USDe Risk Audit / Evidence method
How to read a claim without overstating its evidence
A source, an observed setting and an available exit are different kinds of proof. Keep the boundary between them visible.
A source label is not deployment equivalence
A useful risk claim needs four things beside it: the position affected, the evidence, its date, and the conclusion it cannot yet support. A document, a getter and an executed cash payment answer different questions. Their agreement can strengthen a conclusion; their disagreement must remain visible.
Read the evidence at its actual strength
| Evidence | What it can establish | What it cannot establish by itself |
|---|---|---|
| Published terms, proposal or provider description | The author’s stated mechanism, policy, entity or proposed conditions at the document’s date. | Execution, enforceability for a particular client, current balances or guaranteed performance. |
| A source file at an identified version | The behavior expressed by the inspected code, subject to the inspected imports and scope. | That a deployed address has that implementation or configuration. |
| ABI, source association, runtime or match metadata | Interface and deployment evidence that can help bind a version to an address. | A complete independent compiler rebuild, full semantic review or absence of vulnerabilities. |
| A getter or role query | A returned value for a particular address, function, chain and observation block. | A complete role set, historical continuity, signer independence or every exceptional execution path. |
| An accounting or stress calculation | The consequence of specified inputs, units and assumptions. | Actual exposure, the probability of the scenario or completion of a transaction. |
| A read-only quote | Simulated output for that route, size and sampled state. | A filled trade, future price, all-market capacity or funds available on another chain. |
| Matched standard token logs | A provider-reported token movement and matching burn/recipient/transaction at identified blocks. | Independent receipt or finality verification, exact event-ABI decoding, private quote terms or the prior backing-recovery source. |
| A completed transfer or funded unwind | Evidence of the particular operation, asset, recipient and time when actually reconciled. | A guarantee for all holders or stressed future capacity. This investigation did not complete such a funded end-to-end unwind. |
Every promoted number needs a unit and a denominator
A share is not a dollar. A USDe-per-sUSDe conversion can be correct while the dollar price or recoverability of USDe differs. Aave’s measured valuation combines that ratio with a capped USDT/USD input. Its accepted value is not a liquidation sale quote. The relevant contracts, raw scales and formula are in the Aave case.
A concentration needs its denominator. The 88.761411% figure refers to the selected Base market allocation divided by one vault’s total assets at Base block 51,477,892, 18 September 2026 at 15:25:31 UTC. It does not measure USDe backing or the share of the ecosystem at risk. The source quantities and the separate market-supply-share ratio are in the same-batch table.
A report period is not a retrieval date. The $501 million total RWA amount is an issuer-reported June figure published on 17 July 2026. Reading it in September does not update it to September, and it is not all JAAA/STAC. Dated backing evidence.
Hypothetical means hypothetical. The normalized 1,015-assets/1,000-liabilities book and chosen stress haircuts are teaching examples from the research. They are not a reserve estimate or a forecast. The reserve is already included in the asset total; separate scenarios must not be stacked without changing their assumptions. Inputs and results.
Keep state, source and time attached
The investigation’s Ethereum and Base observations were provider-mediated reads. Some multi-call batches included their own block and timestamp getters. Those observations share a batch; the entire investigation does not share a single block or reporting time. On-chain timestamps are not the wall-clock times at which a researcher opened a document or received a response.
An ordinary explorer link is an identity locator, not a frozen replay of the displayed observation. To independently reproduce a past-block read, a reader needs a suitable archival data source and the same address, function, arguments and unit conversion. The present investigation’s calls were current-only. The foundation evidence trail states the binding and source limits rather than claiming archival replay.
A runtime hash proves identity of bytes, not what every function means. A common proxy-pattern screen cannot exclude every proxy design. A successful ABI call proves its returned result, not that an entire candidate source is equivalent. Conversely, a rejected or unavailable read does not supply a default value such as “no role,” “unpaused” or “no deployment.”
A token log, a balance and a recovery chain prove different things
The 20 September payment example matches a standard USDe burn to an outbound USDC Transfer in the same transaction and block, marked nonremoved. That is stronger than a token symbol or an unexamined Mint event. The investigation did not separately obtain the receipt/status; its candidate Mint-event signature did not match the observed topic. The retained candidate events are therefore not an ABI-verified redemption count or a throughput series. The precise pairing and its limits.
Chronology prevents double counting. That payment precedes the later Mint balance snapshot, so subtracting it again from the snapshot would duplicate the outflow. The burn and payout are two legs of one operation, not two independent cash payments. Neither log identifies a Maple or JAAA recovery as its source. Inventory versus payment evidence.
Denominators also prevent overstatement. Maple’s 88.64281% is the selected wallet’s share of that pool’s shares. JAAA’s 99.996563% is a share of the sampled Base token supply, not the whole fund. A JAAA token count is not a dollar NAV, and the pool’s direct USDC is not total withdrawable liquidity. Both observations are dated 20 September 2026 at separate blocks. Maple inputs · JAAA inputs.
A source label identifies why a wallet was investigated; it does not prove its beneficial owner or the legal agreement binding the position. The 14 September assessor values, published on 18 September, remain separate from 20 September token observations. No aggregate reserve ratio is reconstructed from inconsistent assessment denominators or an old NAV. Selection and evidence dates.
A useful cash test is conservative about identity, not automatically pessimistic about recovery. Track the paying entity, asset, network, release condition and deadline. A pool-to-issuer transfer moves one resource; it does not create a second reserve. A bridge adds cash and a debt or assigns proceeds. A positive final balance does not erase an earlier missed deadline; the supplied timing example checks the largest cumulative deficit. Cash conservation and maximum-prefix example.
A mismatch is a finding about the evidence
The Base meta-oracle provides a concrete example. The inspected candidate source’s deviation formula does not reproduce the observed getDeviation() result using the recorded primary and backup. The public assessment therefore preserves the measured inputs, threshold and timers, but withholds a complete claim about fallback and healing semantics. Another formula matching one result would not prove all of the implementation.
This is neither a demonstrated exploit nor a reason to pretend the candidate is a complete deployment match. It identifies the evidence needed for a stronger conclusion. The numerical comparison remains visible in the main oracle discussion, not hidden in a technical appendix.
Likewise, an unread attestation is not an adverse opinion. A proposal is not a deployed safeguard. A reported historical redemption is useful counterevidence, but not an independent transaction replay. Those distinctions prevent uncertainty from being turned into either automatic reassurance or an unsupported failure claim.
Corrections belong to propositions and dates
Dated observations do not change when a reader opens a page later. The control report dated 12 September uses an 11 September snapshot; the 18 September whole-system assessment separates its 17–18 September state observations from older portfolio reporting. Neither date should be silently assigned to the other’s evidence.
Differences in inspected source material are not themselves evidence that a deployment changed or that an earlier conclusion was false. The useful correction identifies the old proposition, the added evidence and the remaining limit. All dated reports remain inspectable, and History preserves their surrounding context.
The reader pages require no wallet connection, keys, transaction or background data request. Source links are deliberate references to open; the tables and scenarios are static.