BTCX engaged Guardian to review the security of their BTCX Token. From the 15th of December to the 18th of December, an auditor reviewed the source code in scope.
- Published
- Review window
- December 15 to 18, 2025
- Language
- Solidity
- Chains
- Ethereum
- Sector
- Tokens
- 0 Critical
- 0 High
- 0 Medium
- 0 Low
- 4 Informational
Scope
Overview
BTCX engaged Guardian to review the security of their BTCX Token. From the 15th of December to the 18th of December, an auditor reviewed the source code in scope.
Findings 4
-
I-01 Informational Unfixed Pragma Best Practices Resolved
Description
In order to clearly identify the Solidity version with which the contracts will be compiled, pragma directives should be fixed and consistent across files within a project.
To avoid unexpected changes in bytecode across deployments the pragma version of the
BTCXDigitalCurrencycontract should be fixed instead of the current unfixed^0.8.27specification.Recommendation
Fix the exact version of Solidity that will be used to deploy the BTCX token in the
BTCXDigitalCurrencyfile.Resolution
BTCX Team: Resolved.
-
I-02 Informational Readability Improvements Best Practices Resolved
Description
The initial supply for the
BTCXDigitalCurrencycontract is 1.2 Billion tokens and this is represented as1200000000 * 10 ** decimals().However this formatting may prove not optimally readable for verifiers or readers.
Recommendation
Consider using underscores to clearly display the supply as 1.2 Billion as follows:
1_200_000_000 * 10 ** decimals()Resolution
BTCX Team: Resolved.
-
I-03 Informational Unnecessary ERC20 Inheritance Warning Acknowledged
Description
The
BTCXDigitalCurrencyinherits fromERC20as well asERC20BurnableandERC20Permit.However, the direct
is ERC20inheritance is not strictly necessary since both theERC20BurnableandERC20Permitcontracts inherit fromERC20themselves.Recommendation
Consider removing the direct
is ERC20inheritance as it is not strictly necessary, however there is no harm in keeping it.Resolution
BTCX Team: Acknowledged.
-
I-04 Informational Unnecessary Minting Event Events Acknowledged
Description
The constructor emits an
InitialMintevent upon minting the 1.2 Billion initial supply of tokens.However, this initial event emission is not necessary because the
_mintfunction itself emits aTransferevent where thefromaddress isaddress(0)to indicate that this is a mint.As this is the only time a mint can occur with the BTCX token, this is sufficient to represent the initial mint.
Recommendation
Consider removing the
InitialMintevent as it is redundant with the event emitted by_mint.Resolution
BTCX Team: Acknowledged.
No findings match.
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
