WStaking

    Security information

    Security and audit documentation

    Review the available smart-contract audit, its scope, remediation status, contract references, and the process for reporting a security issue.

    Audit overview

    WStaking has a smart-contract security assessment performed by CredShields. The report should be read together with the contract name, version, network, source reference, and scope identified in the audit.

    The audit reflects the code and conditions reviewed during a specific period. It does not guarantee that the contract is free from vulnerabilities or that later deployments, upgrades, frontend systems, backend services, or operational processes are covered.

    • Auditor: CredShields Technologies PTE. LTD.
    • Audit period: March 10-19, 2026
    • Retest date: March 20, 2026
    • Contract: WStaking Smart Contract (BSCSecureStakingV5 in the findings)
    • Network: BNB Smart Chain Testnet
    • Audited scope address: 0xf7edfbf075b48daa47b3405c190b126fb6f02dcd
    • Retested scope address: 0x6B6b5eca778BcFdbC9D8b2d718e01233A1C1d5eD
    • Source revision: Not identified in the published report

    Audit scope and limitations

    The report describes a smart-contract assessment of the identified testnet scope. It states that CredShields reviewed the contract source, functions, and business logic during the audit window and retested the remediation changes.

    The report does not establish coverage for the frontend, backend services, infrastructure, administrative procedures, external integrations, token contracts, operational wallets, or later contract versions and deployments.

    The report identifies testnet addresses and does not publish a source commit that proves the current mainnet deployments match the audited or retested code. Users should compare the audited source and version with the currently deployed contract information.

    Findings and remediation

    The report records 16 findings: 1 Critical, 2 High, 3 Medium, 6 Low, 1 Informational, and 3 Gas optimization items. Its executive summary states that the findings were addressed, while the finding table records individual items as Fixed or Acknowledged.

    The report records a retest on March 20, 2026. Users should review the finding entries and retest notes in the full report for the exact status of each item; an acknowledged finding should not be treated as resolved.

    • Critical: 1 finding - recorded as Fixed; the report records the retest for this item.
    • High: 2 findings - 1 Fixed and 1 Acknowledged.
    • Medium: 3 findings - 2 Fixed and 1 Acknowledged.
    • Low: 6 findings - recorded as Fixed.
    • Informational: 1 finding - recorded as Fixed.
    • Gas optimization: 3 findings - recorded as Fixed.

    Contract and deployment verification

    Before relying on an audit, compare the audited contract name, version, source reference, and network with the contract currently used by the application.

    Confirm the network, full contract address, proxy or implementation status, version, and explorer source-code verification where available. Current published mainnet references are listed separately in the contract registry and transparency information.

    Source-code verification on a blockchain explorer allows published source to be compared with deployed bytecode. It is not a substitute for an independent security audit.

    The published report identifies BNB Smart Chain Testnet scope addresses, while the application publishes mainnet references on other deployments. Exact audited source-to-mainnet deployment matching is not currently verified on-site.

    • X Layer mainnet reference: 0xe5ef454b050e7a6cffe692c05b71ee2768c32bba
    • BNB Smart Chain mainnet reference: 0x1C5204bb87cE4A2c2e00d42f20a5aF24705c2496
    • Base mainnet reference: 0xA4B852C076A119586269054E919FFF1F711A52cA

    Security contact and responsible disclosure

    Security researchers and users can report a suspected vulnerability through the responsible-disclosure process. Include the affected page, contract, or network; a clear description; reproduction steps; a transaction hash or contract address where relevant; potential impact; and supporting technical details.

    Do not publish an unresolved vulnerability publicly. Do not share private keys, seed phrases, wallet recovery phrases, or account passwords. For general account or transaction support that is not a vulnerability report, use the normal support channel.

    Security contact: service@wstaking.net

    Related information

    More WStaking documentation