Shaduf.
USDe Risk Audit/Claims and exits

USDe Risk Audit / Claims and exits

What do you hold—and what comes back?

Follow the next asset, the next permission and the first deadline. Staking withdrawal, issuer redemption and a market sale are not interchangeable exits.

Start with the asset that can actually leave your position. A transferable USDe token, an earning sUSDe share, a fixed staking claim and a lender’s receipt are different claims. None should silently become “one bank dollar tomorrow.” The route determines who must pay, which permissions apply and who bears a delay. Claim definitions and published terms.

Find your claimCompare exit size

A borrower’s funding has to arrive before the queue can help

Exit Clock WideRepay first: For pledged collateral: obtain enough of the debt asset. Then Free the shares: This path burns free sUSDe into a fixed queued USDe claim. Then Claim USDe: After the recorded release condition, submit unstake. Then Exit USDe: Eligible redemption or sale; the payout is a separate asset. Repay firstFor pledgedcollateral:obtainenough of thedebt asset.Free the sharesThis path burnsfree sUSDeinto a fixedqueued USDeclaim.Claim USDeAfter therecordedreleasecondition,submit unstake.Exit USDeEligibleredemption orsale;the payout is aseparate asset. Exit Clock NarrowRepay first: For pledged collateral: obtain enough of the debt asset. Then Free the shares: This path burns free sUSDe into a fixed queued USDe claim. Then Claim USDe: After the recorded release condition, submit unstake. Then Exit USDe: Eligible redemption or sale; the payout is a separate asset. Repay firstFor pledged collateral: obtainenough of the debt asset.Free the sharesThis path burns free sUSDeinto a fixed queued USDe claim.Claim USDeAfter the recorded releasecondition, submit unstake.Exit USDeEligible redemption or sale;the payout is a separate asset.
Time-ordered mechanism, not a real account. One day was the observed staking duration at Ethereum block 26,005,156 (18 September 2026, 15:02:59 UTC); it is not a complete cash-delivery time. A free-share sale is an alternative, not completion of the cooldown. Claim mechanics and ordered example.

Which claim do you have?

A position’s next transition—not a promise that the transition will execute.
PositionNext transitionFirst consequence
Plain USDeSell to a funded buyer, or redeem through the issuer only with the required eligibility and service access.The holder bears market discount, unavailable access and the underlying backing risk.
Free sUSDeSell the unpledged shares, or begin cooldown and later claim USDe.The staker bears share-sale discount, lower rewards and withdrawal constraints.
USDe in cooldownMeet the recorded release condition and submit the unstake transaction.The queued amount is fixed USDe. The burned shares no longer exist to earn or sell.
Collateral with debtObtain the debt asset or sufficient other collateral before releasing the pledged asset.A borrower can face liquidation before staking or issuer redemption can fund repayment.
Lending or vault receiptWithdraw available loan assets or wait for repayment / liquidation through the relevant market and allocation.The supplier can face illiquidity or residual bad debt without holding USDe directly.
PT, YT or venue accountFollow the exact wrapper, maturity, account and output rules.A principal label or account credit does not remove the underlying or operational exit risk.

The deeper examples are direct sUSDe on Aave and a Base USDe/USDC lending market, not a complete active pre-maturity PT review. Full claim and risk-bearer explanation.

Holding USDe does not grant the issuer’s route

The published terms distinguish ordinary Holding Users from eligible Mint Users. The issuer, Ethena BVI Limited, applies onboarding, jurisdiction, compliance, fee and service conditions. Its published redemption commitment is reserve-based and capped at one-dollar notional per USDe; that ceiling is not an unconditional dollar floor for every holder. The agreement places legal reserve title with the company rather than describing a personal segregated deposit for each token holder. Published terms and agreement.

For an admitted customer, obtaining a quote, signing an order, authorised submission and receiving the settlement asset are distinct stages. A signature alone does not create an operator, reserve remaining block capacity or replenish payout inventory. The observed Mint V2 ceilings constrain a route; they are not cash waiting for that customer. Issuer workflow and limits.

A USDC or USDT payment still leaves a separate asset-issuer, market or banking transition. Finishing one step should be described precisely: USDe returned from staking, a supported token delivered on redemption, and bank dollars credited are different outcomes. Private customer rights and stressed processing performance were not established.

The August 2025 terms, reread on 20 September 2026, do not pass Maple borrower rights or fund-holder redemption permissions through to every USDe holder. They distinguish the eligible Mint User from a secondary-market holder; US users are not eligible to become Mint Users under those published terms. A specific person’s enforceable rights and any private agreement still require separate legal assessment. Issuer title and claim boundaries · Published eligibility terms.

What an observed payout does—and does not—prove

A payment is a flow; a later balance is a stock

An observed burn and USDC transfer occurred before the inventory measurementAn observed burn and USDC transfer occurred before the inventory measurement. The earlier payment must not be subtracted again from the later balance. Standard token logs support the pairing, not an independently obtained receipt, exact Mint-event ABI interpretation or a link to Maple or JAAA funding.20 SEPTEMBER 2026 · ETHEREUM · CHAIN TIMES IN UTC13:13:11 · Token logs165,891.907 USDe burned.165,890.828 USDC sentfrom Mint V2 to the same address.Block 26,018,948.13:31:35 · Later stock30,934,109.172 USDCheld by Mint V2.No deduction of that earlierpayment a second time.Block 26,019,040.Do not extend the evidence beyond the observed pairingNo independently fetched receipt/status; the candidate Mint-event ABI differs.Neither selected backing chain was traced as the source of this payment.An observed burn and USDC transfer occurred before the inventory measurementAn observed burn and USDC transfer occurred before the inventory measurement. The earlier payment must not be subtracted again from the later balance. Standard token logs support the pairing, not an independently obtained receipt, exact Mint-event ABI interpretation or a link to Maple or JAAA funding.20 SEP 2026 · ETHEREUM · UTC13:13:11 · Token logs165,891.907 USDe burned.165,890.828 USDC paid.Same recipient and transaction.Block 26,018,948.13:31:35 · Later stock30,934,109.172 USDCat Mint V2 · block 26,019,040.Do not subtract the earlierpayment again.Pairing—not a full traceNo separate receipt/status.Mint-event ABI mismatch.No Maple or JAAA fundingattribution established.
Matched standard Transfer logs share the transaction/block hashes and are marked nonremoved. The nominal difference of 1.079 is not attributed to a fee: commercial quote terms were not obtained. Inventory can be replenished or spent and is not future accepted capacity. Transaction and recorded log evidence · Three separate payout-asset inventories.

The three sampled Mint assets were active and subject to one global 10 million-USDe redemption limit per block, alongside the sampled per-asset limits, at Ethereum block 26,019,040. Adding three asset caps does not produce thirty million of independent capacity. Nor does a balance promise that an order will be accepted, submitted or paid before this holder’s deadline. Configuration and inventory in the same 20 September snapshot.

To fund later payments from Maple, the authorized pool withdrawal and onward transfer must actually return the needed asset. To fund them from JAAA, the investor instruction, portfolio settlement, claimability and network route must all work. A current market sale may provide another exit, but it has its own size and price; a published recovery interval cannot stand in for it. Lending route · Fund route.

Cooldown changes the claim—not only the clock

On the inspected positive-duration route, requested sUSDe shares burn when cooldown begins. The amount of USDe is fixed and moved into the Silo arrangement. It no longer participates in later reward-driven growth of the burned shares. A rising USDe-per-share accounting value is also not proof that those USDe units can be sold for a dollar. Staking source and design.

The sampled cooldown was 86,400 seconds at Ethereum block 26,005,156, on 18 September 2026 at 15:02:59 UTC. The endpoint is a staking-release condition, not a complete payment deadline. A further request can aggregate the amount and reset the account’s common endpoint; a change in positive global duration does not simply rewrite every stored timestamp. No generic transferable or cancellable queue receipt is assumed. Dated setting and identity.

A separate observation reconfirmed 86,400 seconds at Ethereum block 26,019,040 on 20 September 2026, 13:31:35 UTC. It did not execute a user withdrawal or establish a bank-cash deadline. The diagram above retains its original 18 September reference. New cooldown read and its limited scope.

For a borrower, the necessary funds may be needed before any of that begins. Pledged collateral cannot all be withdrawn while debt remains inadequately secured. External debt-asset liquidity can make an orderly release possible; a hoped-for future cooldown payout cannot be spent before the collateral has been released. This is why an eventual sound claim can still produce a forced loss.

The size of the exit changes the question

A quote for 100 tokens does not describe an exit for 100,000

Sized Quotes WideIndependent read-only USDe to USDT quotes in one Ethereum Uniswap V3 pool, fee 0.01 percent, price limit zero. 100 USDe returns 100.026581 USDT at block 26,005,291. 100,000 returns 10,062.463842, 1 million returns 10,076.081591 and 10 million returns 10,077.338815 USDT at block 26,005,285. Bars show output per input USDe, not a global price or executed trades. Quotes are not cumulative fills. ONE ETHEREUM POOL · INDEPENDENT QUOTES100 USDe →100.026581 USDT1.000265810 USDT / input USDe100,000 USDe →10,062.463842 USDT0.100624638 USDT / input USDe1,000,000 USDe →10,076.081591 USDT0.010076082 USDT / input USDe10,000,000 USDe →10,077.338815 USDT0.001007734 USDT / input USDeScale: 0–1.05 USDT per input USDe.Small near-par quotes ≠ large depth. Sized Quotes NarrowIndependent read-only USDe to USDT quotes in one Ethereum Uniswap V3 pool, fee 0.01 percent, price limit zero. 100 USDe returns 100.026581 USDT at block 26,005,291. 100,000 returns 10,062.463842, 1 million returns 10,076.081591 and 10 million returns 10,077.338815 USDT at block 26,005,285. Bars show output per input USDe, not a global price or executed trades. Quotes are not cumulative fills. ONE ETHEREUM POOL · INDEPENDENT QUOTES100 USDe →100.026581 USDT1.000265810 USDT / input USDe100,000 USDe →10,062.463842 USDT0.100624638 USDT / input USDe1,000,000 USDe →10,076.081591 USDT0.010076082 USDT / input USDe10,000,000 USDe →10,077.338815 USDT0.001007734 USDT / input USDeScale: 0–1.05 USDT per input USDe.Small near-par quotes ≠ large depth.
18 September 2026, Ethereum USDe/USDT Uniswap V3 pool 0x435664008f38b0650fbc1c9fc971d0a3bc2f1e47, fee 0.01%, no protective sqrt-price limit. The small quote is block 26,005,291 (15:29:59 UTC); the three larger quotes are block 26,005,285 (15:28:47 UTC). Independent simulations, not trades, cumulative fills, a market-wide depeg, Base liquidation capacity or USD cash. Thin bar widths are rounded to at least one display pixel; labels give the rates. Full quote evidence.

The small near-par observation is a genuine countercase to treating every route as distressed. The larger outputs nevertheless show that this particular pool, in its sampled state and without a protective price limit, did not support a near-par large sale. They do not establish an issuer reserve shortfall or the capacity of other pools, venues, multihop routes or primary redemption. Quote arguments, balances and limitations.

A remote-chain holder also needs local conversion or a working bridge path. An exchange customer must satisfy that account’s margin and transfer rules. Neither Ethereum liquidity nor a documentary conversion facility establishes funded cash where a Base borrower or venue customer needs it. Remote-chain boundary · Venue gates.

Search published pools, pages, reports, and evidence.