Skip to main content

Security

This page states what is true today, including what does not yet exist. If a claim is not on this page, do not assume it has been made elsewhere.

Audit status

ItemStatus
ARC token contractNot deployed — not audited
Subscription TreasuryNot deployed — not audited
Buyback contractNot deployed — not audited
Burn mechanismNot deployed — not audited
Verifier staking and slashingNot designed in final form — not audited
Liquidity lockNot established
Bug bounty programmeNot established
Nothing here has been audited

No Arc Trace contract has been reviewed by a third-party security firm. No contract has been deployed to mainnet. Any address, link, or "audited" claim about ARC TRACE that you encounter today is fraudulent. When contracts are deployed and reviewed, this table will be replaced with addresses, auditor names, report links, and lock proofs — not with adjectives.

Risks you are taking

Smart-contract risk

The buyback and burn path involves a treasury holding USDC and a contract executing market purchases. A flaw in that path could result in loss of treasury funds or failed burns. This risk exists for every DeFi contract and is not eliminated by an audit — an audit reduces it.

Execution and MEV risk

Buybacks execute on public markets. Predictable, large, or badly parameterized purchases can be front-run, sandwiched, or executed at poor prices, which converts subscriber revenue into value captured by others. The mitigations described in Protocol Mechanics — time-weighted purchases, slippage limits, liquidity thresholds, route controls — reduce this but do not remove it.

Data accuracy risk

Arc Trace publishes claims about issuers, backing, legal structure, and corporate actions. Those claims can be wrong, stale, or incomplete, particularly before the Verification Network is live and there are no staked verifiers or bonded disputes holding the data accountable. Arc Trace data is an input to your research, not a substitute for issuer disclosures and legal documents.

Oracle and price risk

Oracle-deviation monitoring depends on the oracles it monitors. A compromised, stale, or halted feed degrades every downstream analysis, including risk scores.

Tokenized securities carry the risks of the referenced instrument plus the risks of the token structure. Issuer documentation for this asset class typically states that stock tokens are tokenized debt securities providing economic exposure to referenced securities, and do not grant direct legal or beneficial ownership of the underlying securities. Structures differ between issuers, and Arc Trace's role is to surface that difference, not to flatten it.

Regulatory risk

Tokenized real-world assets sit in an active and inconsistent regulatory environment. Availability of assets, issuers, and features varies by jurisdiction, and can change without notice.

Token risk

ARC can go to zero

ARC is a small, volatile crypto asset with no deployment history. Buyback and burn mechanics reduce supply; they do not guarantee price appreciation, and they do not protect against loss. Nothing in this documentation is investment advice, and no part of it should be read as a promise of return.

Integrity commitments

These are design commitments, stated so they can be held against us:

  1. Commercial relationships stay separate from risk scoring. An issuer cannot purchase a better rating. Issuer bonds are accountability mechanisms for disclosure and disputes, not payments for favorable treatment.
  2. Risk methodology is published, not opaque. Dimension weights, methodology version, and per-dimension rationale are exposed to users and integrators.
  3. Buyback and burn activity is verifiable. Monthly reporting is intended to disclose subscriber revenue, USDC committed, ARC purchased, average execution price, ARC burned, and transaction hashes — such that a reader can reconcile the report against chain data without trusting us.
  4. The Access Pass is non-transferable to reduce unauthorized resale and account sharing.

Protecting yourself

  • Verify every contract address against the Contracts page on this domain. Any ARC contract not listed there is fraudulent.
  • Verify ARC Mainnet network parameters from the official ARC Mainnet documentation, not from a search result or a message.
  • Arc Trace will never ask for a seed phrase or private key, and will never ask you to send tokens to "verify" a wallet or "claim" an allocation.
  • Arc Trace has no presale, no allocation claim, and no airdrop process running. Any such offer is a scam.

Responsible disclosure

If you find a vulnerability in a Arc Trace contract, application, or data pipeline, report it privately before disclosing it publicly. Contact details are on the Links page.

Please include reproduction steps, affected components, and an assessment of impact. Do not test against production systems in ways that risk other users' funds or data, and do not access or modify data that is not yours.