Shaduf.
USDe Risk Audit/Control and contracts

USDe Risk Audit / Control and contracts

Who can change issuance, access and the exit route?

Trace the actual action through its controller and permission. A signature count or a one-day label does not describe the entire system.

A fixed token contract does not make the issuance policy immutable. USDe’s owner can replace its minter; the current Mint V2 route supplies a separate policy layer. A controller delay, a Safe threshold and a redemption cap each constrain something specific. None alone establishes that every harmful action is delayed or every eligible exit is funded. Control assessment.

One controller, more than one execution path

Authority WideThe Ethereum Safe has an observed threshold of five and proposer, executor and whitelisted-executor roles at the owner-controller. The ordinary controller delay is one day. Tested Mint V2 cap and configuration selectors are not whitelisted. Selected role revocation and customer-whitelist changes can use an immediate path. The Safe also has collateral-manager membership. This is not a universal one-day warning window or a complete source audit. Ethereum SafeThreshold: 5 signaturesIndependence not established.Owner-controllerOrdinary delay: 86,400 secondsSafe has both execution roles.Ordinary scheduled routeTested cap / configuration setters:not on the delay whitelist.Not every alternate path checked.Separate immediate routeRole revocation; add or removea whitelisted customer.Target permissions still apply.Mint V2Issuance / exitpolicy layer.Safe separately hascollateral-manager role.The USDe token owner can replace the minter.A cap inside Mint V2 is not an immutable token-level reserve rule. Authority NarrowThe Ethereum Safe has an observed threshold of five and proposer, executor and whitelisted-executor roles at the owner-controller. The ordinary controller delay is one day. Tested Mint V2 cap and configuration selectors are not whitelisted. Selected role revocation and customer-whitelist changes can use an immediate path. The Safe also has collateral-manager membership. This is not a universal one-day warning window or a complete source audit. Ethereum Safe5 required signatures observed;independence not established.Owner-controllerOrdinary delay: 86,400 seconds.Safe also has whitelist execution.TWO ALTERNATIVE EXECUTION PATHSScheduled routeTested cap and configurationselectors are not whitelisted.Not a complete bypass audit.Whitelisted routeRevoke a role; add / removea whitelisted customer.Target permissions still apply.Mint V2 policy layerSafe separately holds thecollateral-manager role.A token owner can replace V2.
Ethereum observations: core links and delay at block 26,005,156; roles and selected whitelist entries at 26,005,198, both on 18 September 2026. Arrows identify observed or source-supported authority, not a transaction executed here. No compromised key or unbacked mint was observed. Exact identities, selectors and limitations.

The observed chain of authority—and its boundary

Ethereum core observations, primarily block 26,005,156, 18 September 2026 at 15:02:59 UTC.
ComponentObserved link or settingWhat it does not establish
USDe tokenOwner 0xe8dc0fab349ea169283c48ccfd09d797e6db7c94; minter 0xe3490297a08d6fc8da46edb7b6142e4f461b62d3.A token-level reconciliation of reserves or immutable Mint V2 constraints.
Mint V2The same controller is its owner / sampled default administrator.A complete role roster, all custody routes or signed-order invariants.
Owner-controllerMinimum ordinary delay of 86,400 seconds; separate whitelisted execution.A universal 24-hour warning period.
Ethereum SafeThreshold 5; proposer, executor and whitelisted-executor membership checked at block 26,005,198.Five independent people, a fresh full owner enumeration or complete module / guard analysis.
sUSDeSame owner-controller; sampled cooldown 86,400 seconds.A one-day exit to bank dollars or the same restrictions as ordinary USDe.

Safe: 0x3b0aaf6e6fcd4a7ceef8c92c32dfea9e64dc1862. Full core identities and dated observations.

Immediate authority can protect the system and interrupt service

At Ethereum block 26,005,198 (18 September 2026, 15:11:23 UTC), the tested delay-whitelist entries were true for Mint V2 role revocation and customer-whitelist addition/removal. They were false for the sampled global and per-asset cap setters, stable-delta and token-type settings, supported-asset changes, role grants, custodian changes and admin transfer. False for a queried selector is not proof that every alternative path is absent. Observed selector scope.

The source-supported whitelisted route identifies a target and function selector, not a separate approval for every argument. Revoking an operator can help contain compromise; removing a customer or operator can also stop service. The target contract’s checks still apply. The Safe separately held collateral-manager membership in Mint V2; its full set of deployed transfer methods and destination constraints was not verified.

Both sampled addresses returned false for the gatekeeper role. That does not mean the global gatekeeper roster is empty. Seven mint operators and four redeem operators identified in a bounded recent-event sample were checked as current members—not exhaustively enumerated across history. A complete control explanation has to preserve this distinction between positive observed links and unseen alternatives.

An amount guard protects nominal units—not the dollar value of a payout

Read-only Mint V2 helper responses at Ethereum block 26,005,263, 18 September 2026, 15:24:23 UTC. USDC and USDe amounts shown in whole-token units.
DirectionUSDC / USDe amountsHelper result
Mint100 / 100true
Mint100 / 101false
Mint100 / 99true
Redeem100 / 100true
Redeem101 / 100false
Redeem99 / 100true

The sampled verifyStablesLimit helper rejected minting more nominal USDe than the stable collateral and redeeming more nominal stable collateral than the USDe amount. Less favourable customer amounts passed this particular helper. It is not a dollar-price oracle, a fair-quote guarantee or proof that the helper is reached on every execution path. No complete signed order or rollback test was executed in this investigation. ABI, helper and implementation scope.

Mint V2’s sampled global ceilings were 200 million USDe minted per block and 10 million USDe redeemed per block. USDT, USDC and USDtb were active in the sampled settings. These are not daily allowances, actual throughput, reserve weights or redeemable inventory. The global maximum is not multiplied by the count of active assets.

Keep staking, remote control and source assurance separate

The inspected staking source has restriction and redistribution surfaces for staking shares. Those are not arbitrary confiscation powers over ordinary USDe. Shares before cooldown, a fixed queued claim and the later Silo payout have different accounting and access boundaries. Staking source scope.

On Base, the direct token owner was an intermediate controller, 0xd896f26f76ed089a1711284a00af497b19d65171, with a one-day delay getter and Safe proposer/executor roles behind it. That resolves an owner relationship; it is not evidence of a historical ownership change. Actual messaging verification, executor, delegate, rate-limit and emergency settings remain unverified. A rejected paused() probe is not proof that transfers are unpaused. Remote identity and security boundary.

Known settings do not equal complete security. Full deployment-matched Mint V2 source/build, all consequential invariants, signer independence and every bypass were not verified. The historical nonce issue and fix are audit-scope facts, not an allegation of a current exploit. The Base meta-oracle’s concrete formula mismatch also blocks stronger fallback claims. Audit versions · Oracle mismatch.

Search published pools, pages, reports, and evidence.