ArcadeMachineManager
Machines, versioned reward tables, and the spin lifecycle.
Freezes price, machine, version and player into each spin. Enforces maximum-liability before accepting one. Settlement is permissionless.
Configuration, inventory, randomness and settlement are four different contracts with four different role sets. That separation is what makes the system auditable.
Machines, versioned reward tables, and the spin lifecycle.
Freezes price, machine, version and player into each spin. Enforces maximum-liability before accepting one. Settlement is permissionless.
Custodies reward inventory and enforces solvency.
Holds the invariant balance >= reserved for every token. The treasurer can only withdraw unreserved surplus, so a won prize cannot be withdrawn by an administrator.
The allowlist of tokens that may be awarded.
Asserts symbol and decimals against the token contract at registration. Decimals are immutable afterwards. Guardians can pause a token; only the registry admin can unpause.
Verifiable randomness without a VRF.
Commitments are published in advance and consumed in strict order. Implements IRandomnessSource so a VRF adapter can replace it without redeploying anything else.
Splits spin revenue between reward funding and treasury.
Accumulates rather than forwarding on receipt, so a failing destination can never make a spin settlement revert. Cannot touch the prize vault.
No role can alter a settled outcome. Pausing stops new spins and never strands one in flight. A production deployment should hold the top-level admin role in a multisig and split the others across separate signers.
Native USDC on Arc uses 18 decimals; the USDC ERC-20 interface uses 6. Arcade prices spins in the native asset, so every spin price in this codebase is an 18-decimal value. Mixing the two is a documented Arc footgun.
These contracts have not been reviewed by an independent security firm. They ship with 61 unit, fuzz and invariant tests, including a solvency invariant driven through thousands of randomised call sequences covering concurrent spins, abandoned randomness, hostile tokens and adversarial treasury withdrawals.
That is meaningful evidence and it is not an audit. Anyone considering a production deployment should commission one, and should read the security assumptions section of the repository README first.

Photographs used as editorial accents. Licences and author credits are read from the source API at download time rather than transcribed, and recorded in public/media/media-attribution.json.