USDe Risk Audit / Control and contracts
Who can change issuance, access and the exit route?
Trace the actual action through its controller and permission. A signature count or a one-day label does not describe the entire system.
A fixed token contract does not make the issuance policy immutable. USDe’s owner can replace its minter; the current Mint V2 route supplies a separate policy layer. A controller delay, a Safe threshold and a redemption cap each constrain something specific. None alone establishes that every harmful action is delayed or every eligible exit is funded. Control assessment.
One controller, more than one execution path
The observed chain of authority—and its boundary
| Component | Observed link or setting | What it does not establish |
|---|---|---|
| USDe token | Owner 0xe8dc0fab349ea169283c48ccfd09d797e6db7c94; minter 0xe3490297a08d6fc8da46edb7b6142e4f461b62d3. | A token-level reconciliation of reserves or immutable Mint V2 constraints. |
| Mint V2 | The same controller is its owner / sampled default administrator. | A complete role roster, all custody routes or signed-order invariants. |
| Owner-controller | Minimum ordinary delay of 86,400 seconds; separate whitelisted execution. | A universal 24-hour warning period. |
| Ethereum Safe | Threshold 5; proposer, executor and whitelisted-executor membership checked at block 26,005,198. | Five independent people, a fresh full owner enumeration or complete module / guard analysis. |
| sUSDe | Same owner-controller; sampled cooldown 86,400 seconds. | A one-day exit to bank dollars or the same restrictions as ordinary USDe. |
Safe: 0x3b0aaf6e6fcd4a7ceef8c92c32dfea9e64dc1862. Full core identities and dated observations.
Immediate authority can protect the system and interrupt service
At Ethereum block 26,005,198 (18 September 2026, 15:11:23 UTC), the tested delay-whitelist entries were true for Mint V2 role revocation and customer-whitelist addition/removal. They were false for the sampled global and per-asset cap setters, stable-delta and token-type settings, supported-asset changes, role grants, custodian changes and admin transfer. False for a queried selector is not proof that every alternative path is absent. Observed selector scope.
The source-supported whitelisted route identifies a target and function selector, not a separate approval for every argument. Revoking an operator can help contain compromise; removing a customer or operator can also stop service. The target contract’s checks still apply. The Safe separately held collateral-manager membership in Mint V2; its full set of deployed transfer methods and destination constraints was not verified.
Both sampled addresses returned false for the gatekeeper role. That does not mean the global gatekeeper roster is empty. Seven mint operators and four redeem operators identified in a bounded recent-event sample were checked as current members—not exhaustively enumerated across history. A complete control explanation has to preserve this distinction between positive observed links and unseen alternatives.
An amount guard protects nominal units—not the dollar value of a payout
| Direction | USDC / USDe amounts | Helper result |
|---|---|---|
| Mint | 100 / 100 | true |
| Mint | 100 / 101 | false |
| Mint | 100 / 99 | true |
| Redeem | 100 / 100 | true |
| Redeem | 101 / 100 | false |
| Redeem | 99 / 100 | true |
The sampled verifyStablesLimit helper rejected minting more nominal USDe than the stable collateral and redeeming more nominal stable collateral than the USDe amount. Less favourable customer amounts passed this particular helper. It is not a dollar-price oracle, a fair-quote guarantee or proof that the helper is reached on every execution path. No complete signed order or rollback test was executed in this investigation. ABI, helper and implementation scope.
Mint V2’s sampled global ceilings were 200 million USDe minted per block and 10 million USDe redeemed per block. USDT, USDC and USDtb were active in the sampled settings. These are not daily allowances, actual throughput, reserve weights or redeemable inventory. The global maximum is not multiplied by the count of active assets.
Keep staking, remote control and source assurance separate
The inspected staking source has restriction and redistribution surfaces for staking shares. Those are not arbitrary confiscation powers over ordinary USDe. Shares before cooldown, a fixed queued claim and the later Silo payout have different accounting and access boundaries. Staking source scope.
On Base, the direct token owner was an intermediate controller, 0xd896f26f76ed089a1711284a00af497b19d65171, with a one-day delay getter and Safe proposer/executor roles behind it. That resolves an owner relationship; it is not evidence of a historical ownership change. Actual messaging verification, executor, delegate, rate-limit and emergency settings remain unverified. A rejected paused() probe is not proof that transfers are unpaused. Remote identity and security boundary.
Known settings do not equal complete security. Full deployment-matched Mint V2 source/build, all consequential invariants, signer independence and every bypass were not verified. The historical nonce issue and fix are audit-scope facts, not an allegation of a current exploit. The Base meta-oracle’s concrete formula mismatch also blocks stronger fallback claims. Audit versions · Oracle mismatch.