Do not open a public issue. Report privately through GitHub Security Advisories, or email security@furlpay.com.
Please include a reproduction — for this package that usually means an amount, the function called, and the value you got versus the value you expected.
We aim to acknowledge within 3 business days and to ship a fix or a written assessment within 30 days.
This package computes with money amounts. The bugs that matter most here are arithmetic, not memory safety:
- Precision errors — any input where
toErc20,toNative,erc20Remainder,formatNativeUsdcorparseNativeUsdcreturns a value that does not match the chain's own arithmetic. - Rounding direction —
toErc20must truncate. A case where it rounds up is a vulnerability, not a style choice: it would authorise a transfer the ERC-20 interface cannot settle. - Wrong constants — a chain id, contract address or decimal count that
does not match the live network. Run
node scripts/verify-onchain.mjsfirst; if that script disagrees with this package, that is the report. - Domain confusion —
arcUsdcDomainreturning a domain for a non-Arc chain, or one the token would reject.
- The security of Arc, Circle's USDC contracts, or any RPC provider.
- Anything requiring a compromised signer or a malicious RPC endpoint — this package performs no network calls at runtime.
- Denial of service via absurdly large
bigintinputs.
The latest minor release. This package has no runtime dependencies, so its supply-chain surface is its own source plus TypeScript at build time.