Summary
LlamaRisk supports the onboarding of syrupUSDC to Aave V4 on Arc. syrupUSDC on Arc is a Chainlink CCIP representation of Maple’s Ethereum pool share, and its value, redemption and credit exposure all sit on Ethereum. The Arc market is very small and controlled by the issuer. Its supply of about 422,500 tokens is 0.05% of the total, Maple holds effectively all of it, and the single Uniswap V4 pool can absorb about $500,000 of selling before its USDC side is exhausted. Issuance on Arc can also be expanded by a 3-of-5 Safe with no delay, which Maple has committed to put behind a timelock.
syrupUSDC’s contract on Arc cannot be upgraded and matches the Base deployment Aave already lists, and because it has no pause function, blocklist or transfer fee, Maple has no way to block a liquidation or a repayment. Circle’s USDC blocklist, which Arc enforces on every transaction, remains the one control that can stop a listed address from bidding in a liquidation or repaying its debt. The bridge route is owned by Chainlink under its own timelock, so Maple cannot repoint it, and it carries the same bridge rate limits as every other syrupUSDC deployment.
The main residual risk is issuance, since the admin Safe can make any address a minter with immediate effect and the token has no supply ceiling, which would let that minter create unlimited supply on Arc in the next transaction. Base places the same contract behind a three-day timelock, and Maple has committed to the same arrangement on Arc. Redemption is the other gap, as Arc has no native redemption path and a holder exits either by selling into the single liquidity pool or by bridging to Ethereum and redeeming there, which takes two to five minutes end to end under normal conditions.
The initial supply cap of 25 million syrupUSDC, about $30 million, is sized to the bridge-and-redeem exit, which clears about $10 million an hour, and will be raised in stages as demand and liquidity develop. LlamaRisk will reassess if the committed timelock is not put in place or if Maple’s loan book inidcates liquidity stress.
1. Asset Fundamental Characteristics
1.1 Asset
syrupUSDC is a yield-bearing stablecoin backed by overcollateralized institutional loans underwritten and managed by Maple Direct. It is an immutable ERC-4626 vault on Ethereum whose shares carry a pro rata claim on the pool’s net asset value, with 6-decimal precision. The token does not rebase, and the share price rises as the pool earns. The vault manages approximately 1.00B USDC of lender deposits, the large majority of which is lent to institutional borrowers on open-term, overcollateralized loans, with the balance held as unallocated liquidity for redemptions and deployed into DeFi protocols on Ethereum, including Aave. The yield is the combination of loan interest and the return on those liquidity reserves. The asset’s design is described in full in the V3 Core onboarding assessment and is unchanged.
1.2 Architecture
The core architecture of syrupUSDC is unchanged from the V3 Core onboarding. Lender USDC enters the ERC-4626 pool share on Ethereum, the PoolManager funds open-term loans through its loan managers, and exits are served first-in-first-out by the WithdrawalManager queue. Underwriting and collateral management happen off-chain. Maple’s credit desk reviews borrowers, sets loan terms and runs margin calls, and borrower collateral is held in segregated wallets at third-party custodians including Anchorage Digital, BitGo and Zodia Custody. Net asset value accounting and redemption run on Ethereum, in the pool and its WithdrawalManager. None of this is deployed on Arc, which carries only the bridged token.
Source: LlamaRisk
Arc supply is bridged, not issued. Chainlink’s Cross-Chain Interoperability Protocol (CCIP) runs the route on a lock-and-mint basis: shares lock in the LockReleaseTokenPool on Ethereum, and the BurnMintTokenPool on Arc, which holds the token’s minter and burner roles, mints the matching amount. The return leg burns on Arc and releases on Ethereum. Ethereum is the Arc pool’s only configured lane, so Arc syrupUSDC cannot move directly to any of the seven other chains carrying the token and has to transit Ethereum in both directions.
The Arc token is a non-upgradeable ERC-20 with 6 decimals. It doesn’t sit behind any proxy. The token and the Arc token pool are both source-verified on the Arc explorer. The token’s runtime is identical to Base syrupUSDC, and the pool runs Chainlink’s BurnMintTokenPool 2.0.0.
Redemption is currently unavailable on Arc. Maple’s cross-chain receiver, which redeems in a single message for holders on Base, Arbitrum and Solana, does not accept Arc. That receiver supports only CCIP version 1, and Maple plans a replacement mint and redeem contract on CCIP version 2 for all its chains, expected around the first quarter of 2027. An Arc holder converting back to USDC bridges the position to Ethereum and redeems there. Maple puts the bridge leg at about 1.5 minutes and the redemption at a median of 3.5 minutes, for two to five minutes end to end in normal conditions.
1.2.1 Cross-chain Deployments and Bridge Scope
syrupUSDC is native to Ethereum and reaches eight further chains over Chainlink CCIP, of which Arc is the deployment under assessment.
| Chain |
Token address |
Bridge stack |
Aave status |
| Ethereum |
0x80ac24aA929eaF5013f6436cdA2a7ba190f5Cc0b |
native (ERC-4626) |
not listed (onboarding recommended) |
| Arc |
0x0dC6b79F3c3854E4d74514fD4d29BE6c96Beee39 |
CCIP |
planned (V4 Arc) |
| Base |
0x660975730059246A68521a3e2FBD4740173100f5 |
CCIP |
listed (V3 Base) |
| Monad |
0xaB6e5a0C3799d020c790D34F7B2C02639e238AF7 |
CCIP |
listed (V3 Monad) |
| Arbitrum |
0x41CA7586cC1311807B4605fBB748a3B8862b42b5 |
CCIP |
not listed |
| Ink |
0x3c23e6FB09064e9A64829Fa8FEe27Ad19A27Bfa9 |
CCIP |
not listed |
| Robinhood |
0xC6a4854eeB493224d5f9485E12Dd3A81f22EEE14 |
CCIP |
not listed |
| Tempo |
0x20c0000000000000000000008191667423F70E67 |
CCIP |
not listed |
| Solana |
AvZZF1YaZDziPY2RCK4oJrRVrbN3mTD9NL24hPeaZeUj |
CCIP |
not listed |
Source: Etherscan, September 23, 2026
1.3 Tokenomics
syrupUSDC has no issuance path on Arc. Supply there grows only when shares are locked on Ethereum, so the Arc float is a claim on tokens in the Ethereum bridge pool, which holds 203,342,206 syrupUSDC against all eight remote chains. The locked balance is the ceiling on what Arc can carry, and it comes out of 846,312,080 shares outstanding on Ethereum. Arc carries 422,521.58 syrupUSDC, 0.2% of the bridged float and 0.05% of total supply.
The token does not rebase and has no supply cap of its own, so a holder’s balance moves only on transfer and the yield reaches them through the rising Ethereum share price.
1.3.1 Token Holder Concentration
Nine addresses hold syrupUSDC on Arc and Maple controls effectively all of the supply. The largest balance, 92.16%, is the liquidity of the single syrupUSDC/USDC pool held in the Uniswap V4 PoolManager, and a Maple-controlled wallet owns 99.999% of that liquidity. The same wallet holds another 7.83% directly, which puts 99.997% of Arc supply behind one externally owned account. The other seven holders carry 6.63 syrupUSDC between them, and no third party holds a material balance on Arc.
Source: Arc Explorer, September 23, 2026
The Uniswap V4 PoolManager controls 92.16% of supply, the top five control 99.99%.
2. Market Risk
2.1 Liquidity
Selling 845,515 syrupUSDC, about $1 million, into Arc USDC clears at 50.00% price impact. The route exhausts the pool’s USDC at roughly $500,000 of proceeds, and larger sales return the same amount. A sale of 211,379 syrupUSDC, about $250,000, costs 0.19%, and the whole Arc float of 422,521 syrupUSDC costs 0.39%. Impact crosses 4% at 440,000 tokens. Single-clip liquidation capacity on Arc is therefore around $500,000, which is the size of the entire Arc float.
Source: KyberSwap, September 23, 2026
2.1.1 Liquidity Venue Concentration
All indexed Arc liquidity for syrupUSDC sits in a single Uniswap V4 pool, a syrupUSDC/USDC pair at the 0.05% fee tier holding $961,000 and opened on September 16, 2026. No second venue is indexed, and KyberSwap’s router sends every quoted size through that one pool. The pool runs without a hook, so no external contract can intercept or halt its swaps. Secondary trading is close to dormant, at $4.77 of volume over the past day. About $500,000 of the pool sits on the USDC side, and that is the balance a liquidator draws against. Venue concentration is total, and a contract failure or a liquidity-provider withdrawal at this pool removes Arc liquidation capacity outright.
2.1.2 DEX LP Concentration
Arc liquidity sits in two Uniswap V4 positions. A Maple-controlled wallet holds 99.999% of the pool’s active liquidity, 389,409 syrupUSDC and 500,004 USDC across ticks 1605 to 1755, and the remainder is a 3.8 syrupUSDC position from an unattributed wallet opened in the pool-creation transaction. Both were funded on September 16, 2026 and neither has been modified since. The same Maple wallet holds a further 33,100 syrupUSDC outside the pool, which puts 99.997% of the Arc float and effectively the whole trading venue behind one externally owned account, and that account is also the dominant syrupUSDC liquidity provider on the other chains where the token trades. Depth on Arc is issuer-supplied, so Maple alone decides whether the venue stays funded, and nothing locks or vests the position against that decision.
2.2 Volatility
The Arc pool has quoted syrupUSDC at 1.18329 USDC since the liquidity was placed, unchanged to the seventh decimal. The Ethereum exit rate accretes daily, so the Arc quote’s discount to redemption value widens alongside it at about 1.4 bps a day, from under 2 bps on September 17, 2026 to just under 10 bps on September 23, 2026, with a median below 6 bps and no reading near 25 bps. Almost nothing trades through the pool to reprice it, and the arbitrage that would close the gap needs a bridge transfer to Ethereum followed by a place in the withdrawal queue. The discount is a static quote measured against an accreting redemption value, with no credit or liquidity event behind it.
Source: Arc explorer and Etherscan, September 23, 2026
On Ethereum, where syrupUSDC has traded for over a year, the secondary market holds a mean discount of roughly 9 bps against the same exit rate. Its widest deviation was 22 bps on April 20, 2026, during a market-wide repricing around the Kelp exploit that carried no Maple-specific catalyst, and it recovered to the prior level. The Arc readings sit inside that envelope.
A sub-10 bps discount is an order of magnitude smaller than the cost of clearing the whole Arc float through the single pool, so depth sets the loss on an Arc liquidation.
2.3 Exchanges
syrupUSDC has no centralized-exchange listing on any chain and trades only on decentralized venues, unchanged from our Aave V3 Core onboarding review. CoinGecko indexes sixteen syrupUSDC pairs spread across Ethereum, Solana, Monad, Base and Arbitrum, carrying about $1.1 million of daily volume with 86% of it on the three largest, and it carries no Arc pair.
2.4 Growth
syrupUSDC launched on Arc on September 9, 2026, too recent for a meaningful growth history. Supply sat at 8.55 syrupUSDC for the first week and then moved in a single step on September 17, 2026 to 422,521.58 syrupUSDC. One inbound bridge transfer into Maple’s liquidity wallet. The only transfer since added 100 syrupUSDC on September 25, 2026, bringing supply to 422,621.58.
3. Technological Risk
3.1 Smart Contract Risk
Maple’s contracts carry eighteen audit reports across eight release cycles by seven firms (Trail of Bits, Spearbit, Three Sigma, 0xMacro, Sherlock, Dedaub and Sigma Prime), indexed on Maple’s security page and held in the core protocol and cross-chain receiver repositories. Severity counts below are the issuer’s reported figures. The six most recent reports:
The Arc deployment introduces no Maple code. The bridge side is Chainlink’s, and Maple’s audits do not extend to it. The Arc token pool runs BurnMintTokenPool from CCIP 2.0.0, released on June 18, 2026. Chainlink states its standard token pools are audited, and the most recent public audit report of the pool contracts covers version 1.5, from July 2024.
No publicly documented smart contract incident, exploit or upgrade failure is located as of September 23, 2026.
3.2 Bug Bounty Program
Maple runs a live bug bounty on Immunefi paying up to $500,000 for a critical smart contract vulnerability, calculated as 10% of the funds affected with a $50,000 floor, and a flat $25,000 at high severity. A proof of concept and know-your-customer (KYC) verification are required for payout. The scope is 43 Ethereum addresses covering the pool, loan and withdrawal manager stacks, the yield strategies and the GovernorTimelock added in November 2025, with the syrupUSDC pool listed for reference and ERC-4626 compliance issues excluded. No Arc address is in Maple’s scope. The Arc token and both CCIP pools run unmodified Chainlink code, which Chainlink’s own Immunefi programme covers under its CCIP scope, with a maximum payout of $3,000,000.
3.3 Price Feed Risk
Chainlink publishes a syrupUSDC/USDC exchange rate feed on Arc on a 24-hour heartbeat with a 0.05% deviation threshold, alongside a USDC/USD feed. No Chainlink Proof-of-Reserve feed covers Maple’s loan book. Arc holds no net asset value accounting, so the exchange rate reaches the chain only through that feed. Pricing on Arc resolves to a Capped Adjustable Price Oracle (CAPO) adapter combining the exchange rate feed with the capped USDC/USD feed Aave already uses there. This is the design Aave runs for syrupUSDC on Base and Monad, where the Chainlink exchange rate feed carries the Ethereum vault’s exit rate, convertToExitAssets, which is net of unrealised losses, so a loan impairment lowers the price Aave reads.
3.4 Dependency Risk
syrupUSDC’s value is set entirely on Ethereum, and those dependencies are unchanged from the V3 Core onboarding. Maple Direct underwrites, prices and manages every loan in-house, and borrowers post liquid digital assets against open-term loans, so the share price rests on that collateral’s quality and on a single internal credit desk. The pool holds 99.3% of its $1.00 billion of assets in those loans, recognises no unrealised losses and no balance in its DeFi yield strategies. Arc introduces no Maple contract and no additional credit dependency.
Arc syrupUSDC depends on Chainlink CCIP to move between Arc and Ethereum. Messages are signed by a sixteen-operator Decentralized Oracle Network, and a separate Chainlink Risk Management Network can pause the lane in an emergency. A paused Ethereum to Arc lane leaves Arc balances intact and transferable, since the token is an ordinary ERC-20, but it cuts off the only path from an Arc position to redemption and the only way new supply reaches Arc.
Arc is a standalone Layer 1 and inherits no settlement guarantee from a base chain. Its consensus is a Byzantine Fault Tolerant protocol over a permissioned Proof of Authority validator set that Circle whitelists, and a block is final once more than two thirds of validators commit it, with no staking or slashing behind that commitment. Liveness needs more than two thirds of the set online, so an outage across a third of a small validator group stops the chain and every liquidation on it, and because finality is irreversible, a colluding two thirds could commit a block that cannot be undone. Circle holds protocol upgrade authority over the network, with no upgrade timelock and no published change-management process for consensus-layer upgrades.
USDC is Arc’s gas asset as well as the asset borrowed against syrupUSDC. Arc enforces the USDC blocklist at the execution layer, so a blocked address cannot transact at all. A liquidator on that list cannot bid and a borrower on it cannot repay, and the list is Circle’s to write.
Redemption runs on Ethereum, is open to any holder, and carries no deposit, redemption or spread fee. Redemption requests wait in line and are paid, first in first out, as USDC comes back into the pool. Most redemptions have cleared in under an hour, and a stressed queue can run to 30 days. Instant capacity is the pool’s 7.4 million USDC of cash, 0.7% of its assets, beyond which redemption waits on loan repayments or on called principal, where the borrower’s notice period runs to 30 days and can be shortened to two.
Arc offers no direct redemption path. An Arc holder would bridge to Ethereum and redeem there. Maple puts the bridge leg at about 1.5 minutes and the redemption at a median of 3.5 minutes, for two to five minutes end to end in normal conditions, and the queue governs anything beyond the pool’s cash. Bridge transfers on the route are limited to about $10 million an hour, refilling continuously, and a transfer above the remaining limit is rejected. Maple can raise the limit temporarily and offers over-the-counter alternatives during market events. There is a Uniswap V4 pool, whose USDC side saturates near $500,000 for secondary market exits, which liquidators can utilize.
Maple runs a single-message redemption route for other remote chains, and Arc is not on it. The Maple cross-chain receiver on Ethereum takes syrupUSDC sent over CCIP, files the redemption in the same withdrawal queue under its own name, and once the queue serves the request a Maple redemption executor sends the USDC back to the chain it came from. It accepts Base, Arbitrum and Solana only, all three enabled on January 29, 2026, and supports only CCIP version 1. Maple plans a replacement contract on CCIP version 2 for all its chains, including Arc, expected around the first quarter of 2027. The route charges no deposit or redemption fee and has no per-request size limit, so the only cap on its flow is the Ethereum pool’s inbound CCIP bucket of 9,482,758 syrupUSDC an hour. It saves the holder the return bridge and a separate Ethereum transaction. Usage is negligible, at three requests of under one share each, all on February 3, 2026, each executed on Ethereum within six minutes of arrival. Maple’s operational 3-of-5 holds the receiver’s admin role and can add a chain, set fees, switch redemptions off or upgrade the contract with immediate effect.
3.5 Bridge Risk
Arc syrupUSDC is a Chainlink Cross-Chain Interoperability Protocol (CCIP) representation of shares escrowed on Ethereum, and Ethereum is the only remote peer the Arc token pool recognises. Shares are locked on Ethereum and minted on Arc on the way in, and burned on Arc and released on Ethereum on the way out. The Ethereum pool escrows 203,342,206 syrupUSDC and can grow that balance only by locking, since it accepts no external liquidity and has no rebalancer, and every syrupUSDC in circulation on Arc was minted through the Arc pool against a share locked there. Supply minted outside the bridge would carry no such backing, which is the risk a direct minter grant creates.
| Field |
Ethereum to Arc |
| Bridge stack |
Chainlink CCIP, OffRamp 1.6.0 |
| Custody mechanism |
Lock-and-mint into Arc, burn-and-release back to Ethereum. LockReleaseTokenPool 1.5.1 on Ethereum, BurnMintTokenPool 2.0.0 on Arc |
| Verifier set |
Committing Decentralized Oracle Network of 16 node operators, tolerating up to 5 faulty operators |
| Threshold |
6 of 16 on-chain signatures, 11 of 16 off-chain agreement |
| Verifier path |
One OffRamp registered in the Arc Router, signer set owner-gated under Chainlink’s Arc timelock, 3-hour minimum delay |
| Rate limits |
Ethereum leg 8,620,689 syrupUSDC outbound and 9,482,757.9 inbound, each refilling in one hour, the same as every syrupUSDC lane. Arc leg none |
| Verdict |
Passes the rate-limit, consensus-threshold, pinned-verifier and no-single-party standards |
Source: Etherscan and Arc Explorer, September 23, 2026
The committing network signs a Merkle root of each message batch, needing 6 of its 16 signatures on the destination chain and agreement from 11 of 16 operators before the root leaves the network. Execution reports carry no signature check of their own, so the commit fixes the integrity of every message in the batch. Risk Management Network signature checks are switched off on both legs of the lane, so that network’s only power over the route is the emergency pause, and no pause is active on either chain.
Nothing on the issuer’s side can repoint the lane. The Arc router, off-ramp and token registry resolve to a single owner, Chainlink’s Arc timelock. Normal configuration changes on that timelock wait at least three hours. Chainlink also holds a bypasser role on it for emergencies, which executes changes immediately. That timelock also owns the syrupUSDC pool on Arc, and Chainlink’s Ethereum timelock owns the pool on Ethereum, so pool ownership on both legs sits with Chainlink and Maple’s own authority over the route is one role on the Ethereum pool.
The route’s rate limit sits on the Ethereum leg. The Ethereum pool’s buckets hold 8,620,689 syrupUSDC outbound and 9,482,757.9 inbound, each refilling in an hour, and the same two figures apply to all 8 of its lanes, including Base and Monad, where Aave already lists syrupUSDC. The limits are in line with standard bridge rate limiting. The Arc pool runs CCIP 2.0.0, which carries no limiter of its own, so the Ethereum buckets meter the route in both directions. Maple’s 3-of-5 operational admin Safe holds the rate-limit admin role and can retune both buckets with immediate effect, outside the Chainlink timelock. At about $10 million an hour, this route is the exit for liquidations larger than the single pool can absorb.
Delivery into Arc waits on Ethereum finality of roughly 15 minutes plus the commit and execute rounds. The return leg clears faster, at about 1.5 minutes from Arc to Ethereum by Maple’s figures, and lands a holder at Ethereum redemption.
3.6 Technical Risk Summary
Strengths
- The Arc token is a non-upgradeable ERC-20. It sits behind no proxy and has no implementation contract and no proxy admin, so its code is fixed for the life of the deployment. Its runtime is identical to Base syrupUSDC, which Aave already lists.
- The token carries no transfer fee, no blocklist, no allowlist and no pause, and no setter can introduce one, so Maple has no power to stop a supply, withdrawal, repayment or liquidation of syrupUSDC on Arc. Burning spends an allowance like any other spender, so a holder’s balance cannot be seized.
- Maple’s contracts carry eighteen audit reports by seven firms across eight release cycles, the newest from January 2026 with no critical issue left open, and the Arc deployment adds no Maple code.
- A live Immunefi programme pays up to $500,000 for a critical vulnerability in the Ethereum contracts that set the share price, and the Arc token and pools run unmodified Chainlink code covered by Chainlink’s own programme, which pays up to $3,000,000.
- Nothing on the issuer’s side can repoint the bridge route. One off-ramp is registered in the Arc router, the router, off-ramp and token registry all resolve to a Chainlink-controlled timelock, and message integrity needs 6 of 16 signatures on chain and agreement from 11 of 16 operators off chain, with no single-party verifier.
- The admin Safe can stop Arc issuance in one transaction. Revoking the token pool’s mint and burn roles takes effect immediately, which halts the bridge in both directions if the lane or the pool is compromised.
Weaknesses
- New minters can be added to the Arc token without notice. The 3-of-5 admin Safe grants roles with immediate effect, the token has no maximum supply and no mint throttle, and the bridge rate limit meters only the bridge path, so one role grant expands Arc supply without limit and without matching shares locked on Ethereum. No minter other than the bridge pool has ever been granted. Base deployment puts the same token contract’s admin behind Maple’s GovernorTimelock, which applies a three-day delay. Maple has committed to put role grants on the Arc token behind a timelock, as on Base.
- Three signatures on one Maple Safe are the whole safeguard on the Arc mint path. The same Safe and signer set also administers syrupUSDT on Plasma and holds the CCIP admin slot for syrupUSDC on Base, so a compromise of its keys reaches several deployments at once.
- The exchange rate falls as well as rises. A borrower default or an impaired loan raises the pool’s unrealised losses and cuts the rate with no delay and no floor, and Maple’s own administrators can impair a loan. The Chainlink feed carries that fall onto Arc on a 24-hour heartbeat with a 0.05% deviation threshold, so a drop smaller than 5 basis points can take a day to reach the Arc liquidation price.
- Arc offers no redemption path. An exit means bridging to Ethereum and redeeming there, two to five minutes end to end in normal conditions by Maple’s figures, and a bridge transfer above the hourly limit of about $10 million is rejected outright. Beyond the pool’s 7.4 million USDC of cash, 0.7% of its assets, redemption waits on loan repayments or called principal with a borrower notice period running to 30 days. A halted lane suspends that route entirely.
Recommendations
- Maple committed to put role grants on the Arc token behind a timelock.
4. Counterparty Risk
4.1 Governance and Regulatory Risk
The legal structure, issuing entities and regulatory analysis of syrupUSDC are covered in our V3 Core onboarding assessment, and our July 17, 2026 update found no material change since.
4.2 Access Control Risk
4.2.1 Contract Modification Options
On Ethereum the control surface is split four ways: a role-based GovernorTimelock over protocol-wide parameter and role changes, a Maple-controlled PoolDelegate multi-party computation (MPC) wallet holding upgrade rights over the PoolManager, the withdrawal queue and the loan managers, a 3-of-6 SecurityAdmin Safe that can pause the protocol, and a 3-of-5 OperationalAdmin Safe over a subset of operational functions. The Core onboarding assessment sets out that arrangement and the contracts beneath it.
None of it reaches Arc. The Arc token has no upgrade path, so its only modification surface is a role registry, and that registry is administered by a Safe deployed for this chain. The same Safe holds the CCIP admin slot, which registers the token with Chainlink’s token admin registry. Mint and burn rights sit with the Arc token pool, and the pool is in turn owned by a role-based timelock running Chainlink’s Many-Chain Multi-Sig (MCMS) stack.
| Controlling address |
Role |
Functions |
| 0xdd2D33f35D4D46c5Ec6e6351907964a6ECd49EC9 |
DEFAULT_ADMIN_ROLE |
grantRole, revokeRole over every role including its own, setCCIPAdmin |
| 0xdd2D33f35D4D46c5Ec6e6351907964a6ECd49EC9 |
CCIP admin |
registration with the CCIP token admin registry |
| 0x6be14e674f741faa78da2fecf00870c8b753a0bb |
MINTER_ROLE |
mint |
| 0x6be14e674f741faa78da2fecf00870c8b753a0bb |
BURNER_ROLE |
burn, burnFrom |
| 0x3eC62564F66874f619640cBb7Fd42A157f21A442 |
owner of the Arc token pool |
applyChainUpdates, addRemotePool, removeRemotePool, transferOwnership |
Source: Arc explorer, block 22,354,550, September 23, 2026
These are the token’s only role holders. The Arc pool is its only minter and burner, and no other minter has ever been granted.
The token deducts no fee on transfer and carries no setter that could introduce one, balances move only when tokens move, and the code contains no blocklist, no allowlist and no pause. No power Maple holds can stop a transfer on Arc, so supply, withdrawal, repayment and liquidation remain available to an Aave market. The one transfer restriction on Arc sits at the chain level, where Circle’s USDC blocklist stops a listed address from transacting at all. Burning is allowance-gated, meaning the burner role spends an approval like any other spender and cannot reach a balance that has not approved it, so holder positions cannot be seized. There is no ownership to renounce, and a role holder can drop its own role, so the admin Safe can abandon DEFAULT_ADMIN_ROLE and freeze the registry in place with no route back.
Issuance is where the exposure sits. The token has no maximum supply and no mint throttle, and the rate limit that meters bridged supply, a bucket of 8,620,689 syrupUSDC refilling at 2,394 per second, sits on the Ethereum side of the lane and governs only the bridge path. A minter granted directly by the admin Safe is subject to neither bound, so a single role grant can expand Arc supply without limit and without matching shares locked on Ethereum. The same Safe can revoke the pool’s mint and burn rights in one transaction. That is the emergency brake on a compromised lane, and it also closes the route in both directions, leaving Arc balances with no path back to Ethereum until the rights are restored.
4.2.2 Timelock Duration and Function
No timelock governs the Arc token. Role changes by the admin Safe take effect in the transaction that authorises them. For revocation of minter role, that is the intended design since cutting off a compromised minter or pool cannot wait. For granting minter role, nothing stands between a signer quorum and a new minter with unlimited issuance. Base syrupUSDC runs the same contract with its admin role held by Maple’s GovernorTimelock, whose default delay is three days against a one-day floor. Maple has committed to put role grants on the Arc token behind a timelock in the same way.
The Arc token pool is the one contract with a delay. Normal changes by its owner wait at least three hours between scheduling and execution. Chainlink also holds a bypasser role on the same timelock for emergencies, which skips the delay. Chainlink holds the proposer, executor, canceller and bypasser roles through its Many Chain Multisig (MCMS) contracts, so lane configuration is under Chainlink’s control and three hours is the longest notice period anywhere in the Arc deployment.
4.2.3 Multisig Threshold and Signer Composition
The admin Safe is Safe version 1.4.1 at a 3-of-5 threshold, owned by:
Maple controls this Safe. The same address, with the same five owners and 3-of-5 threshold, administers syrupUSDT on Plasma and holds the CCIP admin slot for syrupUSDC on Base. Three signatures are the whole safeguard on the Arc mint path.
Disclaimer
This review was independently prepared by LlamaRisk, a DeFi risk service provider funded in part by the Aave DAO. LlamaRisk is not directly affiliated with the protocol(s) reviewed in this assessment and did not receive any compensation from the protocol(s) or their affiliated entities for this work.
The information provided should not be construed as legal, financial, tax, or professional advice.