Security
This page sets out what AchSwap's contracts enforce, what you are trusting when you use AchSwap, and what is outside AchSwap's control. It describes the contracts live on Arc Mainnet (chain ID 5042). Addresses are in the contract reference.
Audit and verification status
| Status | |
|---|---|
| Independent third-party audit | None published. AchSwap's contracts have had internal security reviews by the AchSwap team. An internal review is not an independent audit. |
| Source verification | Every live AchSwap contract except one is source-verified on ArcScan: you can read the code that runs and check it matches the deployed bytecode. The exception is the Virtuals adapter (adapter 6), 0x4166…c106, which is live but not yet verified (checked 10 October 2026). |
Source verification shows you what the code is. It says nothing about whether the code is safe. Decide for yourself how much to trust any smart contract.
What the swap contracts enforce
For an AchSwap route, the route executor guarantees, in code:
- It only spends your input. It pulls tokens from the address that calls it, and only the input amount of that call.
- Your minimum is enforced on what you actually receive. The executor measures the recipient's balance before and after, after all fees. Below your minimum, the whole transaction reverts.
- One fee, capped. 0.25% of the final output, paid straight to the AchSwap treasury Safe in the same transaction. The contract caps it at 1%. An increase waits two days, and a transaction built under the old fee reverts instead of paying the new one.
- Nothing is held. There is no vault and no balance between transactions; leftovers of a call are refunded in that call.
- Changes are delayed. New adapters and fee increases take effect two days after they are scheduled, so they are visible on chain before they apply. The owner can pause execution or disable an adapter immediately.
KyberSwap and LI.FI routes execute on those providers' own contracts. Their minimums are enforced by their contracts, not AchSwap's.