ArcVault currently supports Arc Testnet only and has not received a formal external audit. Testnet assets have no real-world value.
Please use GitHub’s private vulnerability reporting feature for this repository when available. If private reporting is not enabled, do not disclose exploit details publicly; contact the repository owner through the private channel configured by the repository owner before publication.
Do not include private keys, seed phrases, wallet backups, API tokens, private RPC credentials, private server details or personal data in any report.
Reports should include the affected component, reproduction steps, impact, relevant commit or contract address, and a safe proof of concept. Public Testnet transaction hashes are acceptable when they contain no personal information beyond what is already public onchain.
Relevant reports include smart-contract accounting/access-control issues, wallet or wrong-network safety failures, transaction-state errors, dependency vulnerabilities and accidental secret exposure. General feature requests belong in issues.
There is no bug bounty or guaranteed response deadline. Acknowledgement and remediation depend on severity, reproducibility and available maintainers.
ArcVault never needs a private key or seed phrase. Verify Arc Testnet, the official USDC address, the ArcVault address and transaction details before signing.