Jump anywhere, copy an address, change the theme.
How PayXTipping v2 protects funds in escrow, who can do what, and what to watch for.
Funds are held by the contract, not by XyloNet. There is deliberately no owner or admin path that can move user escrow. The only way funds leave escrow is a valid claim for that handle.
Bound to chain 5042 and this contract.
No single key controls the contract.
Guardian can freeze, never move funds.
Claims are authorized by a typed signature Claim(string handle, address wallet, bytes32 nonce) under domain {name: "PayX", version: "2", chainId: 5042, verifyingContract}. A signature cannot be replayed on another chain or another deployment. Each nonce is single-use.
tip() and claimTips() can be halted by the guardian or the owner. The guardian role can only pause; it cannot unpause, change parameters, or touch funds. Unpausing requires the owner (the Safe).
Ownership is held by the XyloNet Admin Safe (0xFD3A…Ed96). Any admin action needs two of three signers, and ownership transfers must be explicitly accepted by the new owner.
The 1% platform fee accrues separately from escrow and can only be withdrawn to the fee recipient, the Treasury Safe (0x7EF8…9990), by the owner or the recipient itself.
The contract tracks totalPending (sum of every handle's unclaimed balance). sweepExcessUSDC can only move USDC above totalPending + totalFeesCollected, and rescueToken refuses USDC entirely. There is no function that reduces a handle's pending balance except its own claim.
If a creator loses the wallet they first claimed with, the owner (2-of-3) can relink the handle to a new wallet. This only redirects future claims and emits WalletRelinked; it never moves existing funds by itself.
OpenZeppelin ReentrancyGuard on tip/claim/withdraw, SafeERC20 for every transfer, handle normalization onchain, custom errors for every rejection.
| Role | Can | Cannot |
|---|---|---|
Owner Admin Safe 2-of-3 | Set oracle, guardian, fee (≤5%), min amount, fee recipient; pause/unpause; relink a handle's wallet; sweep excess; rescue non-USDC tokens; withdraw fees | Move or reduce any handle's pending balance; claim on a user's behalf; withdraw fees anywhere but the Treasury Safe |
| Guardian | Pause payments and claims | Unpause; change any setting; move any funds |
| Oracle signer | Sign claim authorizations for a handle-to-wallet pair after X OAuth | Move funds; sign for a wallet without a valid X session; replay a signature elsewhere |
| Anyone | Pay any handle; read every balance and event | Claim without an oracle signature |
The USDC instance escrows Arc's native USDC through its 6-decimal ERC-20 interface and holds no other asset. Any additional supported asset gets a separate deployment of the same code that escrows only that token. Each instance holds exactly one token.
Learn more about USDCReentrancyGuard, SafeERC20, Ownable2Step, Pausable, EIP712 and ECDSA: audited, widely deployed building blocks.
OpenZeppelin documentation0xFD3A6DEE167C9B519fE7f646F91e9D80ba51Ed96 is the Admin Safe referenced above.