DEX–Arbitrum Vault: operation and security
CoinRobot trades on Arbitrum through a user-owned Vault smart contract. The Vault holds the trading capital; a separate CoinRobot bot-wallet submits the automated trade calls and pays their network fees. Your owner private key is never required by CoinRobot.
Read the complete CoinRobot trading flow for the common route from market data and strategy decisions to execution and balance monitoring.
Bot-wallet + ETH fee↑ trade callYour DEX Vault
Vault and bot-wallet: two addresses, one trading flow
The Vault is where trading capital is held. A smart contract cannot autonomously submit its own transactions, so CoinRobot assigns a separate bot-wallet that signs the automated trade calls to the Vault. The network fee therefore appears on the bot-wallet, not on the trading-capital balance inside the Vault.
Arbitrum fees are paid in native ETH. The bot-wallet needs a small initial ETH balance. After that, if ETH becomes low and sufficient USDC is available on the bot-wallet, the robot can attempt to buy ETH automatically. Vault and bot-wallet balances are visible from the Dashboard.
Terms and network details
- Arbitrum One
- Ethereum Layer 2 network, chain ID
42161. - Vault
- The user-owned smart contract that holds trading capital and applies token/router/spend/minimum-output restrictions.
- Bot-wallet
- The separate CoinRobot technical wallet that submits automated trade transactions to the Vault and pays their gas.
- USDC
- The default stablecoin used for trading capital and fee replenishment.
Your integration addresses
0x0f239418a54268f892f0779Ab338bA1675BaFa67Log in and deploy your own Connector Vault before funding.
Log in to view your personal bot address.This wallet drives automated Vault trades. Keep only the small ETH/USDC fee reserve required for execution here; trading capital belongs in the Vault.
Why the Vault is useful
The Vault is a smart contract that lets CoinRobot execute constrained trading on the owner's behalf without the owner giving CoinRobot any private key. The owner creates the Vault and remains the privileged management authority. Automated swaps are constrained by the contract's token and router allowlists and by spend/minimum-output checks.
Why there is a separate bot-wallet
The bot-wallet is the transaction initiator for CoinRobot automation. It signs the trade calls that make the Vault execute a swap, and the gas cost of those calls is charged to this wallet. This separates day-to-day automation and fee funding from the owner's wallet.
Withdrawal is separate from trading
The bot-wallet may initiate the supported withdrawAll path, but that path can return assets only to the immutable owner. Only the owner can use owner-only withdrawal functions to choose another recipient. The owner can also manage withdrawals directly through the Arbitrum contract interface, independently of CoinRobot.
- Connect the owner wallet and deploy the Vault.
- Fund the Vault with trading USDC.
- Fund the bot-wallet with a small amount of native ETH for initial gas; optional USDC on the bot-wallet can be used for later fee replenishment.
- Create a Plan and start it. CoinRobot evaluates the strategy; the bot-wallet submits the trade call; the Vault swaps through an approved router.
- Monitor both Vault capital and bot-wallet fee balance on the Dashboard.
- When you want to exit, stop the Plan and use the withdrawal flow; withdrawal rules are independent of the trading loop described above.
Permission model
| Operation | Owner | Bot-wallet | Boundary |
|---|---|---|---|
| Automated CoinRobot swap | No | Yes | CoinRobot automation is submitted by the configured bot-wallet and remains limited by token/router/spend/min-output checks. |
| Return all assets to owner | Yes | May initiate | Recipient is fixed to the immutable owner. |
| Withdraw token/native ETH to an arbitrary recipient | Yes | No | Owner-only. |
| Change bot, routers or token list | Yes | No | Owner-only. |
Technical note: the current v1.6 contract also permits the owner address to call trade directly at contract level. The table above describes the CoinRobot automation path, where the bot-wallet is the transaction signer.
Approved routers
The current v1.6 Vault restricts trades to the configured 1inch, 0x and KyberSwap router addresses. Router addresses can be updated only by the owner; the Vault rejects trade calls to targets outside its configured router set.
constructor(_botAddress, _initialTokens) owner + bot + initial token/router setup
trade(router, tokenIn, tokenOut, amountIn, minAmountOut, data) constrained swap
withdrawAll() bot/owner may return all assets to owner
withdrawToken(token, to, amount) owner-only targeted token withdrawal
withdrawNative(to, amount) owner-only native ETH withdrawal
updateRouters(...) owner-only router configuration
addToken(token) / removeToken(token) owner-only token allowlist
setBotAddress(newBot) owner-only bot-wallet change
getAllowedTokens() / readers public state inspectionOperational security checklist
- Send trading capital only to your Vault; send only the required fee reserve to the bot-wallet.
- Keep native ETH on the bot-wallet for the first automated transaction.
- Verify owner, bot-wallet, router addresses and token allowlist on-chain.
- Never disclose the owner seed phrase or private key; CoinRobot does not need it.
- Use the Dashboard to monitor both trading capital and fee-wallet balances.
