Security
This page states what is true today, including what does not yet exist. If a claim is not on this page, do not assume it has been made elsewhere.
Audit status
| Item | Status |
|---|---|
| ARC token contract | Not deployed — not audited |
| Subscription Treasury | Not deployed — not audited |
| Buyback contract | Not deployed — not audited |
| Burn mechanism | Not deployed — not audited |
| Verifier staking and slashing | Not designed in final form — not audited |
| Liquidity lock | Not established |
| Bug bounty programme | Not established |
No Arc Trace contract has been reviewed by a third-party security firm. No contract has been deployed to mainnet. Any address, link, or "audited" claim about ARC TRACE that you encounter today is fraudulent. When contracts are deployed and reviewed, this table will be replaced with addresses, auditor names, report links, and lock proofs — not with adjectives.
Risks you are taking
Smart-contract risk
The buyback and burn path involves a treasury holding USDC and a contract executing market purchases. A flaw in that path could result in loss of treasury funds or failed burns. This risk exists for every DeFi contract and is not eliminated by an audit — an audit reduces it.
Execution and MEV risk
Buybacks execute on public markets. Predictable, large, or badly parameterized purchases can be front-run, sandwiched, or executed at poor prices, which converts subscriber revenue into value captured by others. The mitigations described in Protocol Mechanics — time-weighted purchases, slippage limits, liquidity thresholds, route controls — reduce this but do not remove it.
Data accuracy risk
Arc Trace publishes claims about issuers, backing, legal structure, and corporate actions. Those claims can be wrong, stale, or incomplete, particularly before the Verification Network is live and there are no staked verifiers or bonded disputes holding the data accountable. Arc Trace data is an input to your research, not a substitute for issuer disclosures and legal documents.
Oracle and price risk
Oracle-deviation monitoring depends on the oracles it monitors. A compromised, stale, or halted feed degrades every downstream analysis, including risk scores.
Underlying-asset and legal risk
Tokenized securities carry the risks of the referenced instrument plus the risks of the token structure. Issuer documentation for this asset class typically states that stock tokens are tokenized debt securities providing economic exposure to referenced securities, and do not grant direct legal or beneficial ownership of the underlying securities. Structures differ between issuers, and Arc Trace's role is to surface that difference, not to flatten it.
Regulatory risk
Tokenized real-world assets sit in an active and inconsistent regulatory environment. Availability of assets, issuers, and features varies by jurisdiction, and can change without notice.
Token risk
ARC is a small, volatile crypto asset with no deployment history. Buyback and burn mechanics reduce supply; they do not guarantee price appreciation, and they do not protect against loss. Nothing in this documentation is investment advice, and no part of it should be read as a promise of return.
Integrity commitments
These are design commitments, stated so they can be held against us:
- Commercial relationships stay separate from risk scoring. An issuer cannot purchase a better rating. Issuer bonds are accountability mechanisms for disclosure and disputes, not payments for favorable treatment.
- Risk methodology is published, not opaque. Dimension weights, methodology version, and per-dimension rationale are exposed to users and integrators.
- Buyback and burn activity is verifiable. Monthly reporting is intended to disclose subscriber revenue, USDC committed, ARC purchased, average execution price, ARC burned, and transaction hashes — such that a reader can reconcile the report against chain data without trusting us.
- The Access Pass is non-transferable to reduce unauthorized resale and account sharing.
Protecting yourself
- Verify every contract address against the Contracts page on this domain. Any ARC contract not listed there is fraudulent.
- Verify ARC Mainnet network parameters from the official ARC Mainnet documentation, not from a search result or a message.
- Arc Trace will never ask for a seed phrase or private key, and will never ask you to send tokens to "verify" a wallet or "claim" an allocation.
- Arc Trace has no presale, no allocation claim, and no airdrop process running. Any such offer is a scam.
Responsible disclosure
If you find a vulnerability in a Arc Trace contract, application, or data pipeline, report it privately before disclosing it publicly. Contact details are on the Links page.
Please include reproduction steps, affected components, and an assessment of impact. Do not test against production systems in ways that risk other users' funds or data, and do not access or modify data that is not yours.