Historical context — previous programme, preserved from the 14 September 2026 release. Its research and observation dates remain unchanged. Read the current assessment or return to History.
USDe / audit scope
Which evidence do we actually have?
A custody balance, a release permission and a completed payment answer different questions.
This view includes research 5: custody and usable funds. Eighteen discovered components remain visible; this is not a percentage of the whole ecosystem. The earlier Ethereum snapshot is still dated 11 September 2026.
New operational detail, not new account verification. Provider documents describe pending settlement and release conditions. No private account, current balance sheet, signed customer agreement or matching live settlement receipt was inspected.
| Component | Inspected evidence | Unresolved test |
|---|---|---|
| USDe token | Accepted token/import source review and dated owner/minter evidence. | Independent rebuild and complete current authority chain. |
| Development Safe | Accepted proxy and dated signer threshold. | Singleton, modules, guard, fallback, linkage and signer independence. |
| Historical Mint V1 | Selected historical source. | Current equivalence; not a substitute for Mint V2. |
| Mint V2 | Accepted order, signature, nonce, helper, cap and atomic-settlement source paths. | Current roles, active assets, capacity, allowance, payout inventory and actual receipts. |
| sUSDe staking | Accepted share accounting, vesting, fixed queue and restriction source. | Current owner/roles, balances, Silo linkage and actual integration. |
| Silo | Accepted caller/release source and transfer-return qualification. | Independent runtime, immutables and queue/balance reconciliation. |
| Direct issuer redemption | Accepted terms, API/status/policy and pinned client source. | Actual eligibility, private agreement, operator dispatch and final output. |
| Hedges and reserve policy | Mechanism plus an asset-specific illustrative timing model and historical resilience countercase. | Current positions, margin demands, accessible reserves and calibration. |
| Custody and settlement | Provider settlement, pending/top-up, status and main/subaccount release documentation; selected legal structure. | Applicable signed terms, actual account records, receipt joins and recovery outcomes. |
| Backing reconciliation | Current assurance index and historical publisher disclosure. | Latest full report, underlying letters, procedures, liabilities, encumbrance and comparable balances. |
| Backing credit | Public lending proposal and adviser conditions; different legal entities distinguished. | Executed agreements, current allocations, recall performance and usable liquidity floor. |
| RWA and non-crypto assets | Accepted reported strategy inventory. | Current title, custody, valuation, weights and realization terms. |
| Pendle | Accepted selected adapter source. | Exact current market, output adapter, maturity and oracle. |
| Aave PT proposal | Accepted proposal and challenge, not executed-market evidence. | Live listing, oracle/cap/debt parameters and liquidation route. |
| Morpho | Accepted selected liquidity/liquidation source path. | Imports, health helper, vaults and actual market/exposure joins. |
| Strata senior claim | Provider mechanics and scoped reviewer excerpt. | Tranche/admin code, deployment and actual junior buffer. |
| Markets and bridges | Accepted route boundaries and venue-specific historical accounts. | Executable quotes, actual transfer/credit outcomes, bridge controls and recovery. |
| Owner-controller | Accepted custom/inherited source paths; this run retains the missing operational links. | Pinned runtime, role/whitelist history, complete Safe chain and staking linkage. |
The assurance review keeps the latest index entry separate from unread letters. The buffer example is a toy ledger, not an estimate of Ethena’s required reserve.