Skip to content
Fix

Your rate stops moving the day you lock it.

Fix lets you lock an exchange rate today and take delivery on the day you actually need the money. Built natively on Arc.

The problem

You get paid in dollars. You pay rent in euros. Between payday and rent day, the exchange rate moves. Some months you’re up sixty euros, some months you’re down a hundred and forty. You never agreed to take that trade — the calendar took it for you.

Companies don’t live like this. They buy a forward from their bank and fix the rate in advance. It’s a fifty-year-old product. It has never been available to a freelancer, an expat, a parent paying tuition abroad, or a small importer. Minimum sizes too high, business account required, paperwork.

How it works

  1. Step 1.

    Deposit USDC and choose a horizon — 7, 30 or 90 days.

  2. Step 2.

    Fix quotes you a firm rate today and mints a transferable receipt worth exactly that many euros on that date.

  3. Step 3.

    On the date, redeem the receipt for EURC. Need the money sooner? Sell the receipt.

No leverage. No margin calls. No liquidations. Your deposit is funded in full up front, so the most you can lose is the premium you paid.

Under the hood

Netting first.

Every epoch, Fix matches USD→EUR demand against EUR→USD demand. Flows that offset each other cost almost nothing — each side hedges the other. This is what a corporate treasury does before it ever calls its bank.

Only the residual.

Just the net imbalance is underwritten by the Underwriting Vault (USDC and EURC deposits), which hedges continuously through Arc’s native FX engine.

The premium.

Carry — the interest rate differential, anchored on tokenised cash yields on the dollar leg — plus a spread that widens with horizon and with the epoch’s net imbalance. The vault earns that premium.

Safety bounds.

Open notional is capped per epoch and per currency. First-loss capital is staked in $FIX. The coverage ratio is published on-chain at all times. When the cap is reached, new locks are refused rather than underfunded.

Why Arc

  • Native FX engine

    the vault hedges at institutional RFQ pricing, 24/7, without an off-chain broker. On any other chain this is a fragile external dependency.

  • USDC gas

    a €200 lock isn’t eaten by fees, and you can quote a flat dollar fee to someone who has never used crypto.

  • Sub-second deterministic finality

    the rate you’re shown is the rate you get. No transaction failing thirty seconds later on a stale price.

  • Native EURC and opt-in privacy

    a product built on salaries shouldn’t publish everyone’s salary.

$FIX is not live yet.

The token has not launched. There is no contract address, no presale, no whitelist, and no private round. When $FIX goes live, the contract address will be posted in two places and two places only: @FixOnArc on X, and this page.

Anyone sending you a contract address anywhere else is trying to steal from you.

Contract address

Not yet announced
  • Staked as first-loss capital in the Underwriting Vault, earning a share of premiums and absorbing losses ahead of passive LPs.
  • 15% of premiums flow to the protocol: 10% buy-and-burn, 5% treasury.
  • Governance over three levers only: eligible currencies, maximum notional per epoch, spread curve.

Docs

Protocol documentation. Sober by design; nothing here is live yet.

01Overview

Fix is a protocol for locking an exchange rate between two stablecoins, USDC and EURC, for a fixed horizon. A user deposits the currency they hold, receives a firm rate for a chosen settlement date, and takes delivery of the other currency on that date. The position is fully funded at inception: there is no leverage, no margin and no liquidation path.

The protocol runs on Arc, Circle’s Layer 1, and relies on three of its properties: a native FX engine used for hedging, USDC as the gas token, and deterministic finality.

This documentation describes the instrument, the lifecycle of a lock, how a lock is priced, how risk is carried by the Underwriting Vault, and the role of the $FIX token. It reflects the current design. Numbers given as examples are illustrative; the actual parameters are set by governance before launch and published on-chain.

Nothing is deployed yet. There is no contract to interact with, and connecting a wallet to this page is read-only.

02The instrument

What a locked rate is

A lock is an agreement between a user and the Underwriting Vault. At inception the user deposits an amount of the source currency (for example 1,000 USDC) and chooses a settlement date T. The protocol fixes a rate R and mints a receipt that entitles its holder to a precise amount of the target currency (for example 918.44 EURC) on T. Neither the amount nor the date changes afterwards, whatever the market does.

Receipts of the same direction and settlement date are fungible with each other. They are ordinary tokens on Arc: they can be held, transferred or sold.

How it differs from a spot swap

A spot swap exchanges one currency for another now, at the current price. A lock exchanges them on a future date, at a price agreed today. Economically it is a forward contract with physical delivery. The user does not hold euros between inception and settlement; they hold a claim on euros for a specific day.

The practical difference is when the exposure ends. With a spot swap, the user carries euro exposure from the moment of the swap. With a lock, the user carries no exposure at all: the dollar amount is gone, the euro amount is fixed, and the rate in between is irrelevant to them.

Physical delivery

Settlement delivers the actual target currency, not a cash difference. On the settlement date a receipt is exchanged for EURC (or USDC, in the other direction) at the vault. Because delivery is physical, the protocol needs no reference price at expiry and therefore no price oracle at the moment of settlement. The rate was agreed at inception; settlement only moves tokens.

Why it is fully funded

The deposit is escrowed in full when the lock is created. The user cannot owe anything later, so there is no margin, no maintenance requirement and no liquidation. The vault’s obligation to deliver is backed by the user’s own deposit plus the vault’s hedges and capital. This is more capital-intensive than a bank forward, which is typically margined, but it is the only structure that works for a counterparty with no credit line and no account manager.

03Lifecycle of a lock

1. Deposit

The user selects a direction (USDC→EURC or EURC→USDC), an amount and a horizon of 7, 30 or 90 days. Horizons map to epochs: every open epoch has one settlement date, and a lock joins the epoch whose settlement date matches the chosen horizon. The deposit is transferred to the protocol at the moment the quote is accepted, not before.

2. Quote

The protocol returns a firm rate for that direction, amount and epoch. The quote is computed from the current spot reference, the carry for the horizon, and the spread for the epoch (see Pricing). A quote is valid for the transaction in which it is accepted. Because Arc finalises transactions on inclusion, there is no window in which an accepted quote can be reverted or repriced.

If the epoch’s cap on open notional would be exceeded, the quote is refused. The protocol never accepts a lock it cannot underwrite.

3. Receipt minting

On acceptance, the deposit is escrowed and a receipt is minted to the user for the exact target amount. The receipt records the direction, the settlement date and the amount. It does not record the rate; the rate is implied by the deposit and the amount, and it no longer matters.

4. Secondary transfer

A receipt can be transferred like any token. A holder who no longer needs the target currency on the settlement date can sell the receipt to someone who does. The buyer inherits the claim unchanged. The protocol does not operate a marketplace; it only guarantees that whoever holds the receipt on the settlement date can redeem it.

Before the settlement date the vault does not buy receipts back. Early exit is by transfer only. This keeps the vault’s hedging simple: its obligations for an epoch are known from inception to settlement.

5. Redemption

From the settlement date onward, a receipt can be redeemed at the vault for the target currency, one-for-one with the amount written on it. Redemption burns the receipt and transfers the tokens. At settlement the vault moves the full target amount for the epoch into a settlement escrow, so redemption does not depend on the vault’s later state.

6. Expiry handling

Receipts do not expire. A receipt that is not redeemed on the settlement date remains redeemable later for the same amount, from the same escrow. Unclaimed balances are not swept, redistributed or re-lent. The only cost of redeeming late is the opportunity cost of holding an idle claim.

04Pricing

A quoted rate has three components: the spot reference, carry, and spread. The first two are what any forward costs; the third is the vault’s compensation for underwriting the residual risk.

Carry

Carry is the interest rate differential between the two currencies over the horizon. Holding dollars for 90 days earns dollar interest; holding euros earns euro interest. A forward rate has to reflect that difference, otherwise one side could earn a riskless profit by borrowing in one currency and lending in the other. The dollar leg is anchored on tokenised cash yields available on Arc; the euro leg on a published euro short-term reference. The forward before spread is

F = S × (1 + r_usd × t) / (1 + r_eur × t)

where S is the spot reference (USD per EUR), r the annualised yields and t the horizon in years.

Spread

The spread has a fixed floor, a term that grows with the horizon, and a term that grows with the epoch’s net imbalance:

spread = s0 + s_h × (days / 30) + s_i × imbalance

imbalance is the epoch’s net residual after netting, divided by the epoch cap, between 0 and 1. It is signed by direction: a lock that adds to the residual pays the full imbalance term; a lock that offsets the residual pays a reduced one, because it lowers the amount the vault has to hedge. This is what makes netting visible in the price.

Worked example

A user deposits 1,000 USDC for a 90-day lock into EURC. Illustrative inputs:

Spot reference (USD per EUR)1.0800
Dollar yield, annualised4.80%
Euro yield, annualised2.40%
Horizon90 days (t = 0.25)
s0 / s_h / s_i0.05% / 0.03% per 30 days / 0.20%
Epoch imbalance, same direction as the user0.40

Carry-adjusted forward:

F = 1.0800 × (1 + 0.048 × 0.25) / (1 + 0.024 × 0.25) = 1.0800 × 1.0120 / 1.0060 = 1.08644

Spread:

0.05% + 0.03% × 3 + 0.20% × 0.40 = 0.05% + 0.09% + 0.08% = 0.22%

Rate quoted to the user, USD per EUR:

R = 1.08644 × (1 + 0.0022) = 1.08883

Receipt amount:

1,000 / 1.08883 = 918.42 EURC on the settlement date

At spot the same 1,000 USDC would have bought 925.93 EUR. The difference, 7.51 EUR or about 0.81%, is the premium: roughly 0.60% carry and 0.22% spread, compounded. It is the most the user can be worse off than the spot price on the day they locked. If the euro strengthens over the 90 days the user is better off than spot at settlement; if it weakens they are worse off. Either way the receipt is worth 918.42 EURC.

Had the user’s direction offset the epoch’s residual, the imbalance term would have been reduced and the quote closer to 1.0880.

05The Underwriting Vault

Deposits

The vault accepts USDC and EURC deposits from liquidity providers and issues vault shares against them. Shares accrue the vault’s share of premiums and bear its losses. Withdrawals are processed at epoch boundaries so that the vault’s capital during an epoch is known when the epoch’s locks are quoted.

Netting

Within an epoch, USD→EUR locks and EUR→USD locks with the same settlement date offset each other. A user locking dollars into euros and a user locking euros into dollars are each other’s hedge: at settlement the vault hands each what the other deposited. The vault carries no price risk on the matched portion and earns the spread on both sides.

Hedging the residual

The unmatched portion, the residual, is the vault’s exposure. The vault hedges it through Arc’s native FX engine: it requests quotes and executes at institutional pricing, on-chain, without an off-chain broker. Hedges are placed when a lock is accepted and rebalanced continuously as the residual changes, so that at any time the vault’s open exposure is a small fraction of open notional.

Coverage ratio

The coverage ratio is published on-chain and updated every block. It is the ratio of the resources available to absorb losses to the loss the residual would suffer under a stress move:

coverage = (premiums accrued + $FIX first-loss stake + LP capital) / (unhedged residual × stress move)

A coverage ratio above 1 means the vault could absorb the stress move in full. New locks are only accepted while the post-lock coverage ratio remains above the governance minimum.

First-loss waterfall

If an epoch settles at a loss, the loss is absorbed in this order:

  1. premiums earned in that epoch;
  2. $FIX staked as first-loss capital;
  3. LP capital in the vault, pro rata across shares;
  4. if all of the above is exhausted, the settlement escrow for that epoch is funded pro rata from remaining assets.

Step 4 is the failure mode the caps and the coverage ratio exist to prevent. It has a defined outcome so that the worst case is known in advance rather than improvised.

06Risk

A gap move

The vault’s risk is the residual moving against it faster than the hedge can follow. In normal conditions the hedge tracks the residual closely and the vault’s loss is limited to slippage. In a gap move, a large jump between two hedge adjustments, the unhedged part of the residual is repriced at once. The loss is bounded by

loss ≤ unhedged residual × size of the gap

Because the residual is capped per epoch and per currency, this bound is known before the epoch opens.

What the caps protect against

The caps limit the vault’s maximum loss to something its capital can absorb. They do not make the vault safer per unit of exposure; they make the total exposure small enough that a bad day is a loss, not a failure. When a cap is reached the protocol refuses new locks in that direction. It does not reduce the quality of the guarantee for locks already open.

What the vault can lose

Liquidity providers can lose capital. The vault’s losses come from hedge slippage, gap moves on the unhedged residual, and the cost of unwinding hedges if an epoch’s composition changes. Losses are absorbed first by premiums and by the $FIX first-loss stake, then by LP shares. LPs should read the coverage ratio and the caps as the description of what they are underwriting.

What the user can lose

A user locking a rate gives up the favourable side of the move: if the market ends up better than the locked rate, the user does not benefit. This is the price of certainty and it is paid in full at inception through the premium. Beyond that, the user is exposed to:

  • smart-contract risk in Fix and in the contracts it depends on;
  • stablecoin risk: a lock is between USDC and EURC, not between dollars and euros. If either token loses its peg, the receipt still delivers the token, not the fiat;
  • the residual failure mode described in the waterfall, in which an epoch is settled pro rata from remaining assets.

The user cannot lose more than the deposit, and cannot be asked for more money after inception.

07Arc integration

FX engine

Arc provides an on-chain FX engine with request-for-quote pricing from institutional liquidity providers. Fix uses it to hedge the vault’s residual. On another chain this hedge would live with an off-chain broker or a general-purpose AMM: an external dependency in the first case, a pricing and depth problem in the second. On Arc the hedge is a contract call that settles in the same block as the lock it protects.

USDC as gas

Gas on Arc is paid in USDC, so a user never needs a separate token to interact with Fix. A lock costs a predictable fraction of a cent in the currency the user already holds, which is what makes a €200 lock viable and makes it possible to state fees to a first-time user in plain dollars.

One implementation detail worth knowing: the native USDC balance on Arc is exposed with 18 decimals to the EVM, while the ERC-20 interface at 0x3600…0000 exposes the same balance with 6 decimals. Fix reads and displays balances through the ERC-20 interface.

EURC

EURC is issued natively on Arc by Circle, so the euro leg of a lock settles in the same environment as the dollar leg, without a bridge. Delivery is a token transfer, not a cross-chain message.

Finality

Arc finalises transactions on inclusion, in under a second. A quote accepted in a transaction is final when the transaction is; there is no reorganisation window in which the price could move between acceptance and confirmation. The rate the user is shown is the rate that is written to the receipt.

Opt-in privacy

Arc offers opt-in confidentiality for transfers. Fix intends to use it so that individual lock sizes are not readable by default, while the aggregate figures that matter for trust, open notional, caps and the coverage ratio, remain public. A product used to move salaries should not publish salaries.

Network details

Mainnet chain ID5042
Mainnet RPChttps://rpc.mainnet.arc.io
Mainnet explorerhttps://explorer.arc.io
Testnet chain ID5042002
Testnet RPChttps://rpc.testnet.arc.io
Native currencyUSDC (18 decimals at the RPC level, 6 on the ERC-20 interface)

08$FIX

$FIX has not launched. There is no contract address, no presale, no whitelist and no private round. When it launches, the address will be posted on @FixOnArc on X and on this page, and nowhere else.

Utility

$FIX is staked as first-loss capital in the Underwriting Vault. Stakers earn a share of the premiums the vault collects and absorb losses ahead of passive liquidity providers. Staking is the mechanism by which the people who set the protocol’s parameters are the first to pay for setting them badly.

Fee flows

Of every premium collected:

  • 85% goes to the Underwriting Vault, split between LP shares and the $FIX first-loss stake according to the risk each carries;
  • 10% is used to buy $FIX on the market and burn it;
  • 5% goes to the protocol treasury.

Governance scope

$FIX governs three parameters and nothing else:

  1. the list of eligible currencies;
  2. the maximum open notional per epoch, per currency;
  3. the spread curve (s0, s_h, s_i).

Governance cannot move user deposits, cannot change the terms of an open lock, and cannot alter the settlement escrow of a settled epoch.

09FAQ

What if I don’t need the euros anymore?

Sell the receipt. It is a transferable token and anyone who needs euros on that date can use it. If you keep it, you can still redeem it on the settlement date and swap the euros back at spot; you will have paid the premium for a certainty you ended up not needing.

What happens if the rate moves in my favour?

You do not benefit. The receipt delivers the fixed amount whatever the market does. Locking means exchanging both the downside and the upside for a known number. If you want to keep the upside, a lock is not the right product.

Is this a bet?

No. A bet takes exposure; a lock removes it. You start with an exposure you did not choose, the rate between payday and rent day, and you pay a premium to get rid of it. There is no leverage, no way to lose more than the premium relative to spot, and no position that needs watching.

What if the vault runs out of money?

Locks are only accepted while the vault’s coverage ratio stays above the minimum, and open notional is capped so that a stress move is a loss the vault can absorb. Losses hit premiums first, then the $FIX first-loss stake, then LP capital. If all of that were exhausted in an extreme event, receipts in the affected epoch would be settled pro rata from what remains. That outcome is defined in advance, and the coverage ratio is published so you can see how far from it the vault is.

What if USDC or EURC lose their peg?

A lock is between the two tokens, not between the two fiat currencies. Your receipt delivers EURC (or USDC), whatever those tokens are worth in a bank at the time. Fix does not insure the stablecoins themselves.

What does it cost?

The premium: carry plus spread, built into the rate you are quoted. There is no separate fee, and gas on Arc is a fraction of a cent, paid in USDC. The worked example in Pricing shows a 90-day lock costing about 0.8% against spot under illustrative inputs.

Is there a minimum or a maximum?

There is no minimum beyond what makes sense against gas, which on Arc is very little. The maximum is set by the epoch cap: if a lock would push the epoch’s open notional over the cap, it is refused. Horizons are 7, 30 and 90 days at launch.

Do I need a euro bank account?

Not to use Fix. You receive EURC on Arc. Moving EURC to a bank account is done through an off-ramp outside the protocol, and whether that is available depends on where you are. Fix delivers the token; it does not touch your bank.