Skip to content

Security: FurlPay/furlpay-arc-kit

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue. Report privately through GitHub Security Advisories, or email security@furlpay.com.

Please include a reproduction — for this package that usually means an amount, the function called, and the value you got versus the value you expected.

We aim to acknowledge within 3 business days and to ship a fix or a written assessment within 30 days.

What is in scope

This package computes with money amounts. The bugs that matter most here are arithmetic, not memory safety:

  • Precision errors — any input where toErc20, toNative, erc20Remainder, formatNativeUsdc or parseNativeUsdc returns a value that does not match the chain's own arithmetic.
  • Rounding direction — toErc20 must truncate. A case where it rounds up is a vulnerability, not a style choice: it would authorise a transfer the ERC-20 interface cannot settle.
  • Wrong constants — a chain id, contract address or decimal count that does not match the live network. Run node scripts/verify-onchain.mjs first; if that script disagrees with this package, that is the report.
  • Domain confusion — arcUsdcDomain returning a domain for a non-Arc chain, or one the token would reject.

What is out of scope

  • The security of Arc, Circle's USDC contracts, or any RPC provider.
  • Anything requiring a compromised signer or a malicious RPC endpoint — this package performs no network calls at runtime.
  • Denial of service via absurdly large bigint inputs.

Supported versions

The latest minor release. This package has no runtime dependencies, so its supply-chain surface is its own source plus TypeScript at build time.

There aren't any published security advisories