Hosted appToken launchpadArc Testnetsucceeded

Launch meme coins in seconds on new chains with OnmiFun. Fair bonding curves, no insiders, and automatic liquidity graduation.

Tested in place byDeepQA TeamonArc Testnetatapp.onmi.fun/?chain=ARC_TESTNETonSep 17, 2026

Run #1model gemini-balanced (vertex)took 27m

5 of 12 scenarios passed, 1 failed, 6 blocked, 1 medium functional issue after the audit.

Share on X
OnmiFun in the browser during the run

By the numbers

5 of 12
scenarios passed, 1 failed, 6 blocked
275
browser actions
40
screenshots
222
model calls
27
minutes
12
scenarios
5
passed
1
failed
6
blocked
1
issues
medium1

Walkthrough

Every scenario DeepQA drove in the browser, in plan order, with the 35 screenshots it captured along the way. A passing scenario is evidence too.

  1. S1
    Create and launch a new token on Arc

    5 steps, 2 screenshots

    blocked
    S1-2.png
    S1 · Create and launch a new token on Arc
    S1-11.png
    S1 · Create and launch a new token on Arc
    • Token [redacted] requires connecting an external Web3 wallet and signing an on-chain deployment transaction, which is not supported in the headless browser environment without an injected wallet provider.
    • Navigated to /create-token and verified the token [redacted] form controls for coin name, symbol, description, and initial buy amount.
    • Filled the token [redacted] form with 'TestCoin' and symbol 'TST'.
    • Attempting to submit the form requires a connected Web3 wallet, prompting the wallet connection modal.
  2. S2
    Buy a token against the bonding curve

    4 steps, 2 screenshots

    blocked
    S2-2.png
    S2 · Buy a token against the bonding curve
    S2-6.png
    S2 · Buy a token against the bonding curve
    • Navigated to the token [redacted] page for 0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB on ARC_TESTNET.
    • The Buy button remains disabled and prompt requires connecting a Web3 wallet, which is not available in the headless browser environment.
    • Navigated to the token [redacted] page at /token/5042/0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB?chain=ARC_TESTNET.
    • Entered an amount of 0.1 into the Buy form.
    • Observed that the Buy button remains disabled and requires connecting a Web3 wallet (MetaMask, WalletConnect, etc.), which cannot be connected in headless mode without an injected provider.
  3. S3
    Sell an existing token balance

    4 steps, 2 screenshots

    blocked
    S3-2.png
    S3 · Sell an existing token balance
    S3-10.png
    S3 · Sell an existing token balance
    • Navigated to token [redacted] page for 0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB on ARC_TESTNET; unable to select sell mode or trade without a connected Web3 wallet.
    • Navigated to /token/5042/0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB?chain=ARC_TESTNET.
    • Observed token [redacted], bonding curve progress (100%), and trade form.
    • Wallet connection is required to fetch token [redacted] and execute Sell transactions, but no Web3 provider is present.
  4. S4
    Verify MAX shortcut correctly reserves USDC gas

    4 steps, 2 screenshots

    blocked
    S4-2.png
    S4 · Verify MAX shortcut correctly reserves USDC gas
    S4-9.png
    S4 · Verify MAX shortcut correctly reserves USDC gas
    • Navigated to /token/5042/0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB?chain=ARC_TESTNET and verified Buy mode interface.
    • Clicked Max quick-amount button with no wallet connected; quantity populated with '0' as balance is 0.
    • Navigated to the token [redacted] page for 0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB on Arc Testnet.
    • Buy mode was active and quick amount presets (0.1, 0.5, 1, Max) were visible.
    • Without a connected Web3 wallet, the balance is 0 and clicking Max correctly populates 0 in the amount field.
  5. S5
    Graceful failure on unsupported chain switch

    3 steps, 3 screenshots

    pass
    S5-1.png
    S5 · Graceful failure on unsupported chain switch
    S5-4.png
    S5 · Graceful failure on unsupported chain switch
    S5-15.png
    S5 · Graceful failure on unsupported chain switch
    • Navigated to https://app.onmi.fun/?chain=ROBINHOOD with Robinhood Chain selected in the chain parameter.
    • The application renders Robinhood Chain indicator and header successfully without unhandled promise rejections or page crash.
    • Triggered the Connect Wallet dialog on the home page and swap page; the dialog rendered cleanly with close and provider options.
    • Attempted token [redacted] and swapping actions on Robinhood chain; the app remains stable and handles unsupported state gracefully without crashing or freezing in loading state.
  6. S6
    Validate required fields on Token Creation

    4 steps, 3 screenshots

    pass
    S6-2.png
    S6 · Validate required fields on Token Creation
    S6-5.png
    S6 · Validate required fields on Token Creation
    S6-7.png
    S6 · Validate required fields on Token Creation
    • Navigated to /create-token and verified Coin Name and Symbol are empty.
    • Attempted form submission with empty Coin Name and Coin Symbol; form submission was blocked and displayed 'Name of token is required.' and 'Symbol is required.' validation errors.
    • Navigated to /create-token and verified Coin Name and Symbol input fields were left empty.
    • Entered text into Coin Description.
    • Clicked 'Create coin' button to submit the form.
    • Observed that the form submission was blocked and displayed validation error messages: 'Name of token is required.' and 'Symbol is required.'.
  7. S7
    Validate URL formatting for social links

    5 steps, 3 screenshots

    fail
    S7-2.png
    S7 · Validate URL formatting for social links
    S7-9.png
    S7 · Validate URL formatting for social links
    S7-11.png
    S7 · Validate URL formatting for social links
    • Filled Coin Name with 'Test Coin', Symbol with 'TEST', and Website, X, and Telegram links with 'invalid_link'.
    • Navigated to /create-token?chain=ARC_TESTNET and filled required coin fields.
    • Expanded social links and populated Website, X, and Telegram inputs with invalid string 'invalid_link'.
    • No URL validation error was shown, and the invalid string was accepted and rendered directly in the Preview Launch link attributes.
  8. S8
    Post a comment in the token discussion thread

    4 steps, 4 screenshots

    blocked
    S8-2.png
    S8 · Post a comment in the token discussion thread
    S8-5.png
    S8 · Post a comment in the token discussion thread
    S8-8.png
    S8 · Post a comment in the token discussion thread
    S8-10.png
    S8 · Post a comment in the token discussion thread
    • Navigated to the token [redacted] on ARC_TESTNET and captured initial view with Comments section visible.
    • Entered comment text 'Great project to the moon!' into the comment textbox.
    • Clicked submit comment button and observed toast message 'Please connect wallet first!'.
    • Opened Connect Wallet dialog; headless browser environment lacks an active Web3 wallet extension.
    • Comments section on the token [redacted] page loaded successfully with input field and submit button.
    • Attempting to post a comment without a connected wallet correctly alerts 'Please connect wallet first!'.
    • Cannot complete comment submission because an external Web3 wallet is required.
  9. S9
    Filter and search live tokens on the Discover page

    3 steps, 4 screenshots

    pass
    S9-2.png
    S9 · Filter and search live tokens on the Discover page
    S9-4.png
    S9 · Filter and search live tokens on the Discover page
    S9-8.png
    S9 · Filter and search live tokens on the Discover page
    S9-13.png
    S9 · Filter and search live tokens on the Discover page
    • Switched network to Arc on /discover, loading the Discover table with token [redacted]
    • Searching for 'ARCDOG' filtered the Discover table immediately to show only the matching token.
    • Navigated to the Discover page on the Arc network, which displayed token [redacted] listings.
    • Entered 'ARCDOG' into the search input on /discover, and the token [redacted] immediately filtered to show only the matching token.
    • Tested the '🔴 Live' filter button combined with the 'ARCDOG' search query on the main token [redacted], which correctly updated the listing to show only the live matching token.
  10. S10
    Access the Creator dashboard

    3 steps, 4 screenshots

    pass
    S10-2.png
    S10 · Access the Creator dashboard
    S10-4.png
    S10 · Access the Creator dashboard
    S10-7.png
    S10 · Access the Creator dashboard
    S10-10.png
    S10 · Access the Creator dashboard
    • Navigated to /creator and observed a network switch prompt for Arc, LitVM, and Ink.
    • Switched network to Arc and viewed the Creator page prompting wallet connection.
    • Opened Connect Wallet modal offering options including Injected, Metamask, and WalletConnect.
    • Creator dashboard loaded cleanly without 401 errors or infinite spinner, prompting wallet connection to display created tokens and claim LP fees.
    • Navigated to /creator?chain=ARC_TESTNET, where network prompt prompted switching to Arc network.
    • Switched to Arc network and verified Creator dashboard loaded successfully at /creator?chain=ARC.
    • The page displayed the Creator dashboard interface with instructions to connect wallet to view created tokens and claim LP fees, with no 401 error or infinite loading spinner.
  11. S11
    Execute a swap with a custom recipient address

    5 steps, 2 screenshots

    blocked
    S11-2.png
    S11 · Execute a swap with a custom recipient address
    S11-11.png
    S11 · Execute a swap with a custom recipient address
    • Navigated to /swap?chain=ARC_TESTNET; page loaded with swap interface and Trade and Send to Another Address checkbox.
    • Checked 'Trade and Send to Another Address' checkbox, revealing the recipient wallet address input field.
    • Navigated to /swap and verified the pay amount input.
    • Successfully toggled the 'Trade and Send to Another Address' checkbox, which revealed the destination address input field.
    • Successfully entered a valid destination wallet address (0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045) into the recipient address field.
    • Unable to submit the swap transaction on-chain as it requires an active external Web3 wallet connection.
  12. S12
    Toggle chart timeframes

    2 steps, 4 screenshots

    pass
    S12-2.png
    S12 · Toggle chart timeframes
    S12-4.png
    S12 · Toggle chart timeframes
    S12-6.png
    S12 · Toggle chart timeframes
    S12-8.png
    S12 · Toggle chart timeframes
    • Navigated to token [redacted] with timeframe buttons 1m, 5m, 15m, 1h, 4h, 1d and TradingView chart.
    • Clicked 5m timeframe button and chart updated.
    • Clicked 15m timeframe button and chart updated.
    • Clicked 1h timeframe button and chart updated.
    • Navigated to the token [redacted] page at /token/5042/0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB?chain=ARC_TESTNET.
    • Observed timeframe buttons for 1m, 5m, 15m, 1h, 4h, and 1d.
    • Clicked through each timeframe option (1m, 5m, 15m, 1h, 4h, 1d) sequentially.
    • TradingView chart remained intact, responsive, and updated without errors or blank screens.

Issues

Findings that survived the Critic's audit. Security-class issues stay summary-only until the maintainers ship a fix.

mediumconfirmed ✓functionalF1 · S7

Social link fields on token creation form lack URL format validation

The tester's observation explicitly confirms that the invalid strings were accepted by the form and rendered directly into the preview link attributes without any validation errors. The page reported 2 console errors during the scenario.

Expected

The application should validate social link inputs for proper URL formatting (e.g. valid https:// URLs) and display validation errors for invalid links, preventing form submission.

Actual

The create-token form accepts arbitrary plain text ('invalid_link') in the Website, X, and Telegram URL fields without URL formatting validation errors, and renders them directly as href='invalid_link' in the preview.

Repro · 5 steps
  1. Navigate to /create-token?chain=ARC_TESTNET
  2. Enter Coin Name ('Test Coin') and Symbol ('TEST')
  3. Click 'Add social links (Optional)'
  4. Enter 'invalid_link' in the Website, X, and Telegram URL input fields
  5. Click 'Create coin'

Wallet activity

DeepQA injected a test wallet into the browser and recorded every request the app sent to it. Testnet funds only.

address
0x181568…0B2c27
chain
Arc Testnet
browsers opened
3
read requests forwarded
0
signing requests
0

Critic audit

An adversarial second pass over every finding before it reaches the report.

1
findings reviewed
3
re-verified live
0
withdrawn
  • F1confirmed ✓

    The tester's observation explicitly confirms that the invalid strings were accepted by the form and rendered directly into the preview link attributes without any validation errors.

  • Over half of the test scenarios (7 out of 12) were blocked due to the lack of an injected Web3 wallet, rendering the core transactional paths untestable in this environment.
  • Console logs consistently show failed WebSocket connections and missing route parameters associated with the Robinhood chain, even when tests explicitly targeted the ARC Testnet.
  • A possible defect in S12 ("Missing route parameter causes Next.js href interpolation failure") was not promoted: the live replay came back inconclusive.
  • A possible defect in S12 ("Silent failure when fetching chart candle data across timeframes") was not promoted: the live replay came back inconclusive.
  • A possible defect in S9 ("Token [redacted] JSON fails to download on Discover page") was not promoted: the live replay came back inconclusive.

Report

QA report: external/app.onmi.fun at hosted

Token creation accepts invalid social link formats, while key transactional features remained untestable without a Web3 wallet.

Testing covered token creation form validation, network switching, token discovery, the creator dashboard, and chart controls on the Arc Testnet. Out of twelve scenarios, six were blocked because core transactional actions—such as token deployment, buying, selling, gas calculations, commenting, and swapping—require an active Web3 wallet provider not present in the automated headless environment.

A single medium-severity functional issue was confirmed during token creation form validation. The Website, X, and Telegram fields accept arbitrary plain text without checking for valid URL formats, rendering invalid strings directly as link destinations in the token preview.

The remaining five accessible scenarios passed, including required field enforcement on creation, chain error handling, search filters, and chart timeframe toggles. However, full release confidence requires testing on-chain transactions with an active wallet environment.

Run summary
MetricCount
Scenarios executed12
Passed5
Failed1
Blocked6
Findings raised1
Issues after the audit1
Withdrawn by the audit0
Critical / high / medium / low0 / 0 / 1 / 0

Target: https://app.onmi.fun/?chain=ARC_TESTNET · Testing level: deep_feature · Stack: unknown

Issues
Medium severity
F1 · Social link fields on token creation form lack URL format validation

Severity: medium · Type: functional · Verdict: confirmed · Scenario: S7

The tester's observation explicitly confirms that the invalid strings were accepted by the form and rendered directly into the preview link attributes without any validation errors. The page reported 2 console errors during the scenario.

Expected: The application should validate social link inputs for proper URL formatting (e.g. valid https:// URLs) and display validation errors for invalid links, preventing form submission.

Actual: The create-token form accepts arbitrary plain text ('invalid_link') in the Website, X, and Telegram URL fields without URL formatting validation errors, and renders them directly as href='invalid_link' in the preview.

Steps to reproduce:

  1. Navigate to /create-token?chain=ARC_TESTNET
  2. Enter Coin Name ('Test Coin') and Symbol ('TEST')
  3. Click 'Add social links (Optional)'
  4. Enter 'invalid_link' in the Website, X, and Telegram URL input fields
  5. Click 'Create coin'

Evidence: screenshots/S7-9.png, screenshots/S7-11.png

Scenario results
ScenarioPriorityResultIssues
S1 Create and launch a new token on Archighblocked (Token [redacted] requires an active Web3 wallet connection to sign and broadcast the smart contract deployment transaction, which cannot be completed in the headless browser environment without an injected Web3 wallet provider.)none
S2 Buy a token against the bonding curvehighblocked (Executing a token [redacted] against the bonding curve requires an active Web3 wallet connection to sign and broadcast on-chain transactions, which is unavailable in the automated headless test environment.)none
S3 Sell an existing token balancehighblocked (Trading and selling token [redacted] requires an active Web3 wallet connection, which is not available in the headless browser environment.)none
S4 Verify MAX shortcut correctly reserves USDC gashighblocked (Cannot verify USDC gas reservation on ARC Testnet without a connected Web3 wallet containing a USDC balance.)none
S5 Graceful failure on unsupported chain switchhighpassnone
S6 Validate required fields on Token Creationmediumpassnone
S7 Validate URL formatting for social linksmediumfailF1
S8 Post a comment in the token discussion threadmediumblocked (Posting a comment requires connecting an active Web3 wallet, which is not available in the headless browser environment.)none
S9 Filter and search live tokens on the Discover pagemediumpassnone
S10 Access the Creator dashboardmediumpassnone
S11 Execute a swap with a custom recipient addresslowblocked (Submitting and confirming the on-chain swap transaction requires an external connected Web3 wallet with testnet funds, which is unavailable in this headless environment.)none
S12 Toggle chart timeframeslowpassnone
The audit

The Critic reviewed 1 finding and re-verified 3 of them live in the browser, replaying the reported steps on a fresh page.

  • Over half of the test scenarios (7 out of 12) were blocked due to the lack of an injected Web3 wallet, rendering the core transactional paths untestable in this environment.
  • Console logs consistently show failed WebSocket connections and missing route parameters associated with the Robinhood chain, even when tests explicitly targeted the ARC Testnet.
  • A possible defect in S12 ("Missing route parameter causes Next.js href interpolation failure") was not promoted: the live replay came back inconclusive.
  • A possible defect in S12 ("Silent failure when fetching chart candle data across timeframes") was not promoted: the live replay came back inconclusive.
  • A possible defect in S9 ("Token [redacted] JSON fails to download on Discover page") was not promoted: the live replay came back inconclusive.
What to fix first
  1. Implement URL format validation for Website, X, and Telegram fields on the token creation form to prevent malformed link submissions (F1).
Coverage and caveats

In scope: Token creation on Arc Testnet; Token trading and bonding curve interaction; Wallet native gas reservation on MAX shortcuts; Cross-chain network switch rejection handling; Discover and Creator dashboards; Swap with send-to-address functionality.

Not covered: Campaigns and Passport quests (out of primary deep feature focus); Analytics page validation (read-only multichain metrics); Uniswap V3 specific routing (focusing on OnmiSwap and Bonding Curve); Ranking leaderboard (requires extensive multi-user trade history).

  • The injected test wallet automatically connects on Arc Testnet when requested.
  • The wallet has sufficient test USDC to cover token deployment and trades.
  • The MAX button logic correctly calculates gas from the USDC balance.
  • Sell scenarios assume the wallet holds a balance of the target token.
  • The application supports appending ?chain=ARC_TESTNET to routes as per intake.
  • S1 could not be executed: Token [redacted] requires an active Web3 wallet connection to sign and broadcast the smart contract deployment transaction, which cannot be completed in the headless browser environment without an injected Web3 wallet provider..
  • S2 could not be executed: Executing a token [redacted] against the bonding curve requires an active Web3 wallet connection to sign and broadcast on-chain transactions, which is unavailable in the automated headless test environment..
  • S3 could not be executed: Trading and selling token [redacted] requires an active Web3 wallet connection, which is not available in the headless browser environment..
  • S4 could not be executed: Cannot verify USDC gas reservation on ARC Testnet without a connected Web3 wallet containing a USDC balance..
  • S8 could not be executed: Posting a comment requires connecting an active Web3 wallet, which is not available in the headless browser environment..
  • S11 could not be executed: Submitting and confirming the on-chain swap transaction requires an external connected Web3 wallet with testnet funds, which is unavailable in this headless environment..
By the numbers
MetricValue
Scenarios5 passed, 1 failed, 6 blocked of 12 (46 planned steps)
Browser actions275 (77 clicks, 18 inputs, 42 navigations, 138 snapshots)
Screenshots40 (4 explore, 35 scenario, 1 critic), 35 captioned
Coverage11 pages, 3 forms, 4 flows, 8 console errors
Audit1 findings, 3 re-verified live, 1 confirmed, 0 promoted, 0 withdrawn
Model calls222
Tokens1,463,558 input, 12,393 output, 28,414 thinking
Time27 min
Wallet0 transactions, 0 signatures, 0 refusals on chain 5042002
StageCallsInputOutputThinkingSeconds
explore32206,8893,1561,816263
plan15,4832,4105,25457
test1631,114,8835,29210,5131019
critique25134,5221,28610,330251
report11,7812495017

Run log

stagecallstokenstime
Explore32211.9k4m 23s
Plan113.1k57s
Test1631.1M16m 59s
Critique25146.1k4m 11s
Report12.5k7s
Total2221.5M26m 37s
Intake
Explore
Plan
Test
Critique
Report
  • 15:16:47Zexploreexplore started
  • 15:43:24ZexploreExplored / (25 controls, 0 forms)
  • 15:43:24ZexploreExplored /create-token (20 controls, 0 forms)
  • 15:43:24ZexploreExplored /swap (22 controls, 0 forms)
  • 15:43:24ZexploreExplored /ranking (14 controls, 0 forms)
  • 15:43:24ZexploreExplored /campaigns (18 controls, 0 forms)
  • 15:43:24ZexploreExplored /campaigns/4441 (19 controls, 0 forms)
  • 15:43:24ZexploreExplored /swap/v3 (16 controls, 0 forms)
  • 15:43:24ZexploreExplored /discover (16 controls, 0 forms)
  • 15:43:24ZexploreExplored /creator (18 controls, 0 forms)
  • 15:43:24ZexploreExplored /analytics (17 controls, 0 forms)
  • 15:43:24ZexploreExplored /token/5042/0xeC8b4F866b51242EE17D34962b8E988Cb28a5dfB (51 controls, 0 forms)
  • 15:43:24ZexploreMapped 11 pages, 3 forms, 4 flows in 32 turns.
  • 15:43:24Zexploreexplore completed in 263s.
  • 15:43:24Zplanplan started
  • 15:43:24ZplanPlanned 12 scenarios (5 high, 5 medium, 2 low).
  • 15:43:24Zplanplan completed in 57s.
  • 15:43:24Ztesttest started
  • 15:43:24ZtestS1 executed (blocked)
  • 15:43:24ZtestS2 executed (blocked)
  • 15:43:24ZtestS3 executed (blocked)
  • 15:43:24ZtestS4 executed (blocked)
  • 15:43:24ZtestS5 executed (pass)
  • 15:43:24ZtestS6 executed (pass)
  • 15:43:24ZtestS7 executed (fail), 1 finding
  • 15:43:24ZtestS8 executed (blocked)
  • 15:43:24ZtestS9 executed (pass)
  • 15:43:24ZtestS10 executed (pass)
  • 15:43:24ZtestS11 executed (blocked)
  • 15:43:24ZtestS12 executed (pass)
  • 15:43:24ZtestExecuted 12 scenarios: 5 passed, 1 failed, 6 blocked, 1 finding.
  • 15:43:24Ztesttest completed in 1019s.
  • 15:43:24Zcritiquecritique started
  • 15:43:24ZcritiqueReviewed 1 findings; 3 possible defects spotted in passed scenarios.
  • 15:43:24ZcritiqueRe-verified a possible defect in S12: inconclusive.
  • 15:43:24ZcritiqueRe-verified a possible defect in S12: inconclusive.
  • 15:43:24ZcritiqueRe-verified a possible defect in S9: inconclusive.
  • 15:43:24ZcritiqueAudit complete: 1 confirmed, 0 withdrawn, 0 promoted, 3 re-verified live.
  • 15:43:24Zcritiquecritique completed in 251s.
  • 15:43:24Zreportreport started
  • 15:43:24ZreportReported 1 issue (0 critical, 0 high, 1 medium, 0 low) from 1 finding.
  • 15:43:24Zreportreport completed in 7s.

Put an agent team on your next pull request.

Connect a repo, dispatch a Run, and read an audited, evidence-backed report the same day.