USDe Risk Audit / Dated research
A creditor was paid. The debt did not disappear.
A matched refinancing shows how cash can reach an original lender without completing the borrower’s exit. Follow the payment, the new debt and the creditor still waiting.
The advance is real, but limited: an established Ethereum Aave borrower received temporary USDC, paid part of its actual USDT debt, borrowed replacement USDC and returned the temporary principal. The sUSDe collateral remained in place. The replacement USDC debt and most original USDT debt remained outstanding.
4.688632 USDT was the account’s own contribution to repayment—not a fee. The cash event occurred at 05:44:35 UTC; the later two-denomination debt state is dated 14:04:11 UTC. They must not be read as one snapshot or one final settlement.
From an assumed funding step to a recorded partial refinance
Earlier investigations separated three questions: whether collateral has accepted value, whether it can be released, and whether the necessary debt token arrives in time. They also distinguished a temporary advance from the creditor’s ultimate repayment. The new event supports a stronger conclusion for one named account: a specific funding and repayment sequence actually occurred. Keeping all of that account’s funding wholly hypothetical would now understate the evidence.
The account is 0xea1776733cc969df4ff004a9e1a2d87f5b60add4, the direct-sUSDe Aave borrower already identified in the 2 October investigation. The new result does not select a different borrower or make the old hypothetical USDC example real. It follows the actual USDT account into a new state with both USDT and USDC debt.
A second advance examines an additional million-PT path through sDAI and DAI to Ethereum USDC. Exact successive quantities share one explicitly requested state block. This is useful route evidence, but it remains an indicative comparison: it neither identifies a funded PT owner nor shows an executed cash exit. The two findings have different evidentiary strength and must not lend each other unsupported certainty.
| Record | Block and time | What it establishes |
|---|---|---|
| Before the refinancing event block | Ethereum 26,138,498 · 05:44:23 | A newly inspected historical end-of-block state. |
| Matched refinancing and post-event-block state | Ethereum 26,138,499 · 05:44:35 | Nine matched event records and a separately inspected end-of-block state. |
| Later Aave state and PT route | Ethereum 26,140,985 · 14:04:11 | Persistent debt and indicative exact-quantity route views. The account batch’s outer reported head is 26,140,986; the inner block governs. |
| Base borrower and shareholder | Base 52,296,246 · 14:03:59 | A different network and resource set, not an atomic snapshot with Ethereum. |
The event and later Ethereum state are 8 hours, 19 minutes, 36 seconds apart. The later quote is not the price executed by the earlier conversion. October 2 and 4 measurements, the 3 October analysis and the 5 October two-corridor limits keep their original inputs and assumptions. Nothing here refreshes every reserve, permission or legal entitlement in the wider assessment.
Basis: newly supplied October 7 financial records and the observation guide. Matched mined logs and historical states are not a separately obtained full receipt or a production security certification.
The actual payment sequence: trace each token and each creditor
The matched transaction is 0x65262caf428ff6865c63b76f6c094ee7c7a70a72a213e5df78f651e5127f012b. All nine retained records agree on Ethereum block 26,138,499, its block hash, the transaction hash and the timestamp. Their log indices establish the ordering. The public explorer link is an inspection locator; the investigation did not obtain a separate full transaction receipt.
USDC and USDT are both displayed in their own token units. Calling them simply “dollars” would hide the different reserve that provides replacement credit. The Aave interface supplies the reserve, debtor and repayer field meanings; actual transfers and adjacent debt states provide the account-specific evidence. The interface is not a complete deployment match.
An actual payment sequence—and the loan that survives
| Log index | Observed record | Financial meaning |
|---|---|---|
| 0x3ef | Morpho records a 10,000-USDC temporary loan to the selected account. | The principal record, paired with the following transfer. |
| 0x3f0 | 10,000 USDC transfers from Morpho core to the account. | Temporary repayment funding arrives. |
| 0x3f1 | 10,000 USDC transfers from the account to a conversion intermediary. | The first USDC arrival is spent. |
| 0x405 | 10,001.640594 USDT transfers from an intermediary to the account. | The original debt token arrives before payment. |
| 0x40d | 10,006.329226 USDT transfers from the account to Aave’s aUSDT address. | The original reserve receives underlying-token cash. |
| 0x40e | Aave records the matching USDT repayment, with useATokens=false. | The repayment record agrees with the token transfer. |
| 0x413 | 10,000 USDC transfers from Aave’s aUSDC address to the account. | A different reserve supplies replacement cash. |
| 0x414 | Aave records a matching 10,000-USDC variable-rate borrowing for the same account. | A persistent replacement obligation is created. |
| 0x418 | 10,000 USDC transfers from the account back to Morpho core. | The temporary principal is returned—not the persistent Aave debt. |
The source and destination of the two Aave transfers matter. The USDT reserve and its suppliers receive cash. The USDC reserve supplies cash and receives a borrowing claim. Those are different financial effects even though both reserves belong to Aave. Morpho’s principal outflow and return settle its temporary advance, not the borrower’s new USDC obligation.
The internal conversion between the account’s outgoing USDC and incoming USDT was not reconstructed. The records establish the selected cash endpoints, not a complete inventory chain, a particular exchange fee schedule or a future conversion guarantee. No human or legal beneficial owner is inferred from the addresses.
Aave event-field source · Morpho temporary-loan description · Selected transaction and state data.
The account’s 4.688632 USDT contribution is not a fee
The received USDT does not by itself equal the payment to Aave. The recorded amounts differ by exactly the contribution shown below. Adjacent historical states support that interpretation: the account’s idle USDT falls from 9.689386 to 5.000754.
10,001.640594 USDT received + 4.688632 USDT own cash = 10,006.329226 USDT repaid.
This contribution pays debt. It is not gas, a withdrawal charge, a conversion fee or an unexplained loss. The cash record also cannot establish all-in profit: no usable separate receipt, gas payer, sponsorship record or complete service-charge account was obtained. The fact that a conversion delivered slightly more USDT units than the USDC units spent does not settle net economic return.
The USDC ledger balances separately. The account receives 10,000 from Morpho and spends 10,000 through the intermediaries. It later receives 10,000 from Aave and returns 10,000 to Morpho. The sampled pre/post USDC balance is zero in both states. 20,000 USDC of gross arrivals is not 20,000 of independent net funding. The second arrival creates a debt and pays back the first source.
Balance differences are not automatically payment amounts either. The pre/post USDT debt declines by 10,006.047631, whereas 10,006.329226 USDT was transferred as repayment. The 0.281595-USDT difference is retained as an interval accrual/rounding residual, not inferred to be a service fee. The post-block USDC debt is 10,000.000002, two base units above the borrowing event’s 10,000-USDC amount.
At the accepted debt prices returned at both endpoints, reported aggregate debt falls by 5.38082159 USD between the blocks. That is an accepted-value accounting change, not realized profit after costs. The endpoints are twelve seconds apart and can include accrual and other block effects; they are not transaction-local balance snapshots. The matching logs strengthen the attribution of the displayed payments without turning every book-value change into cash.
Exact quantities and the pre/post state are retained in the observation guide. No expense is filled in with a guessed or zero amount.
Follow the replacement creditor into the later state
At 14:04:11 UTC the same account still has 5,359,416.826188716790252832 sUSDe represented by its aSUSDe balance. Its outstanding obligations are 5,866,650.101604 USDT and 10,000.460197 USDC. The later record includes the USDC borrowing flag alongside the USDT borrowing and sUSDe collateral configuration. The current account description therefore needs two debt denominations; earlier USDT-only observations remain unchanged as historical facts.
The event and the later debt state have different clocks
| Quantity | 05:44:23 · 26,138,498 | 05:44:35 · 26,138,499 | 14:04:11 · 26,140,985 |
|---|---|---|---|
| USDT debt | 5,876,173.695981 | 5,866,167.648350 | 5,866,650.101604 |
| USDC debt | 0 | 10,000.000002 | 10,000.460197 |
| sUSDe collateral | 5,359,416.826188716790252832 | Same quantity | Same quantity |
| Cooldown end / underlying amount | 0 / 0 | 0 / 0 | 0 / 0 |
| Reported health factor | 1.050383103825264343 | 1.050384082608568726 | 1.050346321491985487 |
The later accepted debt total is 5,875,672.29518107 USD and the category remains eMode 31. Health factors above one are favorable observations about accepted-value collateralization. They are not an owed-token payment or evidence that the collateral has been fully released. The small pre/post improvement does not establish a material reduction in total exposure.
The favorable funding conclusion is also narrow but meaningful: this borrower obtained a real repayment resource and returned the temporary principal. It would now be wrong to characterize all funding for this account as unobserved. It would be equally wrong to scale the 10,000-USDC draw into complete-position capacity. The draw was below the account’s available borrowing headroom; it does not empirically establish a refinance beyond that headroom or a standing facility at any other size.
The variable-rate borrowing event and its rate field do not commit terms through a future sale. No fixed tenor or final repayment date follows from the later positive balance. Without complete intervening history, the increase after the event is not attributed entirely to passive interest.
Finally, the zero/zero cooldown fields show no already-running request at the three sampled states. The observed 86,400-second setting does not start a funded wait merely because it was read. Adding one day to the event or research time would invent a request and cash-arrival schedule. A later direct sale could avoid unstaking, but still needs enough admitted final cash and repayment of every surviving funding obligation.
New event/state evidence, not a retroactive change to the 4 October account comparison. See exact observation scope.
A wider PT route reaches USDC through a different savings claim
The separate PT comparison still starts from 1,000,000 PT-sUSDE-26NOV2026 in the previously selected Ethereum market. The new route sells its native sUSDe output for sDAI, previews DAI redemption, then quotes DAI into Ethereum USDC. It avoids an Ethena unstaking step by selling the sUSDe claim. That removes one modeled waiting dependency, not the need to obtain, redeem and convert another claim under applicable conditions.
The selected first-hop pool is 0x167478921b907422f8e88b43c4af2b8bea278d3a. Its reported coins identify sDAI at index 0 and sUSDe at index 1. The sDAI asset getter identifies DAI; the final 3pool identifies DAI at index 0 and Ethereum USDC at index 1. The denomination chain is grounded in those specific reads rather than inferred from names.
A further route changes the receipt—but not the repayment target
| Step | Quantity | Meaning |
|---|---|---|
| Starting budget | 1,000,000 PT | An input budget, not an identified owner’s completed sale. |
| PT → native output | 791,280.184140667115346965 sUSDe | Static-router net-token output. |
| sUSDe → sDAI | 290,094.735978077632862708 sDAI | A quote for exactly the preceding sUSDe output. |
| sDAI → DAI | 342,730.930787028554113413 DAI | Redemption preview, not a transfer. |
| DAI → Ethereum USDC | 342,677.470045 USDC | Final quote for exactly the previewed DAI quantity. |
| Retained hypothetical principal | 900,000 USDC | Not a measured PT borrower or financing offer. |
| Named-route gap before extra costs | 557,322.529955 USDC | Additional interest or external costs would not close this shortfall by themselves. |
The successive inputs retain full integer precision and the same explicit block. Rounded display quantities were not fed into later enquiries. That is stronger measurement consistency than combining unrelated amounts from drifting states. It remains a set of views, not an executed package, reserved future prices or an admitted financing commitment.
Pendle distinguishes net token output from the SY amount redeemed to produce it. These are not two balances to add together, and a fee already deducted from the net quote is not subtracted a second time. Other execution, financing and service costs remain unknown. Spark’s documentation identifies the observed sDAI address as a DAI savings receipt offered through Sky’s savings mechanism, not an Ethena payment or a corporate guarantee by Spark.
The selected pool holds 290,286.893683513943564680 sDAI at this state; the quoted output is approximately 99.9338% of that inventory. The final DAI/USDC pool holds 45,789,752.349654 USDC. A large final-pool cash balance therefore does not by itself enlarge the earlier receipt-token output. Neither inventory is owned repayment funding assigned to the PT holder.
The preview implies approximately 1.1814448464 DAI per sDAI for this quantity, rather than one. The route uses that specific preview instead of a new par assumption. But a favorable share-conversion ratio cannot compensate for not obtaining enough shares. sDAI, previewed DAI and final USDC are successive forms of the same route resource, not three reserves.
Registry discovery returned four candidates, not four established cash paths. One other full-budget enquiry returned only 32.557419537236092841 sDAI; another requested quote reverted and remained nonnumeric; another was not carried through a full final-token route. Neither the small quote nor a failed call is added to the selected path. A rejected enquiry is not a zero-liquidity finding.
This is an additional route, not an additive correction to the earlier two-corridor envelope. Adding a new whole-input quote to the old whole-input amounts would spend the same PT budget again and mix state dates. The old restricted assumptions remain intact. No optimized split, best-execution guarantee or all-market upper bound is claimed.
For the retained hypothetical 900,000-USDC principal, the selected path is insufficient even before extra costs. That bounded negative says nothing about every possible route, a lower actual debt or an independent contribution. The observed 10,000-USDC Aave refinance belongs to a different account/obligation case; it cannot supply financing to this hypothetical PT holder by association. An actual owner, credit interval, applicable redemption conditions and final receipt remain unestablished.
Pendle net-output definitions · sDAI claim and preview · Indexed quote interpretation · Exact amounts and pool identities.
Base: a remeasured obligation still needs an identified payer
The selected Base borrower remains 0x5afe2414f865cbc5ff4e25979996c5b1252e0002 in the same USDe-collateral/USDC-loan market. At Base block 52,296,246, 14:03:59 UTC, its collateral is 3,042,881.283763481768838477 Base USDe. Upward-rounded stored-share debt is 2,707,724.528483 Base USDC, using the retained virtual-share convention.
The market’s recorded accrual is 34 seconds older than the batch clock. The calculated amount is not an executable future payoff invoice; later settlement can require a different amount. No guessed rate or unobserved repayment is added to make the stored figure current at another time.
The inspected direct Base-USDC balance, free Base-USDe balance and supplied shares in this same market are all zero. Those are scoped observations, not failed requests converted into zeros. They exclude those particular objects as positive owned resources at that state, but do not establish complete wealth or rule out another wallet, other markets, a sponsor or an admitted facility. Matching borrow-share counts at the October 4 and 7 endpoints do not prove an absence of repayment and redrawing between them.
The market’s nominal supply-minus-borrow amount is 38,816,025.713668 USDC. It does not identify a willing lender, the account’s admitted draw, net proceeds after fees or the replacement obligation. Similarly, October 4’s protocol-held inventory was not assigned borrower cash. The actual Ethereum refinancing cannot pay this Base loan simply because both networks use a token named USDC.
The funding branch therefore remains open: a sufficient, entitled same-network resource or a supported final sale must still be identified for complete repayment. That is narrower than saying no Base refinancing or alternative route exists. Earlier unsuccessful route enquiries retain their original dates and do not become new zero-proceeds findings.
New Base borrower records and the retained location-specific payment boundary. See the clocked resource screen.
Who benefits from the payment—and who still bears the risk?
The original USDT repayment is a stabilizing counterflow for that reserve. Suppliers there receive underlying cash for the repaid slice rather than merely a promise of eventual collateral recovery. At the same time, another reserve supplies USDC and holds a continuing receivable. Calling the whole sequence an undifferentiated improvement in “Aave liquidity” would conceal both the denomination and the creditor.
| Condition | Helpful effect | Exposure that remains |
|---|---|---|
| Recoverable temporary discount | Refinancing may avoid forcing an immediate sUSDe sale; the recorded collateral stayed in place. | The borrower and persistent creditor still need final payment under actual terms. |
| Genuine impairment | The repaid original slice has received cash. | Changing debt denomination does not manufacture missing collateral value; remaining or replacement creditors can bear it. |
| A new receipt-token route | Selling sUSDe avoids that route’s Ethena unstaking step. | The receiving pool takes sUSDe exposure; the exit side relies on sDAI redemption and final USDC conversion. |
| A different network or owed token | The observed Ethereum transaction completed its particular token-payment leg. | Ethereum USDC, Ethereum USDT and Base USDC cannot be automatically netted or bridged by assumption. |
| Competing claims on vault resources | Working admission and genuine borrower repayments can support cash access. | Admission does not reserve cash, determine priority or reveal the selected holder’s all-in cost. |
An unleveraged holder may have time to wait or choose another route; a creditor with an earlier obligation may not. A fixed-block quote can show that a named amount misses an illustrative debt without proving the underlying asset is worthless or requiring every holder to sell. Conversely, a positive health factor cannot substitute for a funded final-token arrival.
The whole-system boundaries remain essential. Issuer backing claims are not personal assets of these borrowers. PT, SY, sUSDe and USDe are not separate reserves to add together; neither are sDAI, its DAI preview and final USDC. The foundation and backing-recovery investigation preserve the ownership, location and timing distinctions behind those conclusions.
Exceptional oracle response, authority changes, bridge continuity and PSM funding remain conditional. A natural refinancing event, an ordinary quote or a normal setting does not establish those protections. The new evidence strengthens the financial account of one partial repayment; it does not complete deployment assurance or a system-wide solvency assessment.
What is now established—and what would overstate it
The full funding and recovery investigation remains partial. The progress is not merely another quote: an actual named-account funding sequence is observed. The remaining gap is also not merely a missing timestamp: most original debt and replacement debt persist, and complete final settlement has not been traced.
| Question | Supported advance | Still unestablished |
|---|---|---|
| Can this Aave account obtain any repayment funding? | Yes: a specific 10,000-USDC temporary advance, USDT payment, replacement borrowing and return are matched. | Standing or full-position capacity, final repayment of both debts, realized all-in cost and complete collateral recovery. |
| Is the new PT comparison quantity-consistent? | Yes: exact successive inputs share Ethereum block 26,140,985. | Actual PT owner, committed capital, admitted funded interval and final payment receipt. The named route misses hypothetical principal before extra costs. |
| Does Base protocol cash fund this borrower? | Inspected borrower balances and same-market supply shares remain scoped zeros. | A sufficient owned or committed same-network resource and final obligation terms; other resources are not presumed absent. |
| Has the selected shareholder received a net payout? | A new preview and a successful bounded standard-event negative are available; October 2 ordinary admission remains positive. | Its actual receipt, complete expenses, attributable fee dilution and full-period competing uses. |
| Are exceptional protections certified? | No additional assurance is drawn from these financial records. | Unresolved control, oracle, bridge and PSM conditions remain separate. |
The evidence is provider-mediated. Matching transaction/block hashes, log order, reserve fields and adjacent states substantiate the described cash sequence, but no separate complete receipt or independent finality certification was obtained. C0/C1 are end-of-block observations rather than internal transaction traces. The broader intervening history is incomplete, and the internal conversion intermediary chain is not reconstructed.
The historical access error, rejected candidate quote and initially unsuccessful metadata call remain unavailable or nonnumeric where appropriate. A subsequent documented token-binding enquiry supplied the route identity; none of these acquisition outcomes is interpreted as a contract-security defect. Research’s offline consistency checks support decoding and bookkeeping at the saved inputs, not successful future execution.
No transaction instructions, financing recommendation or promise of par exit follows. The decision-changing next evidence would link a whole obligation to final settlement with attributable costs, rather than scale a partial draw or relabel an indicative amount as committed liquidity.
Source trail and dated observation data
The reader dataset below provides selected token movements, state clocks, route quantities and scope limits. It is a companion for inspection—not an additive balance sheet, live feed or replacement for the full historical investigations. Numeric token amounts and large integers are strings so readers can preserve precision. An explorer’s default current view may differ from the stated historical block.
Download October 7 observations (JSON)
Observed transaction, account states and route quantities
The accepted October 7 research supplies nine unique event records for the matched transaction, adjacent historical states at Ethereum blocks 26,138,498 and 26,138,499, and later state/quote evidence at 26,140,985. The actual borrower is the established Aave account. No full receipt, gas statement or complete internal conversion trace is implied by these locators.
The additional first-hop pool is sUSDe/sDAI; the savings receipt is sDAI; the final DAI/USDC view uses 3pool. The selected PT market retains its earlier instrument identity.
Base observations are at 52,296,246, for the selected borrower and selected shareholder. The owner-indexed standard-withdrawal query covers 52,294,247–52,296,246 only. The separate historical denominator request at 52,154,674 was unavailable.
Morpho: temporary funding and return
Flash Loans, inspected by Research on 7 October 2026. The financial description supports the temporary-principal interpretation. Actual amounts come from the matched transfer records, not a documentation example. No code example or linked test was executed.
Aave: distinguish reserve, account, repayment and borrowing
IPool interface, inspected on 7 October. The Borrow and Repay declarations supply field meanings checked against the observed events, transfers and balances. Served main-branch source is not a pinned production-build match or an all-account service guarantee.
Pendle: net token output is not a second SY receipt
RouterStatic swap functions, inspected on 7 October. Net output, intermediate SY and already-deducted fee fields are distinct. The static enquiry is a prediction, not an executed trade or admitted financing package.
Spark: the specific DAI savings receipt and its preview
sDAI Token, inspected on 7 October. The source describes the exact Ethereum receipt, asset/share units and redemption preview. A different savings product is not substituted for this sDAI address. The preview remains distinct from an actual DAI transfer.
Curve: indexed financial output views
StableSwap NG plain-pool views, inspected on 7 October. Used for the narrow predicted-output and coin-index interpretation, not to certify the code or security of every queried pool. The selected addresses and quantities are separately observed.
The newly inspected public documents have an October 7 access date. That date does not refresh their entire contents, older balances, maturity records, normal admission or exceptional safeguards. Source descriptions, saved observations and conditional financial deductions remain different evidence.
Earlier exact reader data remain available as the 20 September backing-recovery dataset and 27 September integration dataset. They are not October 7 measurements. Read the October 4 chapter and October 5 analysis at their original scopes, or return to the complete research catalogue.