Summary
EURC on Arc is deployed using the FiatTokenV2_2 implementation. It can be bridged to Arc via both Circle Mint and CCTPx, Circle’s custom bridging framework for non-USDC assets, which uses a burn-and-mint mechanism. CCTPx leverages CCTP’s attestation infrastructure, Iris, alongside a dedicated CrossChainTokenService (CCTS) entry contract. The attestation threshold is 2-of-2 and controlled entirely by Circle.
The key findings include that access control across all contracts, including both the asset and bridge contracts in scope, relies on EOAs managed under Circle’s enterprise-grade key management program, which they claim maintains SOC 2 Type 2 attestation and follows NIST frameworks across the infrastructure. Further, no timelocks gate sensitive contract upgrades, consistent with Circle’s operational model for USDC and EURC on other networks. Additionally, the EURC bridge minter, represented by its TokenManager contract, does not pin its own implementation and instead resolves it through the CCTS singleton at call time. This means the CCTS owner ultimately controls the code executed by the TokenManager.
1. Asset Fundamental Characteristics
EURC on Arc is deployed as an upgradable ERC20 FiatTokenProxy contract that uses the FiatTokenV2_2 implementation contract. EURC is natively minted on Arc, with Circle Mint enabling minting and redemptions. Currently, bridging is supported via Circle’s new CCTPx protocol. Redemptions through Circle Mint are accessible only to qualified persons/businesses. The token’s design is consistent with other chains where EURC is listed on Aave.
1.1 Bridge Risk
EURC is bridged on Arc through Circle’s CCTPx protocol via a burn-and-mint mechanism. A dedicated TokenManager was deployed on September 14, 2026 and holds mint and burn rights on the EURC contract, making the mechanism burn-and-mint on the Arc side. Verified users can also utilize Circle Mint as a bridge via its permissioned minting/redemption mechanism.
Circle extends its Cross-Chain Transfer Protocol (CCTP) to non-USDC assets by leveraging its core attestation infrastructure (Iris) alongside a dedicated CrossChainTokenService (CCTS) entry contract. Instead of relying on traditional bridge liquidity pools, the protocol processes transfers using a burn-and-mint mechanism or permissionless wrapping.
Attester Threshold
Because CCTPx routes its messages through the existing CCTP contracts, message authenticity inherits CCTP’s 2-of-2 Circle-operated attester set.
Rate Limits
The TokenManager enforces a per-transfer ceiling of 862K EURC and a net-flow rate limit of 4.31M EURC in each direction over a rolling six-hour window.
2. Market Risk
2.1 Liquidity
Users can swap 610K EURC for $687K USDC within a price impact of 2%.
Source: EURC/USDC Swap Liquidity on Arc, KyberSwap, September 17, 2026
2.1.1 Liquidity Venue Concentration
On-chain liquidity for EURC on Arc is available on multiple venues, the most liquidity being Uniswap V4 EURC/USDC 0.05% ($625K in TVL), Uniswap V4 EURC/USDC 0% ($585K in TVL), and Aerodrome EURC/USDC pools ($375K in TVL).
Source: EURC DEX liquidity pools on Arc, GeckoTerminal, September 17, 2026
2.1.2 DEX LP Concentration
EURC LP concentration on Arc is moderately, with the top suppliers to the respective Uniswap V4 EURC/USDC pools, EOA 1 and EOA 2, accounting for 73.28% and 67.6% of their respective pools’ liquidity. The top liquidity provider in the Aerodrome EURC/USDC pool is a multisig accounting for 80.12% of the pool’s total liquidity.
2.2 Volatility
As the Arc chain went live only two days ago, limited volatility data is available for EURC’s secondary market price. Therefore, no meaningful conclusions regarding its price stability can yet be drawn.
2.3 Exchanges
EURC is traded across several CEXs, though its trading activity and liquidity are predominantly concentrated on Coinbase.
3. Technological Risk
3.1 Smart Contract Risk
The bridge contracts were audited by third-party auditors. However, the reports were not publicly available at the time of review, preventing independent verification of the findings.
The following contracts power CCTPx bridge on the Arc chain:
- CrossChainTokenService: Upgradeable, ERC-1967 proxy. Singleton that creates bridges, routes cross-chain messages, and acts as both the upgrade authority and the ownership assigner for every CCTPx contract on Arc. Controlled by an EOA A.
- CCTP MessageTransmitterV2: Upgradeable, ERC-1967 proxy. The underlying CCTP contract that verifies attester signatures on inbound messages and emits outbound ones. Controlled by an EOA B.
- FeeService: Upgradeable, ERC-1967 proxy. Quotes and collects the cross-chain transfer fee. Controlled by an EOA C.
- DeploymentDelegate: Immutable. Deploys new bridges and tokens on behalf of the service. No owner role.
- TransferDelegate: Immutable. Executes the mint, burn, lock, and unlock legs of a transfer. No owner role.
- FiatTokenDenylistAdapter: Immutable. Service-wide denylist source. A view-only adapter that forwards
isDenylistedto the Arc USDC contract’sisBlacklisted. No owner role, so the effective control sits with the USDCblacklister.
The EURC TokenManager contract is beacon proxy that resolve its implementation through the Cross Chain Token Service singleton at call time as the local override is unset. Whoever controls the CCTS on a given chain can therefore change the code of every CCTPx TokenManager and CCTPx-issued token on that chain in a single action.
3.2 Access Control
The RBAC structure for Circle’s EURC contracts is configured similar to the USDC setup with different controlling wallets as follows.
| Controlling Wallet | Role | Functionality |
|---|---|---|
| EOA 1 | owner |
Re-assign any role except for admin. |
| EOA 2 | admin |
Manage proxy-level functionalities. |
| EOA 3 | pauser |
Pause the contracts, preventing all transfers, minting, and burning. |
| EOA 4 | blacklister |
Prevent transfers to/from an address and prevent it from minting/burning. |
| EOA 5, owner of the masterMinter contract | masterMinter |
Add/remove minters and increase their minting allowance. |
| 15 minters are configured, with the following having non-zero allowance: Minter1: 74,380,918.59 EURC, TokenManager: 41,315,963.99 EURC, and Minter2: 10,053.59 EURC | minters |
Create/destroy tokens. |
| Unassigned | rescuer |
Transfer any ERC-20 token locked in the contract. |
The TokenManager and CCTS contracts use a three-role structure of owner, pauser, and operator. The owner can upgrade the contract and manage the other two roles, the operator sets the rate limit, the maximum transfer amount, and the rate limit window, and the pauser halts and resumes the contract. They have the following role assignments:
| Contract | owner |
pauser |
operator |
|---|---|---|---|
| EURC TokenManager (Arc) | EOA D | EOA E | EOA F |
| EURC TokenManager (Ethereum) | EOA G | EOA H | EOA I |
| Cross Chain Token Service (Arc) | EOA A | EOA J | EOA K |
| Cross Chain Token Service (Ethereum) | EOA L | EOA M | EOA N |
No multisig or timelock sits on any of these contracts, including the CCTS, which is the upgrade authority for all of them and the assigner of ownership for those that are unclaimed. Across the CCTPx deployment on both chains, sixteen distinct wallets hold the assigned roles. No wallet holds two roles, no wallet appears on both the Arc and the Ethereum side, and none of the sixteen matches any of the controlling wallets, masterMinter owners, or funded minters on the USDC, EURC, or cirBTC contracts.
4. Regulatory Risk
The regulatory risk has been previously discussed in detail as part of the EURC Base onboarding review. As there have been no material changes, that assessment remains applicable here.
Disclaimer
This review was independently prepared by LlamaRisk, a DeFi risk service provider funded in part by the Aave DAO. LlamaRisk is not directly affiliated with the protocol(s) reviewed in this assessment and did not receive any compensation from the protocol(s) or their affiliated entities for this work.
The information provided should not be construed as legal, financial, tax, or professional advice.

