Check the address before the money leaves.
Part of five calls for Arc builders (one key, plain fetch). One call your app makes before it sends USDC or a token on Arc. It answers stop, check or ok, with the reasons, in about 0.1 seconds. $0.001 per check, paid over x402. Nothing to sign up for.
const { verdict, reasons } = await sendGuard({ from, to, token })
if (verdict === 'stop') throw new Error(reasons[0].message) // do not build the transaction
if (verdict === 'check') await askUserToConfirm(reasons) // show why, ask again
// 'ok': send
Install: npm install github:apexfaucet-hub/arc-send-guard (GitHub) · or the single-file snippet (official x402 client, fails closed: no answer, no send): send-guard.mts · test fixtures for CI: send-guard-fixtures.json · MCP tool arc_send_guard
What it stops
- lookalike: the destination shares its first and last characters with an address the sender really paid. The classic poisoning trap.
- poison-bait: the destination appears in the sender's history only through forged transfers that a fake token wrote and nobody signed.
- token-contract, burn: sending to a token contract (including USDC's own) or the burn address loses the money.
- sanctioned, usdc-blacklisted: on the OFAC SDN list, or frozen by USDC's own contract on Arc.
- impostor-token: the token calls itself USDC or EURC but is not Circle's contract.
Marked check (look again): a brand-new address with no history, a contract that is not a token, sending to yourself, or a source we could not read just now. A failed read is never an "ok".
A real attack on Arc, 9 Oct 2026
A stranger called a fake "USDC" contract that wrote 64 invented transfers in one transaction. One of them was "from" our UBI wallet to 0x024b820fe19d85a4558ac38cac83ac231070700c, a lookalike of our operator 0x024b82335c29fa5606a8ea5c1d24fc9ead50700c: the same first 6 and last 5 characters. Nothing moved; the trap is that someone copies the lookalike next time they pay.
GET /api/x402/arc-send-guard?from=0x6cf1…c9a0&to=0x024b820f…0700c
verdict: "stop"
poison-bait: this address is in your history only through forged transfers
lookalike: shares its first 6 and last 5 hex characters with 0x024b8233…0700c,
an address you really used
to=0x024b8233…0700c (the real operator) -> verdict: "ok" (known counterparty)
Price and payment
$0.001 per check in USDC on Arc, Base or Solana, through the standard x402 flow: your client gets a 402, signs the payment, gets the answer. No account, no key. A malformed address is refused before payment, and so is a read that fails. Endpoint: GET https://apexfaucet.xyz/api/x402/arc-send-guard?from=0x…&to=0x… (add &token=0x… for a token send).
Related: signal registry (which tool carries which warning) · token info before you show a token (/api/x402/arc-token-info, $0.002) · allowance check before you ask for an approval (/api/x402/arc-allowance, $0.001) · wallet check for people · llms.txt