Shaduf.
USDe Risk Audit/Who can change the rules—and release the cash?

USDe Risk Audit / Documented governance and controls

Who can change the rules—and release the cash?

Permission and usable money are separate dependencies. Follow the policy decision, the operator’s action and the external asset release all the way to the holder.

The central finding: a token balance, an approved investment and a signed order can all exist without an eligible holder receiving the required asset on time. Emergency restrictions may protect common backing while making an individual exit harder. A signature threshold, a delay or an audit count cannot explain that whole chain.

The control assessment remains partial. This chapter delivers a documentation-based investigation, not current deployed-behaviour verification. Complete Mint/controller correspondence, the selected Base oracle’s transition behaviour and remote supply controls remain unverified. No new contract query, transaction or security test supports the 22 September date.

1. The new finding: authority has to meet the payment path

USDe depends on managed backing and on the people and institutions able to use it. A holder first needs to identify the claim: plain USDe, an earning sUSDe share, an already fixed staking claim, or a lending or venue position. Direct redemption then requires the holder’s own access to the issuer’s process; ownership of a token is not ownership of each reserve asset. The 18 September foundation establishes the claim and integration distinctions. The 20 September recovery investigation follows two specific backing chains toward payment.

The new documentary evidence adds decision rights and constraints to those paths. A later committee announcement is more specific than a served roster, but signing the relevant agreements remains a separate step. Public control summaries conflict with the earlier recorded configuration. A proposed local conversion facility received conditional support, not demonstrated production readiness. A reported fee-switch vote concerns revenue allocation, not proof that funds moved. These are useful findings about governance and disclosure, not newly observed contract failures. Fifth-Term Official Committee Announcement · Key Trust Assumptions · Kairos Review of the L2 USDe PSM Proposal · ENA Fee Switch Activation.

What the documentary investigation adds; each boundary remains part of the finding.
New evidence or distinctionWhy it mattersWhat it does not establish
Later committee appointment recordThe Foundation’s screening decision separates an election result from admission to authority.Executed service agreements, full current mandates or control of signing keys.
Conflicting control clocksA holder cannot choose the more reassuring number from a summary page and call it an exit guarantee.A new change of owner, a current universal delay, or universal immediate authority.
Local-conversion conditionsThe proposed seed, reserve commitment and external payout assets require separate accounting and control evidence.Production configuration, satisfied safeguards or funded local capacity.
Revenue and liquidity policyWho receives income and what counts as liquid can change holding and withdrawal incentives.Actual buybacks, automatic policy compliance or an observed loss of principal.
Version-scoped audit recordPublic reviews give meaningful evidence about stated code versions and findings.Current deployment equivalence or assurance spanning borrowers, fund directors, custodians and payment inventory.

Permission and cash must both reach the payment step

Permission and cash must both reach the payment stepPolicy approval, technical permission, external asset release and eligible customer execution are separate necessary conditions. Approving a fund does not make it payout inventory. Arrows show dependencies, not observed transfers, guaranteed times or proportional amounts.POLICYApprove the investmentCommittee / Foundation processEligibility is not a transfer.IMPLEMENTATIONPermit the exact actionOwner, administrator, operatorsA role or limit is not inventory.EXTERNAL RELEASERealize and deliver the assetCustodian, borrower, fund actorsAcceptance is not settlement.CUSTOMER PAYMENTExecute an eligible exitAccepted order + usable assetA token payout is not bank cash.Permission and cash must both reach the payment stepPolicy approval, technical permission, external asset release and eligible customer execution are separate necessary conditions. Approving a fund does not make it payout inventory. Arrows show dependencies, not observed transfers, guaranteed times or proportional amounts.POLICYInvestment approvalCommittee / Foundation process.Approval is not a transfer.IMPLEMENTATIONPermission for the actionOwner / admin / operators.A role or limit is not inventory.EXTERNAL RELEASEAsset release and deliveryCustodian, borrower, fund actors.Acceptance is not settlement.CUSTOMER PAYMENTEligible customer paymentAccepted order + usable asset.Tokens are not bank dollars.
Conceptual dependency map from the 22 September documentary assessment and the dated 20 September claim-to-cash analysis. It is not evidence that a committee controls a fund board, that all shown permissions are installed today, or that a particular payment was funded by these assets.

The practical question is conjunctive: are the relevant rights, permissions and usable assets all present on the route this holder needs? The steps are not additional reserves to sum. Moving a pool asset to an issuer account changes its location; a fund redemption replaces a share with proceeds; a bridge advance adds funding with a liability or assigned claim. None creates a second independent buffer merely because a new actor approved it. Cash conservation and competing deadlines.

2. Policy makers, operators and external asset releasers

The governance overview describes ENA-holder appointment and rotation of expert committees, with most decisions delegated rather than submitted to a general tokenholder vote. It recognizes that the protocol’s off-chain operations cannot be governed wholly by on-chain transactions. This is a description of organizational authority, not a statement that USDe holders vote on their redemption terms or can compel the issuer to execute every committee decision. Governance.

The Risk Committee page describes three members, six-month terms, seven days for proposal deliberation, implementation through relevant parties under Foundation oversight, and recusal for direct financial interests. Ethena Labs Research is described as nonvoting. The service-agreement template was not obtained; quorum, enforceable remedies for nonimplementation and complete emergency exceptions are not established by that description. Risk Committee.

The August appointment sequence is an important real example. The re-election thread reports results on 10 August 2026, subject to screening. On 21 August, the Foundation announced Kairos, OAK and Blockworks as the fifth-term committee, subject to signing agreements before taking seats. The Foundation said it excluded K3 because of structural, continuing conflicts. That is an attributed screening decision, not an allegation of improper conduct by K3 or the Foundation. Risk Committee Re-election, August 2026 · Fifth-Term Official Committee Announcement.

A winning vote and an effective appointment are therefore different events. Screening can protect against conflicted decisions, while giving the Foundation substantive influence over who is eligible to decide. The later announcement supersedes the served roster as the documentary reference; it does not prove agreement execution or the complete present allocation of mandates. A committee seat also says nothing by itself about custody of contract keys.

Decision makers and asset releasers are not one universal controller. Documentary responsibilities are not a freshly enumerated permission graph.
Actor or roleObject of authorityBoundary for a holder
Foundation and committee processEligibility, appointments, portfolio-policy review and implementation oversight as described.A policy decision is not a contract execution, fund instruction or money transfer.
Token owner and contract administratorChoice of authorized minter; facility-specific support, roles and limits under the relevant route.Rules of the present minting facility cannot be assumed to bind every future authorized minter.
Mint/redeem operators and gatekeepersOrdinary execution and protective interruption are described as separate responsibilities.Being able to disable service is not automatically the power to restart it or change all parameters.
Issuer pricing and portfolio servicesQuote acceptance, exposure coordination and backing movements as described.A valid signed order is not a commitment to submit, and a movement request is not completed release.
Custodian, borrower, pool or fund actorsRelease assets, process withdrawal, repay, realize investments or settle proceeds under their own conditions.Issuer investment approval does not override these external rights, calendars or release gates.
Holder or admitted customerConsent to a particular order and use of routes for which they qualify.Token possession alone does not confer institutional issuer access or direct control over reserves.

The role descriptions and dated findings support this separation; they do not prove that the actors are independent organizations or independent failure modes. For the external asset-release relationships, executed mandates and the legal capacity of the particular wallet remain material gaps. Matrix of Multisig and Timelocks · Mint and Redeem Key Functions · Internal Services · Backing Asset Custody. Selected legal-chain limits.

3. Four clocks, and a disclosure conflict that remains unresolved

There is no reliable universal control clock in the material reviewed. The served trust-assumptions page describes seven signatures and seven-day core delays. It also gives inconsistent accounts of gatekeeper powers: one passage associates them with adding custodians, while another restricts them to disabling activity and revoking operators. The role matrix instead separates administrative changes from emergency disabling. Key Trust Assumptions · Matrix of Multisig and Timelocks.

The inherited Ethereum record is narrower and separately dated. On 18 September 2026, the core batch at block 26,005,156 recorded a Safe threshold of five and a controller minimum of 86,400 seconds. The selected role and whitelist batch at 26,005,198 established specific immediate routes. That is not a new September 22 observation, a fresh owner roster or proof of independent signers. Core observation trail; action-specific controls.

Four clocks—not one guaranteed escape window

Four clocks—not one guaranteed escape windowFour different clocks: the documented seven-day committee process, an inherited one-day controller minimum with selected exceptions, action-specific operational intervention, and the holder’s own release or payment deadline. These are different evidence types and starting events, not one guaranteed warning window.COMMITTEE PROCESSProposal submittedSeven-day deliberationDescribed process; not an all-actions lock.CONTRACT ROUTEAction is scheduledOne-day minimum recorded18 Sep observation; selected exceptions.OPERATIONAL ACTIONRequest / incidentNo universal wait establishedAcceptance, disabling or release may differ.HOLDER DEADLINEDebt due / exit requestedAn independent clockQueue, fund, custody and network conditions.Different starting events. No common scale or universal exit window.Four clocks—not one guaranteed escape windowFour different clocks: the documented seven-day committee process, an inherited one-day controller minimum with selected exceptions, action-specific operational intervention, and the holder’s own release or payment deadline. These are different evidence types and starting events, not one guaranteed warning window.COMMITTEE PROCESSProposal submittedSeven-day deliberationDescribed, not an all-actions lock.CONTRACT ROUTEAction is scheduledOne-day minimum recorded18 Sep record; selected exceptions.OPERATIONAL ACTIONRequest / incidentNo universal wait establishedAcceptance / disabling / releasecan follow different conditions.HOLDER DEADLINEDebt due / exit requestedAn independent clockQueue, fund, custody andnetwork conditions still apply.
Relational diagram, not a timeline to scale. The committee process is documentary; the 86,400-second controller minimum and selected immediate paths are inherited from 18 September. The separately served seven-day core-delay/seven-signature description does not refresh or reconcile those observations. Sources and the disclosure conflict.

The control disclosure should be reconciled to a particular deployment and release, not resolved by silently selecting either source as a universal current truth. A seven-day committee discussion, a controller’s minimum scheduling delay and a staker’s one-day observed cooldown start with different events. Even equal nominal durations would not leave a guaranteed margin for detection, debt repayment, transaction inclusion and subsequent issuer or market settlement.

The 18 September record identifies immediate controller permissions for role revocation and benefactor-whitelist addition or removal. Several tested configuration-changing selectors were not on that list. The Ethereum Safe separately held collateral-manager membership in Mint V2; its operational authority cannot be assumed to pass through the controller merely because that controller is the administrator. These were selected observations, not every role or alternate route. Exact inherited scope and limitations.

Holder consequence: do not treat a headline timelock as a guaranteed period in which to get out before every consequential action. But do not reverse that into a claim that all changes are immediate. The relevant protection attaches to the particular actor, target action, execution route and delay, together with a funded exit that can actually finish in the available time. Protective revocation may limit damage and still stop a legitimate customer’s next payment.

4. A signed order, an admitted customer and a paid claim

The order-validity description places checks after the user signs and before the issuer submits an order. They include approved addresses, balances and allowances, timeliness, consistency with the quote, market-price validation and last-look acceptance by Ethena. A user’s signature authorizes the agreed instruction; retaining discretion not to accept it is different from changing its signed terms. These checks can protect common backing from unfavorable execution without promising an individual customer submission or payment. Order Validity Checks.

The 8 July 2024 Mint V2 notice describes benefactor admission through the Dev multisig, benefactor-managed beneficiaries, contract-wallet signatures, signed quote identifiers, global and asset limits, and a directional stablecoin-amount guard. Its strong claim that stable-only operation under those controls prevents operator-key-compromise losses remains the issuer’s description of a conditional design. It is not adopted here as deployed security assurance. Mint and Redeem Contract V2.

The earlier helper observations compared normalized token quantities; they did not independently determine a stablecoin’s dollar purchasing power. On 20 September, the inventory/configuration study recorded USDC, USDT and USDtb as active, with a 10 million USDe global redemption cap per block. That global limit is not multiplied by the number of active assets, and it provides none of the tokens to be paid. Nominal-guard boundary; separate inventory and cap observations.

Three consequences should remain distinct. Withholding execution or disabling service can delay an exit while backing keeps its value. Changing admission, support or limits can change the available route without freezing ordinary token transfers. Altering the authorized minting path or use of surplus can affect claims relative to backing. Those are conditional consequences of documented or inherited authority—not findings of a current compromise, unsupported supply or token-wide confiscation power.

Suspension language must be read with the controlling terms

The issuer agreement names Ethena BVI Limited, assigns legal title to reserve assets to the company and disclaims a fiduciary or custody relationship with the user. Direct redemption depends on continuing Mint User eligibility. The described pro-rata reserve-notional entitlement is capped at one dollar per USDe and payable in supported digital assets, subject to terms and deductions; it is not an unconditional bearer right to immediate bank dollars. USDe Mint User Agreement · USDe Terms and Conditions.

The agreement contains broad suspension and pending-transaction cancellation powers, setoff and severe forfeiture language in section 8. That is not the end of the reading: its conflict provision gives the USDe Terms priority for USDe transactions. Section 14 of those Terms preserves rights and obligations during suspension and subjects discretion to applicable law and licenses. This assessment does not decide enforceability, an individual user’s rights or whether any particular forfeiture could lawfully occur. Suspension must not be presented as automatic extinction of every claim. USDe Mint User Agreement · USDe Terms and Conditions.

The Terms also place conversion valuation with the company and distinguish supported chains, wrappers and third-party market prices. A contractual right to decline service is not evidence of an on-chain function able to reverse every USDe transfer. A liquidator relying on another institution’s issuer access depends on that institution’s continuing eligibility and willingness, as well as on the tokens in its wallet. Market price near par cannot establish equal redemption access for all holders. USDe Terms and Conditions.

There is positive but bounded payment evidence. The 20 September investigation matched a historical USDe burn to an outbound USDC transfer and separately observed Mint V2 inventory later that day. It did not obtain an independent receipt/status or resolve the candidate Mint-event ABI mismatch, and it did not trace that payment’s funding to Maple or JAAA. Successful payment to one customer is not a standing commitment to the next. Payment amounts, chronology and limitations.

5. Who must authorize the backing’s journey into cash?

The issuer’s internal-services description assigns quote production, exposure management, order routing and backing-movement coordination to its portfolio-management systems. It describes waiting for sufficiently current market data before final acceptance and suspending instruments when data lag is excessive. That is evidence of designed operational discretion and protective interruption, not measured system availability or independently audited operating performance. Internal Services.

The custody description covers delegation to venues, undelegation and replenishment of the minting facility through off-exchange settlement providers. A claim of rapid delegation is not a universal settlement guarantee. Issuing a request, receiving the custodian’s permission, completing exchange settlement and delivering the right asset to the payout address remain separate steps. The older user-security page and V2 rollout notice describe different key-management arrangements; neither establishes the current production practice or signer independence. Backing Asset Custody · User Security Measures — Minting · Mint and Redeem Contract V2.

Separation of duties has both a benefit and a cost. It can contain mistakes and unnecessary exchange exposure; it can also require several actors to coordinate before assets move. Protected assets may retain recovery value while holders bear the wait for reconciliation or release. A custody balance and its venue mirror are not two independent sources of payment cash. One-resource accounting.

Maple: requesting and processing are not collecting

The selected Maple chain concerns a documented framework through Protocol Pool Operations Alpha LLC and a specific observed pool-share wallet—not an undifferentiated claim on the Maple brand. The legal mandate joining that wallet to the issuer and the executed loan terms were not obtained. At Ethereum block 26,019,059, 20 September 2026, 13:35:23 UTC, the selected wallet’s floor-rounded accounting claim was 303,218,574.812566 USDC, while the pool directly held 694,920.022526 USDC. These are inherited observations, not a September 22 valuation, loss estimate or measure of all available pool liquidity. Identity, accounting and direct-cash evidence.

The issuer-side authorized holder must request a permitted withdrawal; the pool’s manager must process the relevant request and available liquidity; borrowers or realization routes must provide additional cash where required. Refinancing can resolve a loan call without fresh payment cash. Legal enforcement or collateral can protect eventual recovery but still miss the issuer’s earlier deadline. Direct pool cash was not proven reserved exclusively to the wallet, and a zero maximum-redeem getter did not establish a freeze. Withdrawal and borrower-recovery conditions.

Impairment accounting and cash recovery also differ. The earlier analysis explains that an investor exiting an impaired position may relinquish later recovery participation. That creates a difference between leaving and waiting; it does not make the remaining loan immediately liquid. A later favorable recovery would not retroactively remove a departing holder’s earlier sale loss.

JAAA: investment approval cannot instruct every fund actor

Tokenized JAAA is an Anemoy Capital SPC Limited participating fund interest, not the exchange-traded fund sharing the ticker. The route involves investor eligibility, fund governance, management, administration, asset realization and permitted-network settlement. On Base block 51,561,133, 20 September 2026, 13:40:13 UTC, the identified wallet held 59,637,405.470326 JAAA tokens. That amount is not current dollar NAV, fund-wide supply or a claimable Ethereum-USDC balance. Fund identity, network denominator and limits.

The reported large historical sale and completed-redemption sample are meaningful favorable evidence: a blanket claim that every CLO-fund exit must be prolonged would disregard them. But those attributed observations do not remove board suspension discretion, settle contradictory service-provider descriptions or promise the next investor the same timing. A fund’s own processing and custody conditions remain outside the issuer’s unilateral control. Historical execution and counterevidence.

The June governance update, published 17 July 2026, reports approval of JAAA and STAC following liquidity, credit, drawdown and pricing review, treating them as shared exposure because of common underlying risk. That supports a specific control principle: two approved wrappers over similar credit do not automatically provide independent crisis protection. It is a reported policy decision, not a fresh portfolio weight or legal guarantee. June 2026 Governance Update.

Holder consequence: authority to approve an investment does not confer authority over the borrower, fund board, administrator or custodian. The fact that matters for payment is the net asset actually released to the entitled entity, in the required denomination and network, before the obligation is due—not just the latest balance or approval headline.

6. Staking, liquidity classification and revenue allocation

Staking documentation describes administrator control of cooldown duration up to a 90-day ceiling, a rewarder role and restricted-share redistribution powers; its rescue description excludes underlying USDe. Those are staking-specific descriptions, not a plain-USDe confiscation function. The security page explains share conversion, cooldown and linear reward vesting, not the later bank or issuer-redemption step. Staking Key Functions · User Security Measures — Staking.

The 18 and 20 September studies each observed a one-day cooldown at their own recorded blocks. Starting cooldown burns the requested shares and fixes a USDe claim rather than preserving those shares’ participation in later rewards. Existing queue endpoints, positive-duration changes and the zero-duration branch have distinct source-level treatment. This chapter does not recheck any withdrawal or restriction path. Staking-claim mechanics; 20 September observation.

A policy label cannot speed up a bank or fund

The 12 March 2026 dynamic-cooldown proposal and committee discussion recommend 1/3/5/7-day settings linked to liquidity coverage and queue conditions. They distinguish a small instant-conversion part of USDtb liquidity from a Treasury-backed part requiring a banking-day route, and recognize that a conversion route dependent on USDe is not independent outside cash. The March–April update later reports adoption of a dynamic framework. Dynamic Cooldown Proposal · March and April 2026 Governance Update.

Three different propositions therefore coexist: a described 90-day contract ceiling, a policy framework using 1/3/5/7-day tiers, and one-day inherited state observations. None substitutes for the others. The documentary policy is not proof of a currently autonomous rule, compliance at each change or a holder-specific service level. Changing a timer or liquidity classification cannot advance a fund’s dealing window or make a borrower repay earlier.

Income allocation can change incentives without proving principal loss

The Reserve Fund page describes protection against adverse income and backing shortfalls and says ongoing revenue allocation to the reserve is zero. That does not say its existing balance is zero. Its current composition, encumbrances, usable amount and priorities between competing uses remain unestablished. Reserve Fund.

The 27 August 2026 fee-switch proposal directs revenue toward ENA buybacks at supply milestones; the Foundation’s 8 September reply reports that the vote passed. The record distinguishes a conditionally approved schedule from actual activation after milestones. The supporting discussion notes the schedule’s lack of an explicit Reserve Fund or competitiveness condition. The underlying vote, milestone satisfaction, implementation and transfers were not independently verified. ENA Fee Switch Activation.

ENA value accrual and the highest possible sUSDe distribution are not identical objectives. A lower staking distribution is first an income-allocation outcome, not evidence that USDe principal has been lost. It may still change leveraged carry incentives. An unwind then depends on outside debt-asset funding, collateral release and the recovery paths already described. The sequence is conditional; no actual buyback, resulting outflow or forced unwind is alleged.

Diversified revenue can reduce dependence on derivative funding while retaining credit, valuation and settlement discretion. The revenue page’s diversification rationale is not evidence that all income streams or liquidity routes remain independent in joint stress. One reserve resource cannot simultaneously be fully available for a credit loss, a margin top-up, redemptions and a new facility. Protocol Revenue · Reserve Fund. No-double-counting and bridge conditions.

7. A proposed local backstop is not demonstrated production capacity

A local conversion facility could reduce reliance on a source-chain round trip. That prospective benefit makes the proposed L2 USDe peg-stability module, or PSM, relevant to remote holders and local lenders. The useful evidence is conditional: on 22 July 2026, Kairos reviewed a 15 July integration test and supported a 20 million USDe seed subject to safeguards. This was not final production testing by this investigation. Guardian’s 2 July audit is known here only through Kairos’s description; its original report was not inspected. Kairos Review of the L2 USDe PSM Proposal.

A seed, a safeguard and a payout asset are different things

A seed, a safeguard and a payout asset are different thingsA July integration test and conditional support for a 20 million USDe seed are not evidence of final production readiness or externally funded payout capacity. Published condition closure and actual external settlement inventory remain unverified. Token seed, reserve commitment and payout asset must not be counted as three independent buffers.JULY REVIEW — DOCUMENTARY EVIDENCE15 Julyintegration testNot final production.22 July conditional support20 million USDe seed proposed.Not 20 million USDC ready to pay.PRODUCTION CONDITION CLOSURE NOT ESTABLISHEDPublished roles / oracles / configuration; segregated capped custody;attestor and supply treatment; delayed ceremony; reserve confirmation.A favorable test review is not the missing completion evidence.PAYMENT STILL NEEDS AN EXTERNAL SETTLEMENT ASSETInventory, eligible users and replenishment must be established.A token seed or accounting exclusion does not supply those assets.A seed, a safeguard and a payout asset are different thingsA July integration test and conditional support for a 20 million USDe seed are not evidence of final production readiness or externally funded payout capacity. Published condition closure and actual external settlement inventory remain unverified. Token seed, reserve commitment and payout asset must not be counted as three independent buffers.JULY REVIEW — NOT PRODUCTION PROOF15 July integration testNot final production.22 July conditional support20 million USDe seed proposed.Not USDC payout inventory.Condition closurenot establishedRoles / oracles / configuration.Segregated and capped custody.Attestor and supply treatment.Delayed ceremony.Reserve confirmation / review.External asset still neededActual payout inventory,eligible access and replenishment.A seed is not extra outside cash.
Kairos’s 22 July 2026 review describes conditional support and test evidence, not verified production completion. The original Guardian audit was not inspected. Conditions are detailed in the condition-to-evidence table. Dashed arrows mark unestablished transitions, not observed failures.
Condition-to-evidence check derived from Kairos’s published review. Missing proof is not proof that a safeguard is absent.
Announced condition or dependencyWhat would establish it for a holderStatus of this assessment
Timelocked roles and oracles; published configurationA release-specific record identifying the installed authorities, delays, price inputs and configuration.Condition described; production closure unverified.
Segregated, capped custodyApplicable custody/control evidence and enforceable limits tied to the actual assets.No completed production or private custody assurance established.
Advance attestor and supply treatmentA consistent record of liabilities, circulation treatment and the reserve commitment.Proposed accounting treatment is not a cash injection or verified reconciliation.
Disclosed delayed ceremony without immediate minter permissionThe disclosed implementation and permission record showing the condition was met.No completed production ceremony or effective-role verification supplied.
Reserve confirmation and review for increasesDated backing, availability and commitment evidence for the seed and any expansion.No amount credited as an independent current buffer.
Usable payout collateralActual external settlement inventory, permitted users, competing demands and replenishment.Early redemptions were described as depending on accumulated collateral; current capacity is not established.

Reserve backing was an operational covenant in the reviewed description. A seed denominated in USDe is not itself USDC or another external payment asset. Excluding an amount from a displayed circulation metric does not add cash; recording a reserve commitment does not establish a realized loss. Claims, reserve use and payout inventory need a consistent reconciliation in which each resource is counted once. Kairos Review of the L2 USDe PSM Proposal. Resource-conservation boundary.

For a Base USDC lender liquidating USDe collateral, a larger quantity of collateral tokens is not the debt asset needed for repayment. A local PSM helps only to the extent that its actual asset, custodian, network, permissions and replenishment can support the relevant exit. No present operating capacity, current production seed issuance or unsupported-supply event is established here.

Remote representation and local liquidity are separate protections

Generic LayerZero OFT documentation distinguishes burn/mint arrangements from adapter lock/mint arrangements and describes owners, delegates, peers and message-security settings. It explains why a remote representation needs its own verification chain; it does not identify Ethena’s installed verifier or executor configuration. LayerZero OFT Quickstart.

The inherited 18 September Base record identified controller 0xd896f26f76ed089a1711284a00af497b19d65171 as token owner, with a one-day minimum and proposer/executor membership for the documented Safe, plus an endpoint and peer. It did not reconcile source locks and remote supply or establish every messaging, delegation and emergency setting. A rejected pause-related probe did not establish an unpaused state or absence of a pause path. Remote-identity and security limits.

The March–April update reports a precautionary bridge intervention and later security changes. It is evidence that intervention can affect access, not a September configuration check. A protective pause or unavailable conversion can harm a local exit while Ethereum backing retains value; invalid remote supply would be a different risk. Neither is asserted to be happening. March and April 2026 Governance Update.

8. Valuation policy can move loss between borrower and supplier

Valuation authority is not one system-wide power. Reserve accounting/NAV, an issuer’s quote, a contract quantity guard, a lending oracle and realized sale or repayment proceeds answer different questions. The issuer oracle page describes off-chain exchange-derived pricing cross-checked with external feeds. It does not turn those feeds into a valuation of all reserves or establish Aave’s and Morpho’s independent inputs. Use of Oracles.

Five valuation and quantity boundaries. No unified live valuation-to-cash reconciliation is established.
ValueRelevant decision or sourceDo not substitute it for
Reserve accounting / fund NAVIssuer, managers, administrators and applicable assurance processes.Unencumbered cash at the entity that must pay.
Issuer quotePricing system, agreed order and customer-specific acceptance.Every holder’s enforceable execution right.
Nominal amount constraintRules and parameters of the particular facility.Independent dollar purchasing power or a fair quote.
Collateral oracle valueThe integration’s own installed input and authority chain.The issuer’s legal redemption price or a funded liquidator bid.
Realized proceedsActual buyer, borrower repayment, settlement asset and route.The earlier marked amount or a guaranteed arrival time.

The selected Base Morpho market remains an exact inherited case, not a generic USDe label. Its identifier is 0x54cf9be57fdfa6457a660991907434ff9d295c465a603a50126ff647d50b7354; it lends Base USDC against Base USDe. The 18 September binding recorded 91.5% LLTV and oracle 0xf4b17c79492d68775e22e8dd0a2bb22854a39a47, a clone targeting 0x846e726a1bf5fd5cbe08c179ee491b085b1cac3e. Full market, clone and input evidence.

At Base block 51,477,448, the par-configured primary was selected; the recorded settings included a 0.5% deviation threshold, 16-hour challenge and 24-hour healing. Constituent readings showed a USDe/USD backup without a USDC/USD denominator. These are dated input and setting observations, not tested guarantees that a deviation always switches, that healing restores correct pricing or that local repayment cash exists.

The source mismatch remains unresolved. The earlier same-input comparison rejected exact equivalence between the deployed deviation output and candidate MetaOracleDeviationTimelock.sol’s average-denominator formula. That does not identify every behaviour of the actual implementation or establish an exploitable defect. This documentary investigation did not rerun that calculation or test the candidate contract. Original comparison and its limits.

The newly inspected README at the candidate repository commit lists factories, including Base factory 0x83910ae3f4a7bb8606402289a60feb95bc39a060, and points to factory source at another commit. It does not identify the selected instance’s complete build, initialization or authority. A factory locator cannot resolve an instance-level behavioural discrepancy. The vault curator’s identity and the issuer’s pricing policy likewise cannot be substituted for the selected oracle’s actual control graph. Steakhouse Oracles README.

The Aave countercase is equally specific: the inherited Ethereum sUSDe path uses the staking conversion ratio multiplied by capped USDT/USD, not a direct USDe spot quote. A cap on upward price or ratio growth need not recognize an off-chain loss or exit interruption immediately. Its leverage-headroom arithmetic cannot be relabelled as an arbitrary USDe-market-depeg threshold. Aave inputs and qualified arithmetic.

The exposure behind the Base comparison is also bounded. At Base block 51,477,892 on 18 September, the selected market represented 88.761411% of the vault’s expected assets; the adapter held 99.992236% of that market’s supply shares. Neither denominator is USDe reserves. The separate Ethena-oriented vehicle had nonzero dust shares with expected USDC rounding to zero, not evidence of aggregate issuer funding or its absence. Vault, adapter and ownership counterexample.

Creditor consequence: a par-oriented value may spare a borrower from liquidation in a temporary discount while postponing recognition of real impairment. A market-sensitive value may recognize a problem sooner while forcing sale before an orderly exit becomes available. Neither policy creates a buyer or funds repayment. The 20 September cash and eligibility constraints remain necessary to assess the supplier’s realizable recovery. Debt-asset and holder-access boundary.

9. What the audit record establishes—and where it stops

The public audit record should neither be ignored nor turned into a warranty. A reviewed version, the reported findings and a fixes-review identifier are meaningful evidence. Their reach depends on the exact contracts, assumptions and review period. An issuer audit index spans different generations and products; an ENA or USDtb review does not automatically cover USDe, staking or a new PSM. Ethena Audits Index.

Audit scope does not span the whole payment chain

Audit scope does not span the whole payment chainThe inspected audit supports statements about a reviewed code version and reported findings. The match to a present deployment remains a separate unverified link. Legal authority to receive proceeds and funded timely delivery require different evidence; neither is supplied by a code audit.WHAT A PUBLISHED CODE REVIEW CAN SUPPORTScope + reviewed versionReported findings andfixes-review identity.Present deployment correspondenceNot established by the report alone.No current rebuild or full role check.DIFFERENT EVIDENCE IS NEEDED FOR THE REST OF THE CLAIMLegal entitlement / authorityExecuted mandates, eligible holder,release rights and applicable terms.Funded, timely deliveryAvailable asset at the paying entity;release, transfer and arrival in time.The holder depends on all relevant links.One form of assurance does not replace the others.Audit scope does not span the whole payment chainThe inspected audit supports statements about a reviewed code version and reported findings. The match to a present deployment remains a separate unverified link. Legal authority to receive proceeds and funded timely delivery require different evidence; neither is supplied by a code audit.CODE-REVIEW EVIDENCEScope + reviewed versionReported findings andfixes-review identity.Present deploymentcorrespondenceNot established by report alone.No current rebuild / full role check.SEPARATE EVIDENCE REQUIREMENTSLegal authority / entitlementMandates, eligible holder,release rights and terms.Funded, timely deliveryActual usable asset at the payer.Release and transfer before due.All relevant links matter.An audit does not supply the cash.
Evidence-boundary diagram based on the inspected published audits and the 20 September legal and payment analysis. Missing deployment correspondence is not a finding of an active defect. No current solvency or end-to-end security certification is supplied.
What was actually inspected for the documentary chapter, not the union of every audit ever listed.
Material inspectedSupported scopeImportant limit
Pashov Mint V2 review, May 2024Complete published Markdown: EthenaMinting and SingleAdminAccessControl; reviewed/fixes-review identifiers and reported findings.No current runtime equivalence, full role inventory, custody-control or whole-system security conclusion.
Code4rena Ethena reportScope/summary, relevant dispositions and architectural discussion for the older six-contract system.Not every line or embedded proof; does not cover every later V2 change or the selected Base oracle.
Ethena audit indexListed report dates and product labels.Not every listed report body was inspected. Count is not coverage.
Guardian PSM audit as described by KairosReviewer-reported existence, scope and results.Original Guardian report not obtained; its rating, fix closure and production readiness are not independently endorsed.
Prior dated observationsSelected normal-state bindings, settings, amounts and scoped arithmetic from 18 and 20 September.Not fresh 22 September state, a complete invariant review or operational assurance.

Pashov identifies reviewed commit b60b7193636d499ce7f89c4f5afe3b99cf31a2b6 and fixes-review commit 9cd4ad7b46acc35f6b3340c808200279fbe75de0. It reports one Medium issue concerning order reuse and two Low issues concerning initial asset configuration and economically related asset limits. The inspected text names a fixes-review version but does not provide a complete per-finding resolution table. This chapter neither alleges an active defect nor treats the fixes-review identifier as proof of today’s deployed remediation. Pashov Ethena Security Review — May.

Code4rena records a 24–30 October 2023 review window, publication on 21 December 2023, and four Medium findings with no High findings. Review dates, publication dates and index dates are different. Historical caps, inventory assumptions and sponsor responses cannot establish a current bounded-loss amount for the different September configuration. Code4rena Ethena Labs Audit Report.

Financial assurance has another scope. The 20 September study could not inspect then-current assurance bodies; among its accessible alternatives, the latest readable issuer body had a 26 November 2025 cutoff, with linked custodian images unreadable. That statement is about accessible evidence, not a claim that no later assurance exists. This chapter did not refresh the assurance search. Later governance references to attestations are not the missing opinion, procedures, liabilities and encumbrance schedule. Original assurance-access boundary March and April 2026 Governance Update · June 2026 Governance Update.

The missing end-to-end assurance would have to join several types of evidence: deployment-specific code and authority; applicable legal rights and recipient mandates; assets net of other commitments; and actual ability to release and deliver the required settlement asset. A source review, appointment announcement or custodian balance alone cannot establish all of those propositions.

10. Holder consequences and the evidence still needed

The documentation makes the decision chain more concrete without completing the deployed-control investigation. Some gaps concern the ability to prevent a harmful action; others concern the ability to complete a legitimate payment. They have different loss bearers and may require different evidence.

Conditional pathways, not incident findings or failure probabilities. They need not occur together.
ConditionFirst affected partyProtection and remaining condition
Issuer acceptance or customer access is withheldA redeemer, intermediary-dependent holder or borrower with a deadline.Admission/price controls can protect backing; an alternative exit still needs access and funding.
Pool, fund or custody release is lateIssuer inventory, then holders needing that payment.Collateral, segregation and orderly realization may preserve value but must deliver before the obligation is due.
Income or liquidity classification changesStaker and leveraged staking borrower.Orderly distributions and queues do not supply outside debt-repayment cash.
Oracle value diverges from realizable proceedsBorrower during earlier liquidation, or supplier during delayed recognition.A calibrated feed must be paired with a viable repayment or liquidation route.
Local conversion or messaging is unavailableRemote holder and local lending creditors.Defensive containment does not itself pay creditors or reconcile remote supply.

Helpful outcomes remain possible. A prompt restriction can contain damage; borrower repayment can replenish lending liquidity; an orderly fund sale can avoid a distressed loss; independent cash can meet a deadline while valuable backing settles. The evidence does not justify either an inevitable spiral or a universal rescue. The resource has to be genuinely available to the correct party, not merely described under a shared brand.

Missing facts are ranked by their effect on a decision, not assigned vulnerability severity ratings.
Decision-changing gapConsequence for interpretation
Deployment-specific Mint/controller correspondence and disclosure reconciliationNo complete present control matrix, signer-independence conclusion or action-specific warning-window assurance.
Selected Base implementation, source mismatch and transition authorityNo certified 16-hour switch, 24-hour healing, freshness/failure fallback or complete oracle change-control conclusion.
Installed remote security and production PSM condition closureNo complete source/remote supply reconciliation or quantified funded local exit.
Executed creditor, investor and custody mandatesNo holder-specific enforceable release deadline or complete legal priority for the observed Maple/JAAA wallets.
Reserve assets, encumbrances and commitmentsNo current issuer-wide coverage, independent shared-buffer amount or stressed redemption maximum.
Implementation of announced policy and appointmentsNo verified agreement execution, autonomous cooldown compliance, fee-switch activation or actual buyback transfers.

Use the documentary findings, but retain the partial boundary. Policy intent, publication scope and dated observations are not interchangeable. The missing records do not prove that a control, agreement or asset is absent. They do prevent a stronger claim about current enforcement, full recovery or every holder’s ability to exit. The central reader question remains: who must act, which asset must arrive, and what could stop that happening before the deadline?

11. Sources and inspection boundaries

All new public-document reading for this chapter is dated 22 September 2026. For undated served pages, that is an access date—not an effective policy or deployment date. Governance announcements and historical audits retain their own dates. Repeated publications from the issuer or the same committee are not independent corroboration.

The 18 September whole-system foundation and its source and observation trail supply the inherited contract, Aave/Base, custody and exit bindings. The 20 September backing-recovery chapter and its recorded observations and methods supply the Maple/JAAA, asset-inventory and matched-payment evidence. Neither chapter nor its observations was redated for this update.

Key Trust Assumptions

Served control descriptions, reviewed 22 September 2026. Seven-signature/seven-day statements and conflicting gatekeeper descriptions are not a versioned deployment-specific control record.

Matrix of Multisig and Timelocks

Described separation of roles; no fresh complete operator or signer inventory.

Mint and Redeem Key Functions

Documented administrator, operational and emergency responsibilities; not execution evidence.

Mint and Redeem Contract V2

Rollout notice dated 8 July 2024. Design, benefactor/beneficiary rules and limits; neither present asset support nor security certification.

Order Validity Checks

Post-signature acceptance, validation and last look; not an actual customer quote or service-availability test.

User Security Measures — Minting

Organizational/key-management descriptions, read against the later V2 notice. Production procedures and operating effectiveness were not inspected.

Use of Oracles

Issuer pricing architecture. Does not establish the inputs of an independent lending integration or value all reserves.

Internal Services

Intended portfolio-management, quote, order and backing-movement coordination; not measured performance.

Backing Asset Custody

Delegation, undelegation and inventory-refill description; no executed custody mandate or guaranteed settlement interval.

USDe Mint User Agreement

August 2025 header; especially sections 1, 3, 8, 10 and 19. Served terms, not an executed account-specific agreement or enforceability opinion.

USDe Terms and Conditions

August 2025 header; holding/Mint-user, valuation, chain and suspension provisions, especially sections 1–14. Read with the agreement’s precedence provision.

Governance

Delegated organizational design and limits of wholly on-chain governance; not evidence that USDe holders govern their own redemption terms.

Risk Committee

Served process and roster, read with the later appointment announcement. Service-agreement template and full enforceable mandates were not obtained.

Risk Committee Re-election, August 2026

Thread opened 22 July; result post 10 August. Election/process and result portions inspected; underlying voting-platform record not separately verified.

Fifth-Term Official Committee Announcement

21 August 2026. Foundation screening and conditional appointments; signed agreements and assumption of full mandates not verified.

Reserve Fund

Served reserve policy and zero ongoing revenue allocation. Not a measured zero balance, commitment reconciliation or unconditional support promise.

Staking Key Functions

Described cooldown ceiling, rewards, restricted-share and rescue functions. Not fresh deployed permissions or a plain-USDe confiscation power.

User Security Measures — Staking

Share, withdrawal and vesting design; no current withdrawal or rewarder-operation test.

Protocol Revenue

Income categories and diversification rationale; no quantified independence during joint stress.

Key Addresses

Core Ethereum/Base locator portions inspected. Addresses corroborate identity descriptions, not current roles, funds or remote security.

March and April 2026 Governance Update

Published 28 May 2026. Relevant cooldown, bridge and assurance-account passages; reported operations are not refreshed September configurations.

June 2026 Governance Update

Published 17 July 2026, reporting June. Backing approvals, shared JAAA/STAC exposure and assurance references; not current balances or an inspected assurance body.

Dynamic Cooldown Proposal

Opened 12 March 2026; relevant committee discussion through 16 March. Policy tiers and liquidity classification; backtests not rerun and autonomous operation not verified.

Kairos Review of the L2 USDe PSM Proposal

22 July 2026 review of a 15 July integration test, with conditional support for a 20 million USDe seed. Guardian’s 2 July audit is known only through this account; original audit and production condition closure were not inspected.

ENA Fee Switch Activation

Proposal dated 27 August 2026; Foundation result reply 8 September. Proposal, analysis and result reply read; underlying vote, milestones, activation and transfers not independently verified.

Pashov Ethena Security Review — May

Complete published Markdown inspected; blob 03b44deb49d563680e5f5d3f91f5bea5996ada1d. Reviewed and fixes-review identities are given in the audit discussion; no rebuild or current deployment match.

Code4rena Ethena Labs Audit Report

Review window 24–30 October 2023; publication 21 December 2023. Scope/summary, relevant dispositions and architectural discussion inspected, not every report line or embedded proof.

Ethena Audits Index

Publisher catalogue only. Other listed bodies were not all read; product labels and dates do not enlarge an individual report’s scope.

Steakhouse Oracles README

Complete pinned README; blob 64c5477e2c06e72d0c4d9a3dbcf01fcb0f0ae3cf. Factory-source pointer uses 36385342274f71999b66c79c4475234a39ba9a01. Neither pointer establishes the selected oracle instance’s build.

LayerZero OFT Quickstart

Generic architecture and ownership/configuration portions inspected. No Ethena-specific installed verification or execution configuration checked.

Updated as new research is ready. Documentary research dated 22 September 2026; inherited contract observations and recovery evidence retain their 18 and 20 September dates. No live monitoring, security certification, current reserve opinion or personal investment recommendation.

Assessment · All research reports · Coverage and limits · Evidence method · History

Search published pools, pages, reports, and evidence.