20 inheritance as it is not strictly necessary, however there is no harm in keeping it.

    Resolution

    BTCX Team: Acknowledged.

  4. I-04 Informational Unnecessary Minting Event Events Acknowledged
    Location
    BTCXDigitalCurrency.sol

    Description

    The constructor emits an InitialMint event upon minting the 1.2 Billion initial supply of tokens.

    However, this initial event emission is not necessary because the _mint function itself emits a Transfer event where the from address is address(0) to indicate that this is a mint.

    As this is the only time a mint can occur with the BTCX token, this is sufficient to represent the initial mint.

    Recommendation

    Consider removing the InitialMint event as it is redundant with the event emitted by _mint.

    Resolution

    BTCX Team: Acknowledged.

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote