Hosted appPrediction marketArc Testnetsucceeded

Daily crypto prediction markets settled in USDC on Arc Testnet.

Tested in place byDeepQA TeamonArc Testnetatwww.propexarc.xyz/onSep 17, 2026

Run #1model gemini-balanced (vertex)took 13m

7 of 12 scenarios passed, 5 failed, 5 issues after the audit, 2 high.

Share on X
propexarc in the browser during the run

By the numbers

7 of 12
scenarios passed, 5 failed
229
browser actions
48
screenshots
214
model calls
13
minutes
3
on-chain transactions
12
scenarios
7
passed
5
failed
0
blocked
5
issues
high2medium2low1

Walkthrough

Every scenario DeepQA drove in the browser, in plan order, with the 40 screenshots it captured along the way. A passing scenario is evidence too.

  1. S1
    Search markets by keyword

    2 steps, 2 screenshots

    pass
    S1-1.png
    S1 · Search markets by keyword
    S1-4.png
    S1 · Search markets by keyword
    • Filtered markets with keyword 'BTC' dynamically updated the list to display only the single BTC-related market 'Will BTC close above $78,662 in 24 hours?'.
    • Typing 'BTC' into the 'Search markets, categories…' search box immediately filters the active markets list to only show the BTC market 'Will BTC close above $78,662 in 24 hours?'.
  2. S2
    Filter and Sort markets

    3 steps, 3 screenshots

    pass
    S2-1.png
    S2 · Filter and Sort markets
    S2-3.png
    S2 · Filter and Sort markets
    S2-8.png
    S2 · Filter and Sort markets
    • Navigated to Markets homepage displaying all categories and markets sorted by trending.
    • Clicked 'Crypto' filter button; market list filtered down to 5 crypto-related prediction markets.
    • Sorted by 'trending', ordering the 5 Crypto markets by volume / trending metric (ARC $51.79 > BNB $25.04 > ETH $24.81 > BTC $24.42 > XRP $22.45).
    • The 'Crypto' category filter successfully filtered the active markets list to only display crypto-related prediction markets.
    • The Sort combobox correctly reorders the filtered market list based on the chosen sort criterion ('new' vs 'trending').
    • Under 'Crypto' filter and 'trending' sort, markets were displayed in descending order of trending metrics/volume.
  3. S3
    Execute Buy YES Order

    4 steps, 4 screenshots

    fail
    S3-2.png
    S3 · Execute Buy YES Order
    S3-6.png
    S3 · Execute Buy YES Order
    S3-8.png
    S3 · Execute Buy YES Order
    S3-10.png
    S3 · Execute Buy YES Order
    • Navigated to market detail page for 0x87Cd48c34eC6107310526273f46fFD1D28513B37.
    • Selected YES outcome and entered 10 USDC into the amount input.
    • Clicked submit button, button transitioned to 'Approving USDC…'.
    • Selected YES outcome and entered 10 USDC into the input field.
    • Submitted the order via 'Buy YES · $10.00' button.
    • The UI transitioned to 'Approving USDC…' before displaying an on-screen error banner stating 'Execution reverted for an unknown reason.' without successful trade execution or clear validation.
  4. S4
    Execute Buy NO Order

    4 steps, 4 screenshots

    fail
    S4-2.png
    S4 · Execute Buy NO Order
    S4-4.png
    S4 · Execute Buy NO Order
    S4-7.png
    S4 · Execute Buy NO Order
    S4-10.png
    S4 · Execute Buy NO Order
    • Navigated to the market detail page for market 0x87Cd48c34eC6107310526273f46fFD1D28513B37.
    • Selected the NO outcome button in the trading interface.
    • Entered 10 USDC into the amount input field; button updated to 'Buy NO · $10.00'.
    • Clicked 'Buy NO · $10.00', and the transaction failed with an on-screen error: 'Execution reverted for an unknown reason.'
    • Navigated to market 0x87Cd48c34eC6107310526273f46fFD1D28513B37.
    • Selected the NO outcome button.
    • Entered 10 into the USDC amount field with calculated shares of 170.49 NO at 5.8¢ avg price.
    • Clicked 'Buy NO · $10.00' which entered a 'Confirming…' state before failing with 'Execution reverted for an unknown reason.' toast and inline error.
  5. S5
    Portfolio Sync Post-Trade

    2 steps, 4 screenshots

    pass
    S5-2.png
    S5 · Portfolio Sync Post-Trade
    S5-7.png
    S5 · Portfolio Sync Post-Trade
    S5-9.png
    S5 · Portfolio Sync Post-Trade
    S5-13.png
    S5 · Portfolio Sync Post-Trade
    • Navigated to /portfolio; currently showing 0 open positions and $0.00 portfolio value.
    • Clicked 'Open' positions tab on the Portfolio page, verifying table filter and empty state display.
    • Navigated to the Portfolio page (https://www.propexarc.xyz/portfolio) where portfolio summary cards (Portfolio value, Open positions, Unrealized P&L, Claimable) and position filter tabs (All, Open, Claimable, Resolved) rendered properly.
    • Attempted a trade on market 0x87Cd48c34eC6107310526273f46fFD1D28513B37, which failed as the market is in Ended status.
    • Verified the Portfolio page 'Open' positions tab accurately filters and reflects existing position state with table headers (Market, Side, Shares, Current, Est. payout, Status) and corresponding zero/empty state matching on-chain balances.
  6. S6
    Order Form Validation - Empty Amount

    4 steps, 3 screenshots

    pass
    S6-1.png
    S6 · Order Form Validation - Empty Amount
    S6-4.png
    S6 · Order Form Validation - Empty Amount
    S6-8.png
    S6 · Order Form Validation - Empty Amount
    • Navigated to home markets list page.
    • Navigated to market detail page and observed the trade form.
    • Selected YES outcome and verified amount input is 0 / empty, with the Buy YES submit button properly disabled.
    • Navigated to the market detail page (/market/0x87Cd48c34eC6107310526273f46fFD1D28513B37).
    • Selected the YES outcome button in the trade interface.
    • Verified that when the USDC Amount input is empty or 0, the 'Buy YES · $0.00' submit button is disabled.
    • No transaction is prompted to the wallet when the amount input is empty.
  7. S7
    Order Form - MAX Shortcut Gas Reservation

    2 steps, 3 screenshots

    fail
    S7-1.png
    S7 · Order Form - MAX Shortcut Gas Reservation
    S7-4.png
    S7 · Order Form - MAX Shortcut Gas Reservation
    S7-7.png
    S7 · Order Form - MAX Shortcut Gas Reservation
    • Navigated to market detail page and observed balance of 1.85 USDC displayed in order form.
    • Clicked MAX button and observed USDC Amount populated with 1.85, which is the absolute full balance with no gas reservation.
    • Loaded the market detail page for 0x87Cd48c34eC6107310526273f46fFD1D28513B37.
    • Observed wallet balance of 1.85 USDC displayed in the order form.
    • Clicked the 'MAX' button and observed the USDC Amount field populated with '1.85', leaving 0 USDC for native gas on Arc.
  8. S8
    Order Form Validation - Insufficient Balance

    3 steps, 4 screenshots

    fail
    S8-1.png
    S8 · Order Form Validation - Insufficient Balance
    S8-4.png
    S8 · Order Form Validation - Insufficient Balance
    S8-7.png
    S8 · Order Form Validation - Insufficient Balance
    S8-9.png
    S8 · Order Form Validation - Insufficient Balance
    • Navigated to Markets home page with wallet connected.
    • Loaded market detail page showing current balance of 1.85 USDC and trading form.
    • Entered 999999999 into USDC amount input with balance of 1.85 USDC; button 'Buy YES · $999999999.00' is active and enabled without insufficient balance warning.
    • Clicked submit button and the app attempted on-chain transaction ('Approving USDC...') instead of disabling the submission with an insufficient balance warning.
    • User wallet has a balance of 1.85 USDC displayed in the order form.
    • Entering 999999999 USDC into the amount input does not show any insufficient balance error or warning.
    • The Buy submit button remains active and triggers transaction execution upon click.
  9. S9
    Market Details - Tab Navigation

    4 steps, 4 screenshots

    pass
    S9-3.png
    S9 · Market Details - Tab Navigation
    S9-5.png
    S9 · Market Details - Tab Navigation
    S9-7.png
    S9 · Market Details - Tab Navigation
    S9-9.png
    S9 · Market Details - Tab Navigation
    • Navigated to market detail page where the About tab is displayed by default.
    • Clicked 'Rules & Oracle' tab; panel rendered Market mechanics, Resolution source, Fees, and Cancellation details without page reload.
    • Clicked 'Activity' tab; content panel updated to display off-chain activity status ("Coming soon") without reloading the page.
    • Clicked 'Holders' tab; content panel updated to display Holders view placeholder ("Coming soon") without reloading the page.
    • Navigated to the market details page for market 0x87Cd48c34eC6107310526273f46fFD1D28513B37 where the About tab is rendered by default.
    • Clicked the 'Rules & Oracle' tab button and verified that the mechanics, resolution source, fee structure, and cancellation policy panel rendered without page reload.
    • Clicked the 'Activity' tab button and verified that the indexed off-chain activity panel rendered without page reload.
    • Clicked the 'Holders' tab button and verified that the holders view panel rendered without page reload.
    • Clicked back to the 'About' tab and verified smooth tab switching with full context preservation.
  10. S10
    Order Form Validation - Invalid Characters

    2 steps, 3 screenshots

    pass
    S10-1.png
    S10 · Order Form Validation - Invalid Characters
    S10-4.png
    S10 · Order Form Validation - Invalid Characters
    S10-10.png
    S10 · Order Form Validation - Invalid Characters
    • Started at the home page and navigating to a market detail page.
    • Navigated to the market detail page where the order form with USDC Amount input (type=number) is rendered.
    • Attempted to input invalid non-numeric characters ('abc!@#') into the USDC Amount field; the input field enforces type=number and rejects non-numeric entries, maintaining clean empty/zero state without displaying NaN or crashing.
    • The USDC Amount input is configured with type='number' and min='0'.
    • Typing non-numeric characters like 'abc!@#' is rejected by the input control.
    • The form values safely default to placeholders ('—' and '$0.00') without rendering NaN or encountering application errors.
  11. S11
    Portfolio - Deposit USDC Trigger

    2 steps, 3 screenshots

    fail
    S11-3.png
    S11 · Portfolio - Deposit USDC Trigger
    S11-6.png
    S11 · Portfolio - Deposit USDC Trigger
    S11-11.png
    S11 · Portfolio - Deposit USDC Trigger
    • Navigated to the Portfolio page showing the user's wallet overview and Deposit USDC button.
    • Clicked the 'Deposit USDC' button on the Portfolio page, but no modal or expanded section appeared and no action was triggered.
    • Navigated to the Portfolio page (/portfolio).
    • Located the 'Deposit USDC' button beside the 'Withdraw · soon' button.
    • Clicked the 'Deposit USDC' button repeatedly, but no modal, expanded section, wallet prompt, or testnet faucet trigger appeared.
  12. S12
    Clipboard Permission Error Investigation

    2 steps, 3 screenshots

    pass
    S12-1.png
    S12 · Clipboard Permission Error Investigation
    S12-4.png
    S12 · Clipboard Permission Error Investigation
    S12-6.png
    S12 · Clipboard Permission Error Investigation
    • Opened the wallet info dialog displaying address 0xB4…62A6 and balance 1.85 USDC.
    • Clicked Copy Address button in wallet modal; the button label updated to 'Copied!' confirming successful copy feedback.
    • Navigated to Markets homepage and clicked wallet info button in the top navigation bar.
    • Wallet dialog opened showing wallet address and balance.
    • Clicked 'Copy Address' button; the button state immediately changed to 'Copied!' providing immediate feedback.

Issues

Findings that survived the Critic's audit. Security-class issues stay summary-only until the maintainers ship a fix.

highconfirmed ✓functionalF1 · S3

Buy order submission for YES outcome fails with 'Execution reverted for an unknown reason'

I successfully navigated to the market 0x87Cd48c34eC6107310526273f46fFD1D28513B37, selected YES, input 10 for USDC amount, and clicked the buy button. I observed that the transaction fails and the user interface displays the error message 'Execution reverted for an unknown reason.' The page reported 1 console error during the scenario.

Expected

The transaction should execute successfully or show client-side balance validation / meaningful error guidance.

Actual

The transaction reverts during execution with the error message 'Execution reverted for an unknown reason.'

Repro · 4 steps
  1. Navigate to https://www.propexarc.xyz/market/0x87Cd48c34eC6107310526273f46fFD1D28513B37
  2. Select the 'YES' outcome button
  3. Enter '10' into the USDC Amount input field
  4. Click the 'Buy YES · $10.00' submit button
highconfirmed ✓functionalF2 · S4

Buy NO order execution fails with 'Execution reverted for an unknown reason.'

I navigated to the specified market URL, selected the 'NO' option, and attempted to buy $10 worth of shares. The transaction failed, and the UI displayed the error message 'Execution reverted for an unknown reason.' just as reported. The page reported 1 console error during the scenario.

Expected

The transaction should be submitted successfully and confirmed in the UI, or clear balance validation/approval guidance should prevent contract revert.

Actual

The transaction reverted on-chain with the error 'Execution reverted for an unknown reason.' and was not confirmed.

Repro · 4 steps
  1. Navigate to 'https://www.propexarc.xyz/market/0x87Cd48c34eC6107310526273f46fFD1D28513B37'.
  2. Click the 'NO' outcome button.
  3. Enter '10' into the USDC amount input field.
  4. Click 'Buy NO · $10.00'.
mediumconfirmed ✓functionalF4 · S8

Order form allows submission with amount exceeding available wallet balance

The evidence shows the application attempts to initiate an on-chain transaction for an amount drastically exceeding the wallet's balance instead of validating it client-side. The page reported 1 console error during the scenario.

Expected

The application should validate the input against the user's available USDC balance (1.85 USDC), display an 'insufficient balance' warning, and disable the submission button.

Actual

The application allowed clicking the submit button ('Buy YES · $999999999.00') without balance validation, and attempted to send an on-chain transaction ('Approving USDC...').

Repro · 4 steps
  1. Navigate to a market detail page (e.g., /market/0x87Cd48c34eC6107310526273f46fFD1D28513B37).
  2. Type '999999999' into the 'USDC Amount' input field.
  3. Observe that the submit button is enabled with 'Buy YES · $999999999.00' and click it.
  4. Observe that the app proceeds to submit a transaction ('Approving USDC...') instead of showing an insufficient balance warning and disabling submission.
mediumconfirmed ✓functionalF5 · S11

'Deposit USDC' button on Portfolio page is non-functional

The observation confirms that repeatedly clicking the 'Deposit USDC' button yields no visual feedback or action. The page reported 2 console errors during the scenario.

Expected

A modal or expanded section should appear displaying deposit options, wallet details, or a testnet faucet trigger.

Actual

Clicking the 'Deposit USDC' button produces no visual feedback, modal, or action.

Repro · 2 steps
  1. Navigate to https://www.propexarc.xyz/portfolio
  2. Click on the 'Deposit USDC' button in the portfolio overview header
lowpromoted ↑uxF6 · S12

Copy Address button shows false 'Copied!' success message when clipboard write fails

Surfaced by the audit of S12, which the Tester passed, and reproduced live: I clicked the wallet button to open the wallet info dialog, then clicked the 'Copy Address' button. Its state changed to 'Copied!' (as seen in button text 'CopiedCopied!') even though a clipboard copy failure would normally be expected in this restricted browser environment, corroborating the bug report that it fails to handle clipboard errors gracefully. The page reported 2 console errors during the scenario.

Expected

The UI should handle clipboard write errors gracefully and not display a success message if the copy operation actually failed.

Actual

The button state changes to 'Copied!' while the console logs a 'Write permission denied' error for the clipboard.

Repro · 2 steps
  1. Open the wallet info dialog.
  2. Click the 'Copy Address' button.
mediumwithdrawnfunctionalF3 · S7

Order form MAX shortcut populates full balance without native gas reservation

The finding assumes USDC must be reserved for gas, but gas on this network is paid in the native token (Arc), meaning it is correct to populate the absolute full balance of the USDC token. The page reported 3 console errors during the scenario.

Expected

The USDC Amount input should populate with the total USDC balance minus a native gas reservation so transactions do not fail due to insufficient funds for Arc native gas fees.

Actual

The USDC Amount input is populated with the wallet's absolute full balance (1.85 USDC), reserving 0 USDC for gas.

Repro · 4 steps
  1. Navigate to /market/0x87Cd48c34eC6107310526273f46fFD1D28513B37
  2. Locate the order form with displayed wallet balance (e.g. 1.85 USDC)
  3. Click the 'MAX' shortcut button next to the USDC Amount input
  4. Observe the value populated in the amount input

Wallet activity

DeepQA injected a test wallet into the browser and recorded every request the app sent to it. Testnet funds only.

address
0xB412E2…Ab62A6
chain
Arc Testnet
browsers opened
3
read requests forwarded
0
signing requests
10
time (UTC)methodsummaryresult
19:00:19eth_sendTransactionto 0x3600000000000000000000000000000000000000 value 0 data 68 bytestx 0xea3470…94affb
19:00:20eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000f424000000000000000000000000000000000000000000000000000000000000eee42 Details: execution reverted Version: viem@2.56.5
19:02:39eth_sendTransactionto 0x3600000000000000000000000000000000000000 value 0 data 68 bytestx 0xbd7749…19cf29
19:02:44eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000009896800000000000000000000000000000000000000000000000000000000000954825 Details: execution reverted Version: viem@2.56.5
19:03:26eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000989680000000000000000000000000000000000000000000000000000000000a0f6ed1 Details: execution reverted Version: viem@2.56.5
19:04:03eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000f424000000000000000000000000000000000000000000000000000000000000eee42 Details: execution reverted Version: viem@2.56.5
19:05:39eth_sendTransactionto 0x3600000000000000000000000000000000000000 value 0 data 68 bytestx 0xd68e57…8322e1
19:05:44eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000038d7ea4b73dc0000000000000000000000000000000000000000000000000000376e4cd544c19 Details: execution reverted Version: viem@2.56.5
19:09:30eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000009896800000000000000000000000000000000000000000000000000000000000954825 Details: execution reverted Version: viem@2.56.5
19:09:56eth_sendTransactionto 0x87Cd48c34eC6107310526273f46fFD1D28513B37 value 0 data 100 bytesrefused: Execution reverted for an unknown reason. Request Arguments: chain: Arc Testnet (id: 5042002) from: 0xB412E2B09ea8B59b1cf1c8f29aA4C56fE9Ab62A6 to: 0x87Cd48c34eC6107310526273f46fFD1D28513B37 data: 0x01a9812c00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000989680000000000000000000000000000000000000000000000000000000000a0f6ed1 Details: execution reverted Version: viem@2.56.5

Critic audit

An adversarial second pass over every finding before it reaches the report.

5
findings reviewed
5
re-verified live
1
withdrawn
  • F1confirmed ✓

    I successfully navigated to the market 0x87Cd48c34eC6107310526273f46fFD1D28513B37, selected YES, input 10 for USDC amount, and clicked the buy button. I observed that the transaction fails and the user interface displays the error message 'Execution reverted for an unknown reason.'

  • F2confirmed ✓

    I navigated to the specified market URL, selected the 'NO' option, and attempted to buy $10 worth of shares. The transaction failed, and the UI displayed the error message 'Execution reverted for an unknown reason.' just as reported.

  • F3withdrawn

    The finding assumes USDC must be reserved for gas, but gas on this network is paid in the native token (Arc), meaning it is correct to populate the absolute full balance of the USDC token.

  • F4confirmed ✓

    The evidence shows the application attempts to initiate an on-chain transaction for an amount drastically exceeding the wallet's balance instead of validating it client-side.

  • F5confirmed ✓

    The observation confirms that repeatedly clicking the 'Deposit USDC' button yields no visual feedback or action.

  • F6promoted ↑

    Surfaced by the audit of S12, which the Tester passed, and reproduced live: I clicked the wallet button to open the wallet info dialog, then clicked the 'Copy Address' button. Its state changed to 'Copied!' (as seen in button text 'CopiedCopied!') even though a clipboard copy failure would normally be expected in this restricted browser environment, corroborating the bug report that it fails to handle clipboard errors gracefully.

  • F1 and F2 test trades on a market that S5 explicitly notes is 'Ended', meaning the on-chain revert is the expected behavior and only the generic error message is a defect.
  • F3 incorrectly expects an ERC-20 token (USDC) to be reserved for native gas fees.
  • S12 passed despite clear console evidence that the clipboard copy failed while the UI falsely reported success.
  • A possible defect in S5 ("CoinGecko price API requests fail due to CORS policy block") was not promoted: the live replay came back not-reproduced.
  • A possible defect in S1 ("Frequent HTTP 429 (Too Many Requests) errors during normal navigation") was not promoted: the live replay came back inconclusive.

Report

QA report: external/www.propexarc.xyz at hosted

Core trade executions fail with unhandled on-chain revert errors, alongside missing order balance validation and non-functional deposit controls.

Testing covered 12 deep feature scenarios across market discovery, tab navigation, order configuration and validation, and portfolio management. Market browsing, search filtering, and basic input validations passed without issues.

Critical trade actions failed during execution, where both Buy YES and Buy NO orders triggered unhandled on-chain reverts. The order form also fails to validate available wallet balances before initiating token approval transactions, allowing submissions with exorbitant amounts. Furthermore, the Deposit USDC action on the portfolio page is entirely non-functional, and the copy address control falsely indicates success when clipboard writes are blocked.

Five confirmed issues remain, while one finding regarding ERC-20 gas reservation was withdrawn during audit. Because core trading flows and deposit entry points are broken, these defects prevent standard market operations.

Run summary
MetricCount
Scenarios executed12
Passed7
Failed5
Blocked0
Findings raised5
Issues after the audit5
Withdrawn by the audit1
Critical / high / medium / low0 / 2 / 2 / 1

Target: https://www.propexarc.xyz/ · Testing level: deep_feature · Stack: unknown

Issues
High severity
F1 · Buy order submission for YES outcome fails with 'Execution reverted for an unknown reason'

Severity: high · Type: functional · Verdict: confirmed · Scenario: S3

I successfully navigated to the market 0x87Cd48c34eC6107310526273f46fFD1D28513B37, selected YES, input 10 for USDC amount, and clicked the buy button. I observed that the transaction fails and the user interface displays the error message 'Execution reverted for an unknown reason.' The page reported 1 console error during the scenario.

Expected: The transaction should execute successfully or show client-side balance validation / meaningful error guidance.

Actual: The transaction reverts during execution with the error message 'Execution reverted for an unknown reason.'

Steps to reproduce:

  1. Navigate to https://www.propexarc.xyz/market/0x87Cd48c34eC6107310526273f46fFD1D28513B37
  2. Select the 'YES' outcome button
  3. Enter '10' into the USDC Amount input field
  4. Click the 'Buy YES · $10.00' submit button

Evidence: screenshots/S3-6.png, screenshots/S3-8.png, screenshots/S3-10.png

F2 · Buy NO order execution fails with 'Execution reverted for an unknown reason.'

Severity: high · Type: functional · Verdict: confirmed · Scenario: S4

I navigated to the specified market URL, selected the 'NO' option, and attempted to buy $10 worth of shares. The transaction failed, and the UI displayed the error message 'Execution reverted for an unknown reason.' just as reported. The page reported 1 console error during the scenario.

Expected: The transaction should be submitted successfully and confirmed in the UI, or clear balance validation/approval guidance should prevent contract revert.

Actual: The transaction reverted on-chain with the error 'Execution reverted for an unknown reason.' and was not confirmed.

Steps to reproduce:

  1. Navigate to 'https://www.propexarc.xyz/market/0x87Cd48c34eC6107310526273f46fFD1D28513B37'.
  2. Click the 'NO' outcome button.
  3. Enter '10' into the USDC amount input field.
  4. Click 'Buy NO · $10.00'.

Evidence: screenshots/S4-10.png

Medium severity
F4 · Order form allows submission with amount exceeding available wallet balance

Severity: medium · Type: functional · Verdict: confirmed · Scenario: S8

The evidence shows the application attempts to initiate an on-chain transaction for an amount drastically exceeding the wallet's balance instead of validating it client-side. The page reported 1 console error during the scenario.

Expected: The application should validate the input against the user's available USDC balance (1.85 USDC), display an 'insufficient balance' warning, and disable the submission button.

Actual: The application allowed clicking the submit button ('Buy YES · $999999999.00') without balance validation, and attempted to send an on-chain transaction ('Approving USDC...').

Steps to reproduce:

  1. Navigate to a market detail page (e.g., /market/0x87Cd48c34eC6107310526273f46fFD1D28513B37).
  2. Type '999999999' into the 'USDC Amount' input field.
  3. Observe that the submit button is enabled with 'Buy YES · $999999999.00' and click it.
  4. Observe that the app proceeds to submit a transaction ('Approving USDC...') instead of showing an insufficient balance warning and disabling submission.

Evidence: screenshots/S8-7.png, screenshots/S8-9.png

F5 · 'Deposit USDC' button on Portfolio page is non-functional

Severity: medium · Type: functional · Verdict: confirmed · Scenario: S11

The observation confirms that repeatedly clicking the 'Deposit USDC' button yields no visual feedback or action. The page reported 2 console errors during the scenario.

Expected: A modal or expanded section should appear displaying deposit options, wallet details, or a testnet faucet trigger.

Actual: Clicking the 'Deposit USDC' button produces no visual feedback, modal, or action.

Steps to reproduce:

  1. Navigate to https://www.propexarc.xyz/portfolio
  2. Click on the 'Deposit USDC' button in the portfolio overview header

Evidence: screenshots/S11-3.png, screenshots/S11-6.png, screenshots/S11-11.png

Low severity
F6 · Copy Address button shows false 'Copied!' success message when clipboard write fails

Severity: low · Type: ux · Verdict: promoted · Scenario: S12

Surfaced by the audit of S12, which the Tester passed, and reproduced live: I clicked the wallet button to open the wallet info dialog, then clicked the 'Copy Address' button. Its state changed to 'Copied!' (as seen in button text 'CopiedCopied!') even though a clipboard copy failure would normally be expected in this restricted browser environment, corroborating the bug report that it fails to handle clipboard errors gracefully. The page reported 2 console errors during the scenario.

Expected: The UI should handle clipboard write errors gracefully and not display a success message if the copy operation actually failed.

Actual: The button state changes to 'Copied!' while the console logs a 'Write permission denied' error for the clipboard.

Steps to reproduce:

  1. Open the wallet info dialog.
  2. Click the 'Copy Address' button.

Evidence: screenshots/critic-M2-1.png

Withdrawn findings

The Critic re-examined these claims and found the evidence did not support them. They are kept here rather than deleted.

  • Order form MAX shortcut populates full balance without native gas reservation (S7, medium): The finding assumes USDC must be reserved for gas, but gas on this network is paid in the native token (Arc), meaning it is correct to populate the absolute full balance of the USDC token. The page reported 3 console errors during the scenario.
Scenario results
ScenarioPriorityResultIssues
S1 Search markets by keywordhighpassnone
S2 Filter and Sort marketshighpassnone
S3 Execute Buy YES OrderhighfailF1
S4 Execute Buy NO OrderhighfailF2
S5 Portfolio Sync Post-Tradehighpassnone
S6 Order Form Validation - Empty Amounthighpassnone
S7 Order Form - MAX Shortcut Gas Reservationmediumfailnone
S8 Order Form Validation - Insufficient BalancemediumfailF4
S9 Market Details - Tab Navigationmediumpassnone
S10 Order Form Validation - Invalid Charactersmediumpassnone
S11 Portfolio - Deposit USDC TriggerlowfailF5
S12 Clipboard Permission Error InvestigationlowpassF6
The audit

The Critic reviewed 5 findings and re-verified 5 of them live in the browser, replaying the reported steps on a fresh page.

  • F1 and F2 test trades on a market that S5 explicitly notes is 'Ended', meaning the on-chain revert is the expected behavior and only the generic error message is a defect.
  • F3 incorrectly expects an ERC-20 token (USDC) to be reserved for native gas fees.
  • S12 passed despite clear console evidence that the clipboard copy failed while the UI falsely reported success.
  • A possible defect in S5 ("CoinGecko price API requests fail due to CORS policy block") was not promoted: the live replay came back not-reproduced.
  • A possible defect in S1 ("Frequent HTTP 429 (Too Many Requests) errors during normal navigation") was not promoted: the live replay came back inconclusive.
What to fix first
  1. Resolve on-chain order execution failures and clarify revert messaging for Buy YES orders (F1).
  2. Resolve on-chain order execution failures and clarify revert messaging for Buy NO orders (F2).
  3. Add client-side wallet balance validation to block order submissions exceeding available funds (F4).
  4. Hook up the Deposit USDC button on the Portfolio page to its corresponding action (F5).
  5. Catch clipboard permission denials and suppress the false success message on the copy address button (F6).
Coverage and caveats

In scope: Prediction Market Search, Filter, and Sort; Market detail tab navigation; Buy YES and Buy NO order placement; Order form validation (empty, invalid, insufficient funds); MAX balance calculation with Arc native gas reservation; Portfolio positions synchronization.

Not covered: Leaderboard detailed metrics validation (Excluded to focus deeply on the core trading and market feature).; Docs smart contract address validation (Out of scope for trading deep feature).; Ended market transaction failure (No ended market explicitly provided in the AppMap)..

  • Market 0x87Cd48c34eC6107310526273f46fFD1D28513B37 is active and has not reached its end date.
  • The connected test wallet has a non-zero USDC balance on the Arc testnet.
  • The 'MAX' button is present within or next to the USDC Amount input as described in the flows.
  • The 'Wallet info button' includes a copy-to-clipboard function that triggered the observed clipboard permission error.
By the numbers
MetricValue
Scenarios7 passed, 5 failed, 0 blocked of 12 (34 planned steps)
Browser actions229 (52 clicks, 19 inputs, 40 navigations, 118 snapshots)
Screenshots48 (4 explore, 40 scenario, 4 critic), 40 captioned
Coverage5 pages, 2 forms, 5 flows, 2 console errors
Audit5 findings, 5 re-verified live, 4 confirmed, 1 promoted, 1 withdrawn
Model calls214
Tokens1,977,890 input, 13,294 output, 18,931 thinking
Time13 min
Wallet3 transactions, 0 signatures, 7 refusals on chain 5042002
StageCallsInputOutputThinkingSeconds
explore27273,7092,3501,50294
plan14,0732,1313,18344
test1501,412,7456,4536,514418
critique35285,3332,0357,049196
report12,0303256838

Run log

stagecallstokenstime
Explore27277.6k1m 34s
Plan19.4k44s
Test1501.4M6m 58s
Critique35294.4k3m 16s
Report13k8s
Total2142M12m 40s
Intake
Explore
Plan
Test
Critique
Report
  • 18:59:13Zexploreexplore started
  • 19:11:54ZexploreExplored / (44 controls, 0 forms)
  • 19:11:54ZexploreExplored /portfolio (29 controls, 0 forms)
  • 19:11:54ZexploreExplored /leaderboard (26 controls, 0 forms)
  • 19:11:54ZexploreExplored /docs (42 controls, 0 forms)
  • 19:11:54ZexploreExplored /market/0x87Cd48c34eC6107310526273f46fFD1D28513B37 (48 controls, 1 forms)
  • 19:11:54ZexploreMapped 5 pages, 2 forms, 5 flows in 27 turns.
  • 19:11:54Zexploreexplore completed in 94s.
  • 19:11:54Zplanplan started
  • 19:11:54ZplanPlanned 12 scenarios (6 high, 4 medium, 2 low).
  • 19:11:54Zplanplan completed in 44s.
  • 19:11:54Ztesttest started
  • 19:11:54ZtestS1 executed (pass)
  • 19:11:54ZtestS2 executed (pass)
  • 19:11:54ZtestS3 executed (fail), 1 finding
  • 19:11:54ZtestS4 executed (fail), 1 finding
  • 19:11:54ZtestS5 executed (pass)
  • 19:11:54ZtestS6 executed (pass)
  • 19:11:54ZtestS7 executed (fail), 1 finding
  • 19:11:54ZtestS8 executed (fail), 1 finding
  • 19:11:54ZtestS9 executed (pass)
  • 19:11:54ZtestS10 executed (pass)
  • 19:11:54ZtestS11 executed (fail), 1 finding
  • 19:11:54ZtestS12 executed (pass)
  • 19:11:54ZtestExecuted 12 scenarios: 7 passed, 5 failed, 0 blocked, 5 findings.
  • 19:11:54Ztesttest completed in 418s.
  • 19:11:54Zcritiquecritique started
  • 19:11:54ZcritiqueReviewed 5 findings; 3 possible defects spotted in passed scenarios.
  • 19:11:54ZcritiqueRe-verified F1: reproduced.
  • 19:11:54ZcritiqueRe-verified F2: reproduced.
  • 19:11:54ZcritiqueRe-verified a possible defect in S5: not-reproduced.
  • 19:11:54ZcritiqueRe-verified a possible defect in S12: reproduced.
  • 19:11:54ZcritiqueRe-verified a possible defect in S1: inconclusive.
  • 19:11:54ZcritiqueAudit complete: 4 confirmed, 1 withdrawn, 1 promoted, 5 re-verified live.
  • 19:11:54Zcritiquecritique completed in 196s.
  • 19:11:54Zreportreport started
  • 19:11:54ZreportReported 5 issues (0 critical, 2 high, 2 medium, 1 low) from 5 findings.
  • 19:11:54Zreportreport completed in 8s.

Put an agent team on your next pull request.

Connect a repo, dispatch a Run, and read an audited, evidence-backed report the same day.