About this project
Ctrl+ArcZ is a USDC payments toolkit built for Arc Testnet (chain id 5042002), where USDC serves as both the gas token and the transferred asset. It targets three gaps in ordinary stablecoin transfers: they are final, blind, and one-shot.
Three surfaces share one backend: a web app at ctrlarcz.xyz, the npm package @ctrl-arcz/sdk, and a native Kotlin/Compose Android app on Google Play. The Android client calls the same API endpoints and deployed contracts as the SDK, and parity vectors hold both implementations to one specification.
Layer 1 is a pre-send risk firewall. A pure rule engine returns graded verdicts: lookalike-address and zero-value-bait patterns block, fresh or history-less addresses warn, and previously verified or known counterparties pass. A positive signal never overrides a block, and the firewall fails closed when history cannot be fetched. sendProtected runs the scan itself and throws before funds move. A deliberate escape hatch shows both full addresses side by side for comparison rather than offering a one-click override.
Layer 2 is a protected transfer. Funds are locked in a contract and released only against an 80-bit claim code (Crockford base32, sixteen characters) whose hash alone is on chain. The sender can cancel at any time until claimed; unclaimed transfers are refunded automatically after expiry. Wrong codes return false rather than reverting so an attempt limiter can commit; five wrong guesses freeze the transfer. Anyone may submit a claim, but funds always go to the recipient recorded at send time.
Layer 3 is a clean history: zero-value transfers are dropped and only known tokens shown, with filtered rows returned separately. Settled claims emit RecipientVerified, feeding verified addresses back into the lookalike rule.
Additional features include spend-policy accounts for subscriptions and agent wallets (target, caps, interval, expiry, owned by a one-time address), private payments via disposable accounts, and CCTP or Gateway for bringing USDC onto Arc. The project reports 850 tests across Foundry, SDK, demo-kit, API, keeper, and sender suites. There is no custody, no owner, no pause, and no upgrade path.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.