Start here
Overview
UNDO is buyer protection for USDC payments on Arc. Sellers post a bond, get paid instantly, and lost disputes are refunded from the bond.
What UNDO is
UNDO is buyer protection for USDC payments on Arc.
On Arc a payment is final in under a second. That is good for sellers and bad for anyone who pays by mistake, pays a seller who never delivers, or runs an AI agent that pays for an API response it never receives. Once the money has moved, the payer has no recourse.
UNDO adds recourse without slowing the payment down. A seller posts a USDC bond. As long as the seller's open exposure stays under bond x leverage, the seller is paid instantly. If the seller loses a dispute, the refund comes out of the bond.
The money moves, the guarantee stays.
Payments are final. Mistakes shouldn't be. Think of it as Ctrl+Z for USDC payments.
How a protected payment works
- The buyer pays through UndoPay, the payment entry point.
- UndoPay checks the seller's free capacity.
- If there is room, the seller is paid instantly and the amount is added to the seller's open exposure for the length of the refund window.
- If there is no room, the payment falls back to classic escrow until its window ends. Nothing is rejected.
- If the buyer opens a dispute and wins, the refund follows the refund waterfall.
Read How it works for the full flow.
Two lanes
UNDO is designed with two lanes that share the same bond, the same dispute process and the same fee.
| Commerce lane | Agent lane | |
|---|---|---|
| Payer | A person or a business | An AI agent or any automated client |
| Payment type | One payment per order | Many small paid calls inside a session (x402, nanopayments) |
| Refund window | 7, 14 or 30 days, chosen by the seller | From 10 minutes to 24 hours |
| Proof of delivery | Evidence reviewed in a dispute | A receipt signed by the seller on each paid response |
| Fast path | Seller has 48h to refund or contest | Missing or late receipt means an automatic refund, no arbitration |
See Commerce lane and Agent lane.
Parameters at a glance
| Parameter | Planned value |
|---|---|
| Capacity | bond x leverage |
| Leverage, first 14 days | 1x |
| Leverage, until day 30 | 2x |
| Leverage, after day 30 | 5x |
| Per-payment cap | 2,500 USDC |
| Auto-freeze to 1x | above 5% lost disputes over 30 rolling days |
| Commerce refund window | 7, 14 or 30 days |
| Agent session window | 10 minutes to 24 hours |
| Dispute deposit | 2% of the amount, minimum 1 USDC |
| Seller response time | 48h |
| Arbitrators | 3, then 7 on appeal |
| Vote deadline | 72h |
| Protocol fee | 0.5%, paid by the seller |
| Fee with $UNDO staking | 0.35% |
| Assets | USDC and EURC |
| Gas | paid in USDC |
Public seller profile
Every seller will have a public profile that both humans and agents can read before they pay. It shows:
- protected volume
- dispute rate
- lost-dispute rate
- bond
- free capacity
An agent can read the same profile on-chain and decide whether to open a session with a seller.
Where to go next
- The problem explains why final payments need a refund path.
- Capacity and leverage covers the formulas and worked examples.
- The simulator lets you try the flow. It moves no real funds.