# Circle EUR (EURC) on Aave Arc Assessments

**URL:** <https://governance.aave.com/t/circle-eur-eurc-on-aave-arc-assessments/25646>\
**Category:** Assessments\
**Created:** [September 15, 2026, 7:51pm UTC](https://governance.aave.com/t/circle-eur-eurc-on-aave-arc-assessments/25646 "2026-09-15T19:51:38Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![LlamaRisk](https://dub1.discourse-cdn.com/flex013/user_avatar/governance.aave.com/llamarisk/32/12865_2.png) [@LlamaRisk](https://governance.aave.com/u/LlamaRisk)\
**Post date:** [September 18, 2026, 2:35pm UTC](https://governance.aave.com/t/circle-eur-eurc-on-aave-arc-assessments/25646/3 "2026-09-18T14:35:05Z")

</div>

## Summary

EURC on Arc is deployed using the `FiatTokenV2_2` implementation. It can be bridged to Arc via both Circle Mint and CCTPx, Circle’s custom bridging framework for non-USDC assets, which uses a burn-and-mint mechanism. CCTPx leverages CCTP’s attestation infrastructure, Iris, alongside a dedicated CrossChainTokenService (CCTS) entry contract. The attestation threshold is 2-of-2 and controlled entirely by Circle.

The key findings include that access control across all contracts, including both the asset and bridge contracts in scope, relies on EOAs managed under Circle’s enterprise-grade key management program, which they claim maintains SOC 2 Type 2 attestation and follows NIST frameworks across the infrastructure. Further, no timelocks gate sensitive contract upgrades, consistent with Circle’s operational model for USDC and EURC on other networks. Additionally, the EURC bridge minter, represented by its TokenManager contract, does not pin its own implementation and instead resolves it through the CCTS singleton at call time. This means the CCTS owner ultimately controls the code executed by the TokenManager.

## 1. Asset Fundamental Characteristics

[EURC on Arc](https://explorer.arc.io/token/0xbEf5f6d51CB62b58e6A8f77868681825C6fe21c1) is deployed as an upgradable ERC20 `FiatTokenProxy` contract that uses the `FiatTokenV2_2` implementation contract. EURC is natively minted on Arc, with Circle Mint enabling minting and redemptions. Currently, bridging is supported via Circle’s new CCTPx protocol. Redemptions through Circle Mint are accessible only to qualified persons/businesses. The token’s design is consistent with other chains where EURC is listed on Aave.

### 1.1 Bridge Risk

EURC is bridged on Arc through Circle’s CCTPx protocol via a burn-and-mint mechanism. A dedicated [TokenManager](https://explorer.arc.io/address/0x8c27579e24f9f19d96724e19fc059dacd1469e10) was deployed on September 14, 2026 and holds mint and burn rights on the EURC contract, making the mechanism burn-and-mint on the Arc side. Verified users can also utilize Circle Mint as a bridge via its permissioned minting/redemption mechanism.

Circle extends its Cross-Chain Transfer Protocol (CCTP) to non-USDC assets by leveraging its core attestation infrastructure (Iris) alongside a dedicated [CrossChainTokenService](https://etherscan.io/address/0x431871229103b780868f8c6bb820cd16ecf942bc) (CCTS) entry contract. Instead of relying on traditional bridge liquidity pools, the protocol processes transfers using a burn-and-mint mechanism or permissionless wrapping.

#### Attester Threshold

Because CCTPx routes its messages through the existing CCTP contracts, message authenticity inherits CCTP’s 2-of-2 Circle-operated attester set.

#### Rate Limits

The TokenManager enforces a per-transfer ceiling of 862K EURC and a net-flow rate limit of 4.31M EURC in each direction over a rolling six-hour window.

## 2. Market Risk

### 2.1 Liquidity

Users can swap 610K EURC for $687K USDC within a price impact of 2%.

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/3/3fb2cf81754e8facc950822fc283e964e78f34c1.png)  
_Source: EURC/USDC Swap Liquidity on Arc,_ [_KyberSwap_](https://kyberswap.com/swap/arc/eurc-to-usdc)_, September 17, 2026_

#### 2.1.1 Liquidity Venue Concentration

On-chain liquidity for EURC on Arc is available on multiple venues, the most liquidity being [Uniswap V4 EURC/USDC 0.05%](https://app.uniswap.org/explore/pools/arc/0xeb0fd02fb8044d5514fb6e165ee134fd547eff0378bb33b76f4b81d8b03bd1ae) ($625K in TVL), [Uniswap V4 EURC/USDC 0%](https://app.uniswap.org/explore/pools/arc/0x126fa987e02395a28a6fdc9b7075799975a6d6f350e13515ae837f1f629c8731) ($585K in TVL), and [Aerodrome EURC/USDC](https://www.geckoterminal.com/arc/pools/0xbe080ac37ad1305dfcc9521f5e6f68cfdc41b7fa) pools ($375K in TVL).

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/aave/original/2X/5/58ddafd8158240189b650ae4e02b92a34ab1c711.png)  
_Source: EURC DEX liquidity pools on Arc,_ [_GeckoTerminal_](https://www.geckoterminal.com/arc/pools/0xeb0fd02fb8044d5514fb6e165ee134fd547eff0378bb33b76f4b81d8b03bd1ae)_, September 17, 2026_

#### 2.1.2 DEX LP Concentration

EURC LP concentration on Arc is moderately, with the top suppliers to the respective Uniswap V4 EURC/USDC pools, [EOA 1](https://debank.com/profile/0xa3367bf3879596fc37fec16a0c40b6f48325f5d6) and [EOA 2](https://debank.com/profile/0x4c69b794eb2a78c73db00e0241f41ae7de98f128), accounting for 73.28% and 67.6% of their respective pools’ liquidity. The top liquidity provider in the Aerodrome EURC/USDC pool is a [multisig](https://debank.com/profile/0x19cbc83ded190616d819555c3b42b3b3507fc41e) accounting for 80.12% of the pool’s total liquidity.

### 2.2 Volatility

As the Arc chain went live only two days ago, limited volatility data is available for EURC’s secondary market price. Therefore, no meaningful conclusions regarding its price stability can yet be drawn.

### 2.3 Exchanges

EURC is traded across [several CEXs](https://coinmarketcap.com/currencies/euro-coin/#Markets), though its trading activity and liquidity are predominantly concentrated on Coinbase.

## 3. Technological Risk

### 3.1 Smart Contract Risk

The bridge contracts were audited by third-party auditors. However, the reports were not publicly available at the time of review, preventing independent verification of the findings.

The following contracts power CCTPx bridge on the Arc chain:

- [CrossChainTokenService](https://explorer.arc.io/address/0x431871229103b780868f8c6bb820cd16ecf942bc): Upgradeable, ERC-1967 proxy. Singleton that creates bridges, routes cross-chain messages, and acts as both the upgrade authority and the ownership assigner for every CCTPx contract on Arc. Controlled by an [EOA A](https://explorer.arc.io/address/0xdfe2de0653f46331fbdcb2558ab513c37795545f).
- [CCTP MessageTransmitterV2](https://explorer.arc.io/address/0x81d40f21f12a8f0e3252bccb954d722d4c464b64): Upgradeable, ERC-1967 proxy. The underlying CCTP contract that verifies attester signatures on inbound messages and emits outbound ones. Controlled by an [EOA B](https://explorer.arc.io/address/0xb3ad729b38bf4d1257e224084322cb38edd74ed5).
- [FeeService](https://explorer.arc.io/address/0x88e0fee76fe71f467009dfddcfa759ddc6b1a575): Upgradeable, ERC-1967 proxy. Quotes and collects the cross-chain transfer fee. Controlled by an [EOA C](https://explorer.arc.io/address/0xede2dd51f54dbcb9f03abefbb7b9973d7d14e82a).
- [DeploymentDelegate](https://explorer.arc.io/address/0xd25ebea31f01b81c80960fa6f6351e0af9c21367): Immutable. Deploys new bridges and tokens on behalf of the service. No owner role.
- [TransferDelegate](https://explorer.arc.io/address/0xe98bc278d3cd5cedc8fbff511e807447fde273ff): Immutable. Executes the mint, burn, lock, and unlock legs of a transfer. No owner role.
- [FiatTokenDenylistAdapter](https://explorer.arc.io/address/0x3ebe1f103151890346cd7dbcec1c596cc50ef58e): Immutable. Service-wide denylist source. A view-only adapter that forwards `isDenylisted` to the Arc USDC contract’s `isBlacklisted`. No owner role, so the effective control sits with the USDC `blacklister`.

The EURC TokenManager contract is beacon proxy that resolve its implementation through the [Cross Chain Token Service](https://explorer.arc.io/address/0x431871229103b780868f8c6bb820cd16ecf942bc) singleton at call time as the local override is unset. Whoever controls the CCTS on a given chain can therefore change the code of every CCTPx TokenManager and CCTPx-issued token on that chain in a single action.

### 3.2 Access Control

The RBAC structure for Circle’s EURC contracts is configured similar to the USDC setup with different controlling wallets as follows.

| Controlling Wallet | Role | Functionality |
| --- | --- | --- |
| [EOA 1](https://explorer.arc.io/address/0x1B127715BB61d1561227748CABeAeF51A745F371) | `owner` | Re-assign any role except for `admin`. |
| [EOA 2](https://explorer.arc.io/address/0xB6839A2B63a8f832161D636EB666423197F8bE97) | `admin` | Manage proxy-level functionalities. |
| [EOA 3](https://explorer.arc.io/address/0xeA2F020633b235f14aaa24930238CC211F874e0B) | `pauser` | Pause the contracts, preventing all transfers, minting, and burning. |
| [EOA 4](https://explorer.arc.io/address/0x24584e31AdA775628f72DFea5829122Cf65a5C01) | `blacklister` | Prevent transfers to/from an address and prevent it from minting/burning. |
| [EOA 5](https://explorer.arc.io/address/0xb7850EFBcA3594E50977BD11a05833F18095e021), owner of the [masterMinter](https://explorer.arc.io/address/0x75F7E0800bB98aB6a965B0D9cb0Ff5C27355Bb57) contract | `masterMinter` | Add/remove `minters` and increase their minting allowance. |
| 15 minters are configured, with the following having non-zero allowance: [Minter1](https://explorer.arc.io/address/0x1067a3b05C6fbbEf0b68b7E2D33aDff7Dab3F9E6): 74,380,918.59 EURC, [TokenManager](https://explorer.arc.io/address/0x8c27579e24f9f19d96724e19fc059dacd1469e10): 41,315,963.99 EURC, and [Minter2](https://explorer.arc.io/address/0x178b6c719f1daea593d8a4f8979e4c67ed5a6d2d): 10,053.59 EURC | `minters` | Create/destroy tokens. |
| Unassigned | `rescuer` | Transfer any ERC-20 token locked in the contract. |

The TokenManager and CCTS contracts use a three-role structure of `owner`, `pauser`, and `operator`. The `owner` can upgrade the contract and manage the other two roles, the `operator` sets the rate limit, the maximum transfer amount, and the rate limit window, and the `pauser` halts and resumes the contract. They have the following role assignments:

| Contract | `owner` | `pauser` | `operator` |
| --- | --- | --- | --- |
| [EURC TokenManager (Arc)](https://explorer.arc.io/address/0x8c27579e24f9f19d96724e19fc059dacd1469e10) | [EOA D](https://explorer.arc.io/address/0x7dbaf9c6db35c489fd2ddc3503b9801887639289) | [EOA E](https://explorer.arc.io/address/0x34c1ee5e82e910a1405eedf6dfe5c37e548d99e7) | [EOA F](https://explorer.arc.io/address/0x3fafe0290aa8840b85050e30450b1fc4b5db6940) |
| [EURC TokenManager (Ethereum)](https://etherscan.io/address/0x8c27579e24f9f19d96724e19fc059dacd1469e10) | [EOA G](https://etherscan.io/address/0xa812f0a86f83701f1bc3d9b6ef737a45a046ee42) | [EOA H](https://etherscan.io/address/0x6a63f402f105bc9e0fbbc6c8fec7de1c8a68ea99) | [EOA I](https://etherscan.io/address/0x4cad66a227aa28277f91e7fa2142e03dd652f94d) |
| [Cross Chain Token Service (Arc)](https://explorer.arc.io/address/0x431871229103b780868f8c6bb820cd16ecf942bc) | [EOA A](https://explorer.arc.io/address/0xdfe2de0653f46331fbdcb2558ab513c37795545f) | [EOA J](https://explorer.arc.io/address/0x58bc35dd79c4f433ee56c7859f87586e015977c4) | [EOA K](https://explorer.arc.io/address/0xf3d063a9d5c1838d452b10472da191b5cedeb9f9) |
| [Cross Chain Token Service (Ethereum)](https://etherscan.io/address/0x431871229103b780868f8c6bb820cd16ecf942bc) | [EOA L](https://etherscan.io/address/0x568fb87a8559728007b88142688483214d678e82) | [EOA M](https://etherscan.io/address/0x0335894695dff4c58e59c950bcb317f488ef3ac4) | [EOA N](https://etherscan.io/address/0xae7ca7e1cc3e666fe12d72118b120a136ed99915) |

No multisig or timelock sits on any of these contracts, including the CCTS, which is the upgrade authority for all of them and the assigner of ownership for those that are unclaimed. Across the CCTPx deployment on both chains, sixteen distinct wallets hold the assigned roles. No wallet holds two roles, no wallet appears on both the Arc and the Ethereum side, and none of the sixteen matches any of the controlling wallets, masterMinter owners, or funded minters on the USDC, EURC, or cirBTC contracts.

## 4. Regulatory Risk

The regulatory risk has been previously discussed in detail as part of [the EURC Base onboarding review](https://governance.aave.com/t/arfc-add-eurc-to-base-aave-v3/20680/2#p-52486-h-41-governance-and-regulatory-risk-21). As there have been no material changes, that assessment remains applicable here.

## Disclaimer

This review was independently prepared by LlamaRisk, a DeFi risk service provider funded in part by the Aave DAO. LlamaRisk is not directly affiliated with the protocol(s) reviewed in this assessment and did not receive any compensation from the protocol(s) or their affiliated entities for this work.

The information provided should not be construed as legal, financial, tax, or professional advice.

---

_[View the full topic](https://governance.aave.com/t/circle-eur-eurc-on-aave-arc-assessments/25646)._
