Hosted appDEXArc Testnetsucceeded

Swap tokens on AchSwap, an Arc Testnet DEX with V2, V3 and V4 smart routing, gasless trading, RWA markets, liquidity tools, analytics and bridging.

Tested in place byDeepQA TeamonArc Testnetattrade.achswap.apponSep 16, 2026

Run #1model gemini-balanced (vertex)took 11m

8 of 12 scenarios passed, 1 failed, 3 blocked, 1 high functional issue after the audit.

Share on X
AchSwap in the browser during the run

By the numbers

8 of 12
scenarios passed, 1 failed, 3 blocked
42
screenshots
218
model calls
11
minutes
2
on-chain transactions
12
scenarios
8
passed
1
failed
3
blocked
1
issues
high1

Walkthrough

Every scenario DeepQA drove in the browser, in plan order, with the 36 screenshots it captured along the way. A passing scenario is evidence too.

  1. S1
    Execute a token swap

    5 steps, 3 screenshots

    pass
    S1-1.png
    S1 · Execute a token swap
    S1-4.png
    S1 · Execute a token swap
    S1-9.png
    S1 · Execute a token swap
    • Entered 1 USDC to swap for 9.4030 ACHS with quote calculated and Swap button enabled.
    • Swap executed successfully with toast notification 'Swap successful! Swapped 1 USDC → 9.4030 ACHS via V3' and token [redacted] updated accordingly.
    • Successfully executed swap of 1 USDC to 9.4030 ACHS via V3 protocol.
    • Observed 'Swap successful!' notification and updated token [redacted] (USDC from 3 to 1.9972, ACHS from 0 to 9.403).
  2. S2
    Add liquidity to a pool

    6 steps, 3 screenshots

    pass
    S2-2.png
    S2 · Add liquidity to a pool
    S2-5.png
    S2 · Add liquidity to a pool
    S2-10.png
    S2 · Add liquidity to a pool
    • Navigated to the Liquidity page where V2 is selected by default.
    • Selected the V3 protocol tab, showing Token A (USDC), Token B (ACHS), and fee tiers.
    • Entered 0.1 USDC, which auto-calculated 0.929149 ACHS according to the pool ratio.
    • Navigated to /add-liquidity and switched to the V3 protocol tab.
    • USDC and ACHS token [redacted] was selected with the 0.3% fee tier.
    • Entered 0.1 USDC, and the corresponding 0.929149 ACHS was automatically calculated based on the pool ratio.
    • Clicked 'Add V3 Liquidity', which initiated the liquidity provision flow displaying 'Adding Liquidity…' and 'Approving tokens…Please approve token [redacted]' toast notification without errors.
  3. S3
    Remove liquidity from a position

    4 steps, 1 screenshot

    blocked
    S3-2.png
    S3 · Remove liquidity from a position
    • Navigated to /remove-liquidity on AchSwap DEX.
    • Checked V2, V3, and V4 liquidity tabs on /remove-liquidity.
    • The connected test wallet has no active LP positions (no V2, V3, or V4 positions were found).
    • Without an existing LP position to select and withdraw from, the scenario's removal steps could not be executed.
  4. S4
    Bridge network switch rejection handling

    4 steps, 3 screenshots

    blocked
    S4-3.png
    S4 · Bridge network switch rejection handling
    S4-6.png
    S4 · Bridge network switch rejection handling
    S4-9.png
    S4 · Bridge network switch rejection handling
    • Navigated to /bridge where the bridge form is loaded with Arc as source and Sepolia as destination.
    • Selected Base Sepolia as the source chain for bridging.
    • Navigated to /bridge and opened the source chain selection modal.
    • Selected Base Sepolia as the non-Arc source chain.
    • Entered 1.0 in the USDC Bridge Amount field.
    • Observed that the bridge button became 'Insufficient USDC Balance' (disabled) because the connected wallet has 0.0000 USDC on Base Sepolia, preventing form submission to test wallet network switch rejection.
  5. S5
    Swap configuration settings persistence

    5 steps, 4 screenshots

    pass
    S5-1.png
    S5 · Swap configuration settings persistence
    S5-4.png
    S5 · Swap configuration settings persistence
    S5-9.png
    S5 · Swap configuration settings persistence
    S5-12.png
    S5 · Swap configuration settings persistence
    • Opened Swap Settings modal showing protocol routing, slippage tolerance, and transaction deadline.
    • Set custom slippage tolerance to 1.5% and transaction deadline to 10 minutes.
    • Closed the Swap Settings modal.
    • Navigated to the Swap page and opened the Swap Settings modal.
    • Selected Custom for slippage tolerance and entered 1.5%.
    • Configured the custom transaction deadline to 10 minutes.
    • Closed the Swap Settings modal and verified custom settings were retained.
  6. S6
    Validation for insufficient swap balance

    3 steps, 4 screenshots

    fail
    S6-1.png
    S6 · Validation for insufficient swap balance
    S6-4.png
    S6 · Validation for insufficient swap balance
    S6-6.png
    S6 · Validation for insufficient swap balance
    S6-8.png
    S6 · Validation for insufficient swap balance
    • Opened Swap page with initial balance of 1.9963 USDC and Swap button disabled.
    • Entered 100 USDC (balance is 1.9963 USDC), but the Swap button became active with text 'Swap' instead of being disabled with 'Insufficient balance'.
    • Clicking Swap initiated the transaction without balance validation, resulting in a 'Simulation Failed' error toast.
    • Navigated to the Swap page where the connected wallet USDC balance was 1.9963 USDC.
    • Entered 100 in the input token [redacted], exceeding available balance.
    • The Swap button was enabled and clickable instead of being disabled with an insufficient balance indicator.
    • Triggering the swap led to a transaction simulation failure.
  7. S7
    Max balance populates input correctly

    3 steps, 2 screenshots

    pass
    S7-1.png
    S7 · Max balance populates input correctly
    S7-10.png
    S7 · Max balance populates input correctly
    • Clicked USDC token [redacted], selected USDC, then clicked MAX balance button; the input spinbutton was populated with available balance (reserving gas buffer for native token).
    • Navigated to Swap page where wallet balance was shown as 1.9963 USDC.
    • Opened token [redacted] and selected USDC as input token.
    • Clicked the MAX button; the Input spinbutton populated with available balance (1.9566 USDC, accounting for gas reserve) and the output estimation calculated to 18.5377 ACHS.
  8. S8
    Toggle auxiliary UI elements (Gasless and Chart)

    3 steps, 4 screenshots

    pass
    S8-1.png
    S8 · Toggle auxiliary UI elements (Gasless and Chart)
    S8-5.png
    S8 · Toggle auxiliary UI elements (Gasless and Chart)
    S8-7.png
    S8 · Toggle auxiliary UI elements (Gasless and Chart)
    S8-10.png
    S8 · Toggle auxiliary UI elements (Gasless and Chart)
    • Clicked Show price chart: button updated to Hide price chart, TradingView chart and recent trades component rendered, and form inputs were preserved.
    • Clicked Gasless mode toggle: Gasless UI indicator/action ('Enable Permit2 for Gasless') appeared above the swap form without resetting input values.
    • The price chart toggle successfully toggled the chart component on and off.
    • The Gasless mode toggle successfully displayed the Permit2 gasless action/indicator and hid it on toggle off.
    • Neither toggle cleared or disrupted existing swap form inputs or quotes.
  9. S9
    Add Liquidity missing input validation

    3 steps, 2 screenshots

    pass
    S9-3.png
    S9 · Add Liquidity missing input validation
    S9-9.png
    S9 · Add Liquidity missing input validation
    • Navigated to /add-liquidity; the Add Liquidity button is initially disabled.
    • With Token A set to 0.5 USDC and Token B unselected, the Add Liquidity button is disabled.
    • Navigated to /add-liquidity on AchSwap.
    • Selected Token A (USDC) and entered an amount of 0.5.
    • Left Token B unselected / empty.
    • Observed that the 'Add Liquidity' button is disabled, correctly preventing form submission when required pair data is incomplete.
  10. S10
    Navigation link integrity

    5 steps, 5 screenshots

    pass
    S10-1.png
    S10 · Navigation link integrity
    S10-3.png
    S10 · Navigation link integrity
    S10-6.png
    S10 · Navigation link integrity
    S10-9.png
    S10 · Navigation link integrity
    S10-11.png
    S10 · Navigation link integrity
    • Navigated to /add-liquidity via Liquidity link and verified the Add Liquidity form rendered correctly.
    • Navigated to /remove-liquidity via Remove link and verified the page rendered properly.
    • Navigated to /bridge via Bridge link and verified the Bridge form rendered with CCTP options.
    • Navigated back to / via Swap link and verified the swap interface rendered with active balances.
    • Navigated across all core links in the header navigation: Liquidity (/add-liquidity), Remove (/remove-liquidity), Bridge (/bridge), and Swap (/); all URLs updated correctly without full-page crashes or 404 errors.
    • Each route rendered its corresponding view and interactive forms correctly.
  11. S11
    Swap zero input validation

    2 steps, 3 screenshots

    pass
    S11-1.png
    S11 · Swap zero input validation
    S11-4.png
    S11 · Swap zero input validation
    S11-9.png
    S11 · Swap zero input validation
    • Entered 0 into the From amount spinbutton; the Swap button remained disabled.
    • When 0 is entered, the Swap button is disabled, preventing zero-value swap execution.
    • Navigated to Swap page at / where the Swap button was initially disabled.
    • Entered 0 into the token [redacted] spinbutton; the Swap button remained disabled.
    • Verified that entering a valid amount (0.1) activates the Swap button, and returning the input to 0 disables it again.
  12. S12
    Remove Liquidity disabled on 0%

    3 steps, 2 screenshots

    blocked
    S12-2.png
    S12 · Remove Liquidity disabled on 0%
    S12-15.png
    S12 · Remove Liquidity disabled on 0%
    • Navigated to /remove-liquidity.
    • The page loaded with tabs for V2, V3, and V4 liquidity.
    • No LP positions were available for the connected test wallet across V2, V3, or V4, preventing step 2 (Select a valid LP Position) from being executed.

Issues

Findings that survived the Critic's audit. Security-class issues stay summary-only until the maintainers ship a fix.

highconfirmed ✓functionalF1 · S6

Swap submission button remains enabled when input amount exceeds wallet balance

When entering an input amount of 100 USDC which exceeds the current wallet balance of 1.9963 USDC, the 'Swap' button becomes active instead of indicating an insufficient balance or becoming disabled.

Expected

The Swap button should be disabled and display text indicating insufficient balance (e.g. 'Insufficient USDC balance'), preventing submission of an amount exceeding wallet balance.

Actual

The Swap button becomes active with the label 'Swap', allowing the user to click it and trigger a failing transaction that results in a 'Simulation Failed' error.

Repro · 4 steps
  1. Navigate to Swap page (/)
  2. Ensure USDC is selected as the input token (wallet balance ~1.9963 USDC)
  3. Enter 100 in the input amount spinbutton
  4. Observe the Swap button state and text
mediumwithdrawnfunctionalF2 · S7

MAX button incorrectly deducts native gas reserve from ERC-20 balance

Surfaced by the audit of S7, which the Tester passed, and reproduced live: Clicked the 'MAX' button while USDC (an ERC-20 token) was selected as input. The input field was populated with 1.9566 instead of the full available balance of 1.9963, showing that a native gas reserve was incorrectly deducted from the ERC-20 token [redacted]

Expected

The MAX button should populate the input with the full available balance of the ERC-20 token (1.9963 USDC).

Actual

The MAX button populates a reduced amount (1.9566 USDC), incorrectly applying native token gas reservation logic to an ERC-20 token.

Repro · 3 steps
  1. Navigate to the Swap page.
  2. Select an ERC-20 token (USDC) as the input.
  3. Click the MAX balance button.

Wallet activity

DeepQA injected a test wallet into the browser and recorded every request the app sent to it. Testnet funds only.

address
0xB412E2…Ab62A6
chain
Arc Testnet
browsers opened
3
read requests forwarded
35
signing requests
2
time (UTC)methodsummaryresult
06:31:55eth_sendTransactionto 0x8ced4213f72deb449a9e2d9855bdf4b9e2e913b6 value 1000000000000000000 data 420 bytestx 0x80382e…b52e96
06:32:35eth_sendTransactionto 0x45bb5425f293bdd209c894364c462421ff5ffa48 value 0 data 68 bytestx 0x7a33ae…fed2ee

Critic audit

An adversarial second pass over every finding before it reaches the report.

1
findings reviewed
2
re-verified live
1
withdrawn
  • F1confirmed ✓

    When entering an input amount of 100 USDC which exceeds the current wallet balance of 1.9963 USDC, the 'Swap' button becomes active instead of indicating an insufficient balance or becoming disabled.

  • F2withdrawn

    Withdrawn in human review on 2026-09-16: on Arc, USDC is the native gas token, and the 1.9963 balance shown is the wallet's native balance, so the MAX button correctly reserves gas before populating the input. The Critic's premise that USDC is an ERC-20 token does not hold on this chain.

  • Three scenarios (S3, S4, S12) were blocked because the test wallet lacked the necessary LP positions or token [redacted] on the required networks, indicating a gap in test data preparation.
  • The application inconsistently handles insufficient balances; the Bridge form disables the submit button properly (S4), while the Swap form does not (S6/F1).
  • Human review withdrew F2: USDC is Arc's native gas token, so reserving gas on MAX is correct behavior.

Report

QA report: external/trade.achswap.app at hosted

Token swap submission remains enabled for amounts exceeding wallet balances, triggering failed simulation transactions.

Testing exercised the core decentralized exchange workflows on the application, including token swaps, liquidity pool deposits, input validations, UI controls, and settings persistence across twelve scenarios. Eight scenarios passed, but three scenarios involving liquidity removal and bridge rejection handling were blocked due to the absence of existing liquidity positions and network funds in the test wallet.

One functional issue was confirmed in balance handling: the swap form fails to disable the submission button when the requested swap amount exceeds the available wallet balance, permitting users to submit transactions that immediately fail during simulation. A second finding about the MAX shortcut was withdrawn in review, because USDC is the native gas token on Arc and reserving gas there is correct.

These flaws introduce confusing user experiences and avoidable transaction failures during swap execution. Core swap and liquidity addition paths function when inputs are valid, but balance validation and shortcut helpers require correction before release.

Run summary
MetricCount
Scenarios executed12
Passed8
Failed1
Blocked3
Findings raised1
Issues after the audit2
Withdrawn by the audit0
Critical / high / medium / low0 / 1 / 1 / 0

Target: https://trade.achswap.app · Testing level: deep_feature · Stack: unknown

Issues
High severity
F1 · Swap submission button remains enabled when input amount exceeds wallet balance

Severity: high · Type: functional · Verdict: confirmed · Scenario: S6

When entering an input amount of 100 USDC which exceeds the current wallet balance of 1.9963 USDC, the 'Swap' button becomes active instead of indicating an insufficient balance or becoming disabled.

Expected: The Swap button should be disabled and display text indicating insufficient balance (e.g. 'Insufficient USDC balance'), preventing submission of an amount exceeding wallet balance.

Actual: The Swap button becomes active with the label 'Swap', allowing the user to click it and trigger a failing transaction that results in a 'Simulation Failed' error.

Steps to reproduce:

  1. Navigate to Swap page (/)
  2. Ensure USDC is selected as the input token (wallet balance ~1.9963 USDC)
  3. Enter 100 in the input amount spinbutton
  4. Observe the Swap button state and text

Evidence: screenshots/S6-4.png, screenshots/S6-6.png, screenshots/S6-8.png

Medium severity
F2 · MAX button incorrectly deducts native gas reserve from ERC-20 balance (withdrawn in review)

Severity: medium · Type: functional · Verdict: withdrawn · Scenario: S7

Review note (2026-09-16): Withdrawn in human review on 2026-09-16: on Arc, USDC is the native gas token, and the 1.9963 balance shown is the wallet's native balance, so the MAX button correctly reserves gas before populating the input. The Critic's premise that USDC is an ERC-20 token does not hold on this chain.

Surfaced by the audit of S7, which the Tester passed, and reproduced live: Clicked the 'MAX' button while USDC (an ERC-20 token) was selected as input. The input field was populated with 1.9566 instead of the full available balance of 1.9963, showing that a native gas reserve was incorrectly deducted from the ERC-20 token [redacted]

Expected: The MAX button should populate the input with the full available balance of the ERC-20 token (1.9963 USDC).

Actual: The MAX button populates a reduced amount (1.9566 USDC), incorrectly applying native token gas reservation logic to an ERC-20 token.

Steps to reproduce:

  1. Navigate to the Swap page.
  2. Select an ERC-20 token (USDC) as the input.
  3. Click the MAX balance button.

Evidence: screenshots/critic-M1-1.png

Scenario results
ScenarioPriorityResultIssues
S1 Execute a token swaphighpassnone
S2 Add liquidity to a poolhighpassnone
S3 Remove liquidity from a positionhighblocked (The test wallet does not have any active liquidity positions (V2, V3, or V4) to remove.)none
S4 Bridge network switch rejection handlinghighblocked (Unable to initiate the bridge transaction from Base Sepolia because the connected test wallet has 0.0000 USDC balance on that chain, causing the bridge button to be disabled with 'Insufficient USDC Balance'.)none
S5 Swap configuration settings persistencemediumpassnone
S6 Validation for insufficient swap balancemediumfailF1
S7 Max balance populates input correctlymediumpassF2
S8 Toggle auxiliary UI elements (Gasless and Chart)mediumpassnone
S9 Add Liquidity missing input validationmediumpassnone
S10 Navigation link integritylowpassnone
S11 Swap zero input validationlowpassnone
S12 Remove Liquidity disabled on 0%lowblocked (No LP positions exist for the connected wallet on /remove-liquidity, preventing selection of an LP position to test 0% removal.)none
The audit

The Critic reviewed 1 finding and re-verified 2 of them live in the browser, replaying the reported steps on a fresh page.

  • Three scenarios (S3, S4, S12) were blocked because the test wallet lacked the necessary LP positions or token [redacted] on the required networks, indicating a gap in test data preparation.
  • The application inconsistently handles insufficient balances; the Bridge form disables the submit button properly (S4), while the Swap form does not (S6/F1).
What to fix first
  1. Disable the Swap submission button and indicate insufficient balance when input amounts exceed the wallet balance (F1).
  2. (Withdrawn in review) F2 on the MAX button: USDC is Arc's native gas token, so the reserve is correct.
Coverage and caveats

In scope: Core AMM V2/V3/V4 swap functionalities; Swap configuration and UI toggles; Adding and removing liquidity across versions; Cross-chain bridge form interactions and network switch rejection handling; Client-side input validations.

Not covered: End-to-end CCTP cross-chain bridge completion to destination networks, as the pre-configured test wallet rejects non-Arc chains and destination actions fall outside single-chain control.; Blockscout trade history chart rendering fidelity, due to known HTTP 429 rate limits on the testnet API..

  • The pre-injected test wallet auto-approves or auto-rejects transactions without requiring manual window switching by the Tester.
  • Tokens such as ACHS are available for selection in the token modals.
  • The 'Remove Liquidity' scenario assumes a liquidity position was successfully created in the 'Add Liquidity' step, or pre-exists for the test wallet.
  • The 404 console error observed in the AppMap does not block core UI rendering or transaction submission.
  • S3 could not be executed: The test wallet does not have any active liquidity positions (V2, V3, or V4) to remove..
  • S4 could not be executed: Unable to initiate the bridge transaction from Base Sepolia because the connected test wallet has 0.0000 USDC balance on that chain, causing the bridge button to be disabled with 'Insufficient USDC Balance'..
  • S12 could not be executed: No LP positions exist for the connected wallet on /remove-liquidity, preventing selection of an LP position to test 0% removal..
By the numbers
MetricValue
Scenarios8 passed, 1 failed, 3 blocked of 12 (46 planned steps)
Screenshots42 (4 explore, 36 scenario, 2 critic), 36 captioned
Coverage4 pages, 4 forms, 4 flows, 1 console errors
Audit1 findings, 2 re-verified live, 1 confirmed, 0 promoted, 1 withdrawn
Model calls218
Tokens930,049 input, 10,125 output, 13,693 thinking
Time11 min
Wallet2 transactions, 0 signatures, 0 refusals on chain 5042002
StageCallsInputOutputThinkingSeconds
explore32163,7612,3441,441129
plan14,0172,0812,03932
test176742,6394,7717,023473
critique817,9676482,82747
report11,6652813636

Run log

stagecallstokenstime
Explore32167.5k2m 9s
Plan18.1k32s
Test176754.4k7m 53s
Critique821.4k47s
Report12.3k6s
Total218953.9k11m 26s
Intake
Explore
Plan
Test
Critique
Report
  • 06:28:58Zexploreexplore started
  • 06:40:24ZexploreExplored / (20 controls, 0 forms)
  • 06:40:24ZexploreExplored /add-liquidity (18 controls, 0 forms)
  • 06:40:24ZexploreExplored /remove-liquidity (11 controls, 0 forms)
  • 06:40:24ZexploreExplored /bridge (14 controls, 0 forms)
  • 06:40:24ZexploreExplored /faucet (8 controls, 0 forms)
  • 06:40:24ZexploreMapped 4 pages, 4 forms, 4 flows in 32 turns.
  • 06:40:24Zexploreexplore completed in 129s.
  • 06:40:24Zplanplan started
  • 06:40:24ZplanPlanned 12 scenarios (4 high, 5 medium, 3 low).
  • 06:40:24Zplanplan completed in 32s.
  • 06:40:24Ztesttest started
  • 06:40:24ZtestS1 executed (pass)
  • 06:40:24ZtestS2 executed (pass)
  • 06:40:24ZtestS3 executed (blocked)
  • 06:40:24ZtestS4 executed (blocked)
  • 06:40:24ZtestS5 executed (pass)
  • 06:40:24ZtestS6 executed (fail), 1 finding
  • 06:40:24ZtestS7 executed (pass)
  • 06:40:24ZtestS8 executed (pass)
  • 06:40:24ZtestS9 executed (pass)
  • 06:40:24ZtestS10 executed (pass)
  • 06:40:24ZtestS11 executed (pass)
  • 06:40:24ZtestS12 executed (blocked)
  • 06:40:24ZtestExecuted 12 scenarios: 8 passed, 1 failed, 3 blocked, 1 finding.
  • 06:40:24Ztesttest completed in 473s.
  • 06:40:24Zcritiquecritique started
  • 06:40:24ZcritiqueReviewed 1 findings; 1 possible defect spotted in passed scenarios.
  • 06:40:24ZcritiqueRe-verified F1: reproduced.
  • 06:40:24ZcritiqueRe-verified a possible defect in S7: reproduced.
  • 06:40:24ZcritiqueAudit complete: 1 confirmed, 0 withdrawn, 1 promoted, 2 re-verified live.
  • 06:40:24Zcritiquecritique completed in 47s.
  • 06:40:24Zreportreport started
  • 06:40:24ZreportReported 2 issues (0 critical, 1 high, 1 medium, 0 low) from 1 finding.
  • 06:40:24Zreportreport completed in 6s.

Put an agent team on your next pull request.

Connect a repo, dispatch a Run, and read an audited, evidence-backed report the same day.