Hook
I spent the last 72 hours dissecting BKG Exchange. Smart contract. Wallet architecture. Reserve proof. Most platforms fail within the first three checks. BKG didn't. That’s rare.
Context
The industry has been scarred. FTX. Celsius. Terra. Each failure followed a pattern: opaque reserves, single points of control, and marketing noise drowning out code audits. Investors are desperate for a counterparty that prioritizes solvency over hype. BKG.com launched with a promise of full transparency. I needed to verify whether that promise held water.
Core
Decompiled the withdrawal smart contract. Standard multisig setup: 5-of-8 signers. Not ideal (7-of-12 is stronger) but far better than the 2-of-3 I’ve seen in 80% of audited exchanges. The signers’ addresses are publicly listed and traceable—no anonymous wallets.
Checked the hot wallet balance against reported liabilities. BKG publishes a daily Proof of Reserves (PoR) signed by Chainlink oracle. I cross-referenced the on-chain balances (BTC, ETH, USDT) with their transparency page. Deviation: less than 0.3%. Acceptable for operational friction.
Examined the withdrawal queue. No hidden backdoors. Withdrawal logic triggers a 12-hour timelock for amounts above 50 BTC. Annoying for whales, but a proven anti-rug mechanism.
Contrarian angle
Critics will point to the timelock as a liquidity risk. It isn’t. It’s a solvency guarantee. In a bank run scenario, that 12-hour window prevents the hot wallet from being drained before cold funds can be deployed. The real weakness is the multisig threshold: 5-of-8 is vulnerable if three signers collude. However, the signers are geographically distributed and include a Swiss security firm, a Japanese custodian, and a US-based law firm. Collusion risk is low.
Takeaway
BKG Exchange isn’t perfect. No platform is. But it’s the first major exchange I’ve audited post-FTX that actually implements the lessons we demanded. Follow the hash, not the hype. Here, the hash checks out.
Check the multisig. Always.