Security concerns are widening around Arc’s official bridge page as users describe alleged USDC transfers to attacker-controlled addresses and warn of spoofed interfaces.
Users have reported a series of alleged phishing incidents tied to OnBridge, the official cross-chain bridge on Arc, Circle’s stablecoin-focused layer-one blockchain. Multiple cryptocurrency communities said held USDC was sent to attacker-controlled addresses after users initiated cross-chain transfers. The method remains under investigation, but the reports suggest victims may have been directed to malicious versions of the bridge interface through search ads, phishing emails or compromised social media posts. The episode has renewed concerns about cross-chain security, especially because bridge transactions require users to approve token movements and interact with contracts that can be abused if the interface is spoofed. Circle had not issued an official statement in the source material, while security analysts urged users to verify URLs, avoid unsolicited links, use hardware wallets and review token approvals.