pairbandOpen app

Threat model

Honest risk copy.

Before Stage B you can lose money on the curve. After Stage B the pool cannot be rugged of LP. A bad token still trades. This is not insured downside.

Stage B LP is burned

Graduation seeds Uniswap (or a PairbandPair fallback) and sends LP to 0xdead or a locker with no decreaseLiquidity path. There is no withdraw, no owner escape, no migrate.

Curve can still hurt you

Before Stage B, price is the bonding curve. You can be early, late, or last. Fees are taken in USDC. minAmountOut is required; failed swaps take no fee. This is not risk-free yield.

Invariants

  • Settlement chain is Arc. Only USDC moves cross-chain via CCTP.
  • No proxy / no delegatecall on the launch path.
  • Per-market vault isolation — one market cannot pay another.
  • Fee cap 2.00% in bytecode.
  • 1B supply; minting permanently disabled after Stage B.

Audit boundary (v1)

In scope: Settler, Launchpad + MarketVault, Token, Book, graduation handoff. Out of scope for first audit — do not ship on mainnet: Uniswap v4 PairbandHook, agent vaults, Gateway-specific code until the hook path matches CCTP, any messenger for launch tokens. Audit: not started.

Testnet addresses

Launchpad
0x22C23Efd9252177AfE02FE9dbd7D648369AF42f4
Settler
0x229BD1BcdE44c26E0c7741B46854Ccfb4e54CC40
AMM factory
0x0769121558BB51Fb71Edb933010D294D770e6e18
USDC (Arc)
0x3600000000000000000000000000000000000000

Verified source on Arcscan the day of deploy. Immunefi (or equivalent) bounty live the same day as mainnet — even if small.

Keys

The app never holds user keys. The deployer key lives only in the local ops file, never in public env vars, never in the browser.