Skip to content

Ryntra on Arc · Reviewer evidence

Everything behind the claim, in one document.

TESTNET VERIFIED — direct-EOA ERC-20 USDC transfer only. Every settlement figure on this page — amount, fee, block, hashes, statuses — is read from that run rather than typed into the markup. The product itself is at ryntra.io/arc.

The recorded run, field by field.

One direct-EOA ERC-20 USDC transfer on Arc Public Testnet, authorized and signed by the wallet owner, reconciled against the chain and sealed into a receipt whose hash and integrity digest were recomputed independently of the application.

Ryntra Guard · Arc PackArc Public Testnet
You are about to send1.000000 USDC
To
0x4DdD…f6238
Network
Arc Public Testnet · 5042002
Network fee
0.001548973026 USDC
Evidence
Fresh · valid for 120 seconds
  • Correct network detected
  • Balance and fee read from the chain
  • Total stays under your 100 USDC limit
  • Recipient and exact call data locked to this approval
DecisionALLOWED BY POLICY

What you see while your wallet is still closed.

Network
Arc Public Testnet · eip155:5042002
Supported operation
Direct-EOA ERC-20 USDC treasury transfer, plus one recorded Circle App Kit USDC→EURC swap (2026-08-12, reconciled MATCHED). In-product swap execution remains disabled.
Custody boundary
Non-custodial. Ryntra never receives a private key, seed phrase, entity secret or withdrawal authority.
Authorization actor
The wallet owner, acting in their own wallet, after inspecting the exact payload.
Decimal handling
Native Arc USDC 18 decimals; ERC-20 USDC 6 decimals. Converted with decimal strings and BigInt.
Arc Transaction Memo
memoSupported: false. No SCA, Safe or ERC-4337 memo support is claimed, and no receipt or personal data goes onchain.
Intent / preflight ID
int_58e9bf523de5438c9bc118b5ec1e7dd1 · preflight 0xb9d52657e4ed10933e63b57adf597f8d1f75d7055d87206570155e92a0ae799c
Evidence status and freshness
COMPLETE. Evidence root 0x24aaa5bdc8db9129e87f3c4df03a2d0109b596375450d6d9a3883254d01e50fe, provider Arc Testnet JSON-RPC, validity window 120 seconds.
Policy decision and policy version
ALLOWED_BY_POLICY under demo-arc-usdc-transfer-policy v1, digest 0x4134277b4a9b0660f8844de8aebb2b59f491d4e4138a52a9da6a7ebab257f8aa.
Human authorization
APPROVED. PARTNER_AUTHENTICATED, recorded separately from the wallet signature
Execution fingerprint
0x9dc7552c2cc6271474c89bd1930aec1cdbda01549b7b0d707cabe31e28ee93ed — exact target, calldata and zero native value bound before signing.
Expected effects
Out 1.000000 USDC, fee 0.001548973026 USDC.
Transaction hash and Arc Explorer link
0x6476dc81a38f0cbe385eab5162f391d7954a992a443db7d268e07b2698b8d5f9 — block 55677295, SUCCESS (0x1). https://testnet.arcscan.app/tx/0x6476dc81a38f0cbe385eab5162f391d7954a992a443db7d268e07b2698b8d5f9
Actual effects
Out 1.000000 USDC, fee 0.001530838950 USDC — read back from the chain, not from the estimate.
Execution status
CONFIRMED
Reconciliation status and tolerance
MATCHED · ONCHAIN_VERIFIED. Exact match required on sender, contract target, calldata digest, zero native value, transfer sender, transfer recipient and amount.
Arc dual-event hazard
Arc emitted this single movement as two Transfer events — 1000000000000000000 from the native precompile at 18 decimals, and 1000000 from the ERC-20 interface at 6. Reconciliation reads only the ERC-20 log, so the recorded amount is 1.000000 USDC rather than a 10^12 error.
Receipt ID / integrity
rcpt_b6b010ec3d5e4be19b4c26cdfce28e73 · receiptHash 0xb1530b1273adf5efd0a41ab194546da2c17f58d1842384a281dac173478e64f2 · SHA-256 integrity 0xed006ede12c4e99648a089e401a661d4e7d8c6c9afe5a0ea9892228327ebd1fe. Both were recomputed independently of the application from the stored receipt.
Repository and reproducibility
https://github.com/ryntra-io/ryntra-arc-demo — bounded MIT snapshot at b8af07a0f2e7216fc972756a1af84f91ea688298, not the exact local candidate. Bounded public extraction; it predates the corrective candidate and does not prove source or deployment parity.

Three evidence frames.

Before, settlement and after — each carrying its own truth label, because a frame without one invites the reader to assume it is a live capture.

RECORDED RUN · CAPTURE PENDING

01 · Before — Intent, Evidence, Decision

  • Direct-EOA ERC-20 USDC transfer of 1.000000 USDC on Arc Public Testnet
  • Evidence COMPLETE, root 0x24aaa5bdc8db9129…
  • No missing or stale evidence; validity window 120 seconds
  • Policy demo-arc-usdc-transfer-policy v1 → ALLOWED_BY_POLICY
  • Expected fee 0.001548973026 USDC
RECORDED RUN · CAPTURE PENDING

02 · Settlement — Human authorization and Arc result

  • Authorization recorded separately from the wallet signature
  • Execution fingerprint 0x9dc7552c2cc62714… bound before signing
  • Transaction 0x6476dc81a38f0cbe… — SUCCESS (0x1)
  • Block 55677295, Arc Explorer link published
RECORDED RUN · CAPTURE PENDING

03 · After — Reconciliation and Receipt

  • Expected fee 0.001548973026 USDC versus actual 0.001530838950 USDC
  • MATCHED · ONCHAIN_VERIFIED
  • Execution CONFIRMED, recovery NOT_REQUIRED
  • Receipt rcpt_b6b010ec3d5e4be19b4c26cdfce28e73, hash and integrity independently recomputed

Current evidence state, stated exactly.

The recorded proof covers the one operation that completed the whole lifecycle on Arc Public Testnet and nothing wider. Anything not covered by it carries its own weaker label. The last four rows have no registry record on purpose: nothing was proven, so there is nothing to register.

CapabilityStatusWhat that covers
Arc Testnet connectionTESTNET VERIFIEDCorrect network and chain id confirmed against the chain.
USDC treasury transferTESTNET VERIFIEDOne real direct-EOA ERC-20 transfer settled end to end.
Preflight and policyTESTNET VERIFIEDExact action and versioned policy evaluated before authorization.
Human authorizationTESTNET VERIFIEDRecorded separately from the policy result and from the signature.
Wallet signatureTESTNET VERIFIEDPerformed by the key holder. Ryntra observes the resulting hash, not the act.
Transaction trackingTESTNET VERIFIEDConfirmed and linked to a public Arc Explorer record.
Expected versus actualTESTNET VERIFIEDReconciled from chain data; the fee difference is recorded.
Execution receiptTESTNET VERIFIEDFinalized only after confirmation, hash and integrity recomputed independently.
USDC to EURC swapIN BUILDImplemented in source. No real swap has ever executed.
Bridge and unified balanceIN BUILDVisible in the product and deliberately disabled.
Reliability under loadIN BUILDOne successful run is not a reliability claim.
Arc mainnetNOT VERIFIEDModelled in the network registry and not selectable. No mainnet claim.

Arc chain mechanics that changed the design.

Gas is paid in USDC

Arc has no separate native gas token, so the cost of an action and the action itself are the same currency. The workspace shows one financial picture instead of two.

One balance, two interfaces

Arc keeps a single USDC balance behind an 18-decimal native accounting view and a 6-decimal ERC-20 transfer interface. Ryntra distinguishes them everywhere and never adds them.

The double-count hazard, confirmed

Arc emitted this single movement as two Transfer events — 1000000000000000000 from the native precompile at 18 decimals, and 1000000 from the ERC-20 interface at 6. Reconciliation reads only the ERC-20 log, so the recorded amount is 1.000000 USDC rather than a 10^12 error.

Deterministic finality

One confirmation is final on Arc, so there is no countdown to wait through — but a receipt still waits for reconciliation, because confirmed is not the same as matched.

The questions reviewers actually ask.

Can Ryntra move my money?

No. Ryntra prepares, checks and reconciles. The signature and the broadcast happen in a wallet you control, and Ryntra never receives a seed phrase, a private key or withdrawal authority.

What has actually run on Arc?

One direct ERC-20 USDC transfer on Arc Public Testnet, executed by the wallet owner, reconciled against its expected effects and sealed into a receipt. Every settlement figure on this page — amount, fee, block, hashes, statuses — is read from that run rather than typed into the markup.

Is the swap live?

No. The request and the deterministic preflight are implemented against the provider contract, and execution stays disabled. No swap has been verified end to end, and nothing on this site says otherwise.

Why is there no chain-wide analytics?

Because no indexer runs yet. Block time, gas in USDC, throughput, contract coverage and address activity need one with a stated backfill window, so they are named as unmeasured rather than estimated.

Do I need an account?

No. The Hub is reachable without one. A wallet adds address-scoped reads and is required before any authorization step; a Ryntra account adds the cabinet and the journal.

Is this mainnet?

No. Everything here is Arc Public Testnet, where no real value moves. Mainnet is a separate release programme and never arrives through a network dropdown.

Scope and limitations

  • Public Testnet prototype.
  • No custody or private-key access by Ryntra.
  • No autonomous signing by Ryntra.
  • Human/user-controlled wallet authorization.
  • Not a compliance certification.
  • No guarantee of safety, execution success or profit.
  • Evidence may be partial, stale, conflicting or unavailable.
  • Mainnet/production support is not claimed.

What Ryntra does not do

  • hold funds or take custody of anything
  • receive a seed phrase, private key or withdrawal authority
  • sign transactions on your behalf
  • declare a transaction safe, profitable or compliant
  • represent Arc, Circle or any other provider
  • operate on mainnet — every proof here is Arc Public Testnet

Additional limitations

  • The recorded proofs cover two operations: a direct-EOA ERC-20 USDC transfer (2026-08-06) and one Circle App Kit USDC→EURC swap (2026-08-12), and nothing else. Current capability status also depends on registry freshness.
  • The Circle App Kit USDC→EURC swap has been executed once by the wallet owner and reconciled MATCHED; that record covers the one operation, not general availability.
  • A recorded run proves that its specific lifecycle completed once; it is not a reliability claim or reliability evidence. Gate C — idempotency under load, replay and TOCTOU protection, RPC failure handling, recovery and monitoring — has not been completed.
  • The Circle App Kit swap estimate is request-bound rather than exact-calldata-bound, so in-product swap execution stays disabled until an exact external-signing payload is verified.
  • Persistence is adapter-dependent: memory is ephemeral, file storage is single-writer, and Postgres is the multi-writer implementation. Live Postgres proof for the corrective candidate remains unverified without the authorized integration suite.
  • Testnet assets have no intended monetary value, and the network may reset, change or be unavailable.
  • No security audit has been performed.

Independent project · Not audited · Not financial advice · Testnet only