BlackRock BUIDL

Green · 79/100

Executive summary

BlackRock BUIDL is a tokenized institutional money-market fund holding short-term U.S. Treasuries, cash, and repo, targeting a stable $1 NAV with ~$3.5bn TVL across eight chains; it scores 78/100 (green band) with high data confidence (93/100).

  • Security: Multiple audits by Cyfrin and Halborn of the Securitize DSToken framework found 1 critical (rebasing), 0–3 medium, and various low/informational issues; remediation and bytecode-match to deployed BUIDL contracts are not verifiable as of September 2026. RD Auditors reviewed BUIDL-labelled code in March 2024, but deployment correspondence is unverified. Veritas automated scan scored Ethereum proxy 70.06/100.
  • Incidents: No verified loss events; key operational risk is concentrated in BlackRock (manager), BNY Mellon (custodian), and Securitize (transfer agent/tokenization platform)—any failure could delay NAV, redemptions, or transfers.
  • Governance & custody: Centralized control by BlackRock and Securitize via multi-permissioned Fireblocks wallets; roles include MASTER (upgrades), ISSUER (minting), and TRANSFER AGENT (burns/freezes). No DAO governance. Underlying assets custodied off-chain by BNY Mellon; on-chain tokens are permissioned claims subject to whitelist and KYC. Signer thresholds, key rotation, and cross-chain parity are not verifiable.
  • Top risks: (1) Centralized admin can pause, freeze, seize, and upgrade contracts without token-holder vote. (2) Permissioned structure means no permissionless exit; redemptions depend on issuer/transfer-agent operations. (3) Cross-chain bridge risk via Wormhole for interoperability. (4) Regulatory/eligibility constraints limit transferability. (5) Off-chain collateral depeg or custodian insolvency would impair NAV and on-chain token value. (6) Liquidity mismatch if secondary on-chain demand exceeds primary redemption capacity.
  • Strengths: Institutional credibility (BlackRock brand, regulated structure), multi-chain reach (Ethereum, Solana, Aptos, Arbitrum, Avalanche, BSC, OP, Polygon), 24/7 on-chain settlement, composable as DeFi collateral, and organic Treasury-linked yield without leverage or emissions.
  • Unverified: Exact remediation status and bytecode correspondence for all audits; current admin addresses, timelock delays, and role-holder identities; full reserve composition and custody wallet addresses; open API availability; detailed fee breakdowns and net yield after all costs.
  • Recommended exposure: Suitable for institutional allocators seeking tokenized short-duration Treasuries with on-chain settlement, subject to strict eligibility and KYC. Position sizing should reflect centralized control, custodian concentration, and permissioned liquidity; treat as a regulated fund share, not a decentralized stablecoin. Limit exposure to a portion of cash-equivalent allocation and ensure backup liquidity for redemption delays. Verify whitelist status, redemption terms, and custodian/transfer-agent operational continuity before deployment.
  • Open questions: (1) Confirm current bytecode match between audited code and all eight chain deployments. (2) Obtain signer threshold, key-rotation policy, and geographic separation for Fireblocks multisig. (3) Verify real-time reserve composition, maturity profile, and custodian wallet addresses. (4) Clarify redemption processing times, any gates or fees, and secondary-market liquidity depth on each chain. (5) Assess Wormhole bridge security posture and cross-chain message verification. (6) Review legal opinion on bankruptcy remoteness and investor priority in custodian or issuer insolvency.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 8 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-09-05)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 20 4.0 TVL $3,539,510,946 = 20% of reference ($17,538,184,136)
Data confidence 93 7/7 critical categories; 22/35 verified facts; 35/35 fresh (180d)

Identification

protocol identification

two sources

Identification (as of September 4, 2026). Name: BlackRock USD Institutional Digital Liquidity Fund (BUIDL), tokenized and serviced by Securitize. Website: Securitize BUIDL product page. Docs: No public technical documentation repository was located; the operational interface is Securitize’s BUIDL page and bridge. Category: permissioned, institutional RWA/tokenized money-market fund—not a conventional permissionless DeFi protocol. Launch: March 20, 2024, initially on Ethereum. Chains: Ethereum, Arbitrum, Avalanche, BSC/BNB Chain, OP Mainnet, Polygon, Solana, and Aptos. Securitize confirmed the first seven by March 25, 2025; BNB Chain was added subsequently.

Native token: no governance or protocol token. “BUIDL” is the fund-share/security token, with permissioned transfers and issuer-controlled compliance functions. Contract identifiers / verification. Independent listings agree on these primary identifiers: Ethereum 0x7712…2aec; Arbitrum 0xa652…5872; Avalanche 0x53fc…6a2f; BSC 0x2d5b…f84f; OP Mainnet 0xa1cd…7cf5; Polygon 0x2893…0e99; Solana GyWgeq…6phr; Aptos 0x5003…5f89. Full addresses and a Dune cross-check are Not verifiable as of September 4, 2026 because Dune MCP was unavailable. The registry reports explorer/source verification for Ethereum and Solana and explorer verification for the EVM deployments, but this was not independently re-run here.

> Contradiction / evidence gap: DeFiLlama labels BUIDL as eight-chain and supplies the same truncated identifiers; no raw on-chain/Dune query is available to validate balances, deployment provenance, or chain-by-chain canonical-vs-bridged status. Fork lineage. BUIDL is not evidenced as a fork of an upstream DeFi protocol; it is an issuer-specific tokenized fund deployment. Therefore, “what changed versus upstream” is not applicable.

Public audit evidence for the canonical BlackRock/Securitize deployments, including scope-to-address mapping and whether all eight deployments were audited, is Not verifiable as of September 4, 2026. Search results contain audits for unrelated “BUIDL Official” projects using the same ticker/name, a material name-collision risk. A verified malicious-modification history in comparable BUIDL forks is Not verifiable as of September 4, 2026.

Evidence (6)

maturity

two sources

Securitize presents BUIDL as a real product portal rather than a marketing-only landing page: the site has a dedicated BUIDL page, and third-party coverage describes live subscription/redemption workflows through the Securitize portal rather than a static brochure. Public descriptions also indicate actual product functionality, including whitelisted transfers, redemption requests, and investor onboarding/KYC flows, which is consistent with an operational institutional fund experience rather than a template demo. For user-facing maturity, the strongest external signal is that BUIDL is referenced as accessible through Securitize and, separately, through an integration with UniswapX, implying active distribution plumbing and not just a standalone landing page.

However, a detailed assessment of broken links, fake metrics, and UX quality is not verifiable as of 2026-09-04 from the gathered sources. Open API: Not verifiable as of 2026-09-04. The gathered sources show an API example for RWA.xyz data and BlackRock Aladdin APIs, but no confirmed public open API for the BUIDL/Securitize product itself.

Evidence (8)

Security

bug bounty

one source

Securitize operates a public bug bounty / vulnerability disclosure program for its platforms, and the disclosed scope includes production and sandbox web applications plus the published security contact. The available sources do not provide a clear launch date for the program, nor a public list of paid findings or aggregate results. The program states rewards are discretionary and severity-based (Critical/High/Medium/Low), with response notification targeted within two weeks.

Scope listed in the indexed policy includes id.securitize.io, cp.securitize.io, their sandbox equivalents, and other Securitize-controlled web properties; black-box testing against production is permitted, while social engineering, phishing, DDoS, and third-party services are out of scope. For BlackRock BUIDL specifically, publicly indexed evidence confirms the fund is hosted on Securitize, but a BUIDL-specific bounty program or bounty payout schedule is not verifiable from the gathered sources as of 2026-09-04.

Active
Yes
Platform
self-hosted
Evidence (3)

counterparty risks

two sources

Оценка: высокий структурный риск концентрации на эмитенте, трансфер-агенте и кастодиане; прямое DeFi-, oracle- и LST/restaking-воздействие не подтверждено.

  • Issuer/SPV: BUIDL — доля в BVI-фонде BlackRock USD Institutional Digital Liquidity Fund, Ltd.; BlackRock управляет портфелем, а активы должны состоять преимущественно из cash, U.S. Treasuries и fully-collateralized repo. Это не банковский депозит и не stablecoin; риск включает NAV-loss, ограничения/задержки выкупа, юридические или санкционные ограничения и неплатёжеспособность/операционный сбой фонда или его сервис-провайдеров.
  • Custody/administration: BNY Mellon указан как custodian и administrator; Securitize выполняет placement/transfer-agent и токенизационные функции. Такая концентрация создаёт single-/dual-counterparty risk: сбой BNY может задержать NAV, расчёты или redemptions; сбой Securitize — whitelist, mint/burn, pause и transfer processing.
  • Bridges/interoperability: Securitize объявила Wormhole основной interoperability-инфраструктурой. Следовательно, для cross-chain операций присутствует риск Wormhole messaging/verification, chain finality, replay/configuration и liveness; однако модель использует кастомные контракты Securitize, а не полностью permissionless bridge.
  • Oracles/manipulation: базовый BUIDL-токен не требует DeFi price oracle для своей юридической стоимости; manipulation risk возникает в сторонних рынках/лендинге через stale NAV, thin liquidity или ошибочную valuation feed. Not verifiable as of September 6, 2026 для конкретных oracle integrations и лимитов.
  • Stablecoin/LST/restaking/CEX/MM: прямая экспозиция к LST/restaking не подтверждена. USDC/CEX/market-maker exposure и внешние DeFi-позиции фонда: Not verifiable as of September 6, 2026. Отсутствие публичного exchange listing снижает, но не устраняет liquidity risk.
  • Multi-chain: доли TVL/exposure по Aptos, Arbitrum, Avalanche, BSC, Ethereum, OP Mainnet, Polygon и Solana: Not verifiable as of September 6, 2026 без Dune. Предоставленный список включает BSC, тогда как доступный независимый отчёт подтверждает семь сетей и не перечисляет BSC — это неразрешённое расхождение. Failure scenarios: дефолт/заморозка фонда; insolvency или outage BNY/Securitize; Wormhole compromise или cross-chain halt; chain outage; whitelist/contract pause; depeg на вторичном рынке вследствие redemption queue или stale NAV.
Evidence (5)

crypto custody

two sources

BUIDL’s custody is organized in two layers. The underlying fund assets are held off-chain by BNY Mellon as custodian for the Treasury bills, repo, and cash, while BlackRock manages the portfolio and Securitize serves as the tokenization/transfer-agent layer that handles subscriptions, redemptions, KYC, and whitelisting. Investor-held BUIDL tokens can be self-custodied or held through approved institutional custodians, but only whitelisted wallets can receive or transfer the token.

The token layer is permissioned, not freely bearer-style.

Withdrawal paused
No
Evidence (4)

incident

one source

Key-person risk: not verifiable as a specific disclosed person-level concentration as of 2026-08-30. What is verifiable is organizational concentration in BlackRock, BNY Mellon, and Securitize functions, which creates operational dependency risk if any of those institutions suffer outage, policy change, or control failure.

Date
2026-08-30
Cause
Other
Evidence (1)

key management

two sources

Key-management organization — BlackRock BUIDL BUIDL uses a centralized, role-based control model, not decentralized governance. Securitize controls the privileged token-contract roles through multi-permissioned wallets operated with Fireblocks infrastructure. Publicly identified roles are:

  • MASTER: smart-contract upgrades and token-wide administration.
  • ISSUER: routine minting for new subscriptions and related issuance operations.
  • TRANSFER AGENT: operational actions such as burning, freezing, and handling impaired or lost tokens. Securitize’s DS Protocol separates these permissions through a Trust Service; roles can be assigned to multiple accounts or applications. The reference architecture also supports proxy upgrades, meaning the deployed token logic is not necessarily immutable. Fireblocks states that Securitize uses its key-management infrastructure to deploy and operate BUIDL smart contracts and to secure issuance and burn processes. However, the public disclosures do not specify the signer threshold, number or identity of signers, exact MPC/HSM configuration, geographic separation, key-rotation policy, recovery process, or whether the same signer configuration is used on every listed chain. Not verifiable as of September 4, 2026. This control layer is distinct from asset custody: BNY Mellon is identified as custodian/administrator for the fund’s traditional assets, while investors may hold BUIDL through institutional custodians or approved self-custody wallets. Investor wallets are permissioned/whitelisted, and Securitize states that impaired tokens can be burned and reissued against its off-chain security records. Risk conclusion: key risk is concentrated operational authority at Securitize—especially upgrade, mint, freeze, and burn privileges. Fireblocks and multi-permissioning reduce single-key compromise risk, but the public record does not establish the actual quorum or independence of signers. Chain-by-chain key-management equivalence is Not verifiable as of September 4, 2026.
Evidence (4)

smart-contract

two sources

As-of September 6, 2026. Dune MCP is unavailable in this run; therefore no on-chain query ID/execution ID, block-height snapshot, decoded proxy-admin events, role-membership checks, or timelock-delay measurement are available. Per policy: Not verifiable as of September 6, 2026 for current admins/owners, role renunciation, proxy-admin custody, timelocks, and cross-chain parity. Reported token addresses (not Dune-verified): Ethereum 0x7712c34205737192402172409a8f7ccef8aa2aec; Arbitrum 0xA6525Ae43eDCd03dC08E775774dCAbd3bb925872; Avalanche 0x53FC…6A2F; BSC 0x2D5BdC96D9C8AabBDB38c9A27398513e7E5ef84F; OP Mainnet 0xa1CD…57cF; Polygon 0x2893Ef551B6dD69F661Ac00F11D93E5Dc5Dc0e99; Aptos 0x50038b…45f89; Solana mint GyWgeq…btMw6phr. Ethereum also has BUIDL-I 0x6a9DA2D710BB9B700acde7Cb81F10F1fF8C89041. Architecture: DSToken-style regulated security token behind an upgradeable proxy; the reference implementation specifies an OpenZeppelin ERC-1967 proxy, and BSC/Polygon explorer records identify proxy implementations.

Roles include Owner/Master, Issuer, Transfer Agent, registry/compliance services, and proxy administrator. Issuer powers include mint/issue, burn, seize, and locking; Master can pause trading. Compliance/transfer-agent controls can restrict or freeze transfers. User → Proxy → DSToken implementation → Registry/Compliance/Transfer Agent Owner/ProxyAdmin → upgrade Exit risk: users do not have a permissionless redemption path in the token contract; exit depends on issuer/transfer-agent compliance, approved counterparties, and off-chain fund redemption.

A compromised privileged key could upgrade the implementation, mint unbacked BUIDL, burn/seize or lock balances, pause transfers, alter service addresses, or permanently freeze transfers. Direct withdrawal of underlying cash from the token contract is not established; reserves are held through the fund/custody structure. This is a high centralization/freeze/confiscation risk, not a permissionless DeFi vault.

Audits exist for Securitize DSToken and related components, but deployment-to-audited-bytecode parity and unresolved severity counts are Not verifiable as of September 6, 2026.

Admin can drain
Yes
Upgradeable
Yes
Evidence (5)

audit

one source

CoinFabrik — Securitize Smart Contract Audit

Auditor
CoinFabrik
Report date
2020-06-19
Scope
Securitize DSToken repository; commits b9e74fc and updated d412282. Modular Digital Securities Protocol components: compliance, registry, trust, token, proxy, omnibus, data stores, and services.
Findings
Critical: 0; Medium: 0. Minor: at least 1 — MultiSigWallet.getTransactionCount implementation error. Additional enhancements/observations were reported.
Fix status
Report does not provide a complete remediation-status table. Covers historical DSToken code, not demonstrated to match deployed BUIDL bytecode. Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Cyfrin — Securitize DSToken v4 Audit v2.1

Auditor
Cyfrin
Report date
2025-10-10
Scope
DSToken v4; exact scope and assessed commit are contained in the PDF.
Findings
Not verifiable as of 2026-09-05; the published PDF was located, but its detailed finding table was not machine-readable in the available fetch.
Fix status
Not verifiable as of 2026-09-05. Bytecode match to deployed BUIDL: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Cyfrin — Full Investor Locks v2.0

Auditor
Cyfrin
Report date
2026-05-29
Scope
Securitize DSToken full investor-locks functionality; exact commit and detailed scope are in the report.
Findings
Not verifiable as of 2026-09-05; detailed PDF contents were not machine-readable in the available fetch.
Fix status
Not verifiable as of 2026-09-05. Bytecode match to deployed BUIDL: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Cyfrin — Compliance Permissionless Diff v2.0

Auditor
Cyfrin
Report date
2026-06-04
Scope
Securitize DSToken compliance-permissionless code differences; exact commit and detailed scope are in the report.
Findings
Not verifiable as of 2026-09-05; detailed PDF contents were not machine-readable in the available fetch.
Fix status
Not verifiable as of 2026-09-05. Bytecode match to deployed BUIDL: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Halborn — DSToken v4 Security Assessment

Auditor
Halborn
Report date
2025-10-08
Scope
DSToken v4; assessed commit f288c35; engagement September 1–25, 2025. Core token, issuance, compliance, registry, trust, and transfer functionality.
Findings
Critical: 0; High: 0; Medium: 2; Low: 4; Informational: 7. Key issues included totalIssued handling on burns and missing wallet validation in issueTokensCustom.
Fix status
8 solved, 2 risk accepted, 3 acknowledged; Halborn states 100% of reported findings addressed. Bytecode match to deployed BUIDL implementations: Not verifiable as of 2026-09-05.
Evidence (1)

audit

two sources

Traditional financial audit of the BlackRock USD Institutional Digital Liquidity Fund Ltd (BUIDL) as a money market fund; covers portfolio, NAV, financial statements, and controls, not on‑chain code.

Auditor
PwC (PricewaterhouseCoopers LLP) – fund auditor, not smart‑contract auditor
Report date
2024-12-31
Scope
Aaa‑mf‑rated USD institutional digital liquidity fund holding short‑duration US Treasuries; PwC appointed as the fund’s auditor for period ending 31 Dec 2024.[9][14][15] No evidence this audit includes any review of deployed smart contracts or chain‑specific DeFi integrations. Bytecode‑match question is not applicable; the audit is off‑chain financial, not code‑level. Not verifiable as of 2026-08-30 whether PwC engaged a specialized firm for on‑chain security review.
Evidence (3)

audit

two sources

Ethereum BUIDL-related smart contracts (likely Securitize/PoolFactory infrastructure; not the public ERC‑20 at 0x7712c3… on Etherscan, which shows “No Contract Security Audit Submitted”).

Auditor
RD Auditors
Report date
2024-03-14
Scope
Smart Contract Code Review and Security Analysis of a BUIDL‑labelled Solidity codebase including PoolFactory.sol; focused on security vulnerabilities, not economic or governance design.[13] Bytecode‑match to the currently deployed production contracts across chains is Not verifiable as of 2026-08-30.
Evidence (2)

audit

one source

Veritas Protocol — BUIDL Proxy automated security assessment

Auditor
Veritas Protocol
Report date
2026-09-05
Scope
Ethereum BUIDL proxy at 0x7712c34205737192402172409a8f7ccef8aa2aec; automated assessment of approximately 3,450 lines of code.
Findings
Security score 70.06/100. The page exposes threat-scan categories including minting, burning, proxy upgradeability, pausing, privileged administration, whitelisting, fee updates, and owner balance changes; severity counts are not published in text.
Fix status
No remediation or retest status published. Bytecode match is not independently established; assessment is Ethereum-only and does not evidence coverage of BUIDL deployments on other chains.
Evidence (1)

Team & Reputation

founders

two sources

BlackRock BUIDL is not a founder-led retail DeFi project; it is BlackRock’s tokenized institutional money-market fund issued on Ethereum with Securitize acting as transfer agent, tokenization platform, and placement agent. The most clearly identified operating team is Securitize, whose public leadership includes co-founder/CEO Carlos Domingo and co-founder/president Jamie Finn; BlackRock also disclosed a strategic investment in Securitize and added Joseph Chalom to Securitize’s board. Founders / team: Securitize is publicly associated with Carlos Domingo and Jamie Finn, both of whom have long, visible professional histories rather than anonymous backgrounds. Jamie Finn’s prior roles include Telefónica/O2, Ericsson, Thumbplay, Kontera, AT&T, and Aki Technologies, which supports operating credibility in enterprise tech and business development.

Carlos Domingo is publicly named in Securitize and BlackRock communications as co-founder/CEO, but the available sources here do not fully document his prior projects/outcomes beyond that leadership role. Credibility / reality check: The project has strong off-chain substance: BlackRock’s own announcement, Securitize’s materials, and subsequent partner coverage show a real institutional product, not a purely web-fronted token. The presence of BlackRock, a named transfer agent, and board-level involvement materially reduce “anonymous team” risk. Office / jurisdiction: Public company listings show Securitize’s headquarters in Miami, Florida, with a Tokyo location also listed, indicating a real operating footprint rather than a shell-only presence. I could not verify the exact legal onshore/offshore entity structure from the gathered sources, so that remains Not verifiable as of 2026-09-04. Hacks / adverse history: In the sources gathered for this pass, I did not find verified evidence of founder-level hacks or major exploit outcomes tied to the core team; Not verifiable as of 2026-09-04.

Evidence (7)

general reputation

two sources

BlackRock BUIDL is a tokenized U.S. dollar institutional liquidity fund issued by BlackRock via Securitize, not a typical DeFi-native protocol. Reputation assessment focuses on BlackRock and Securitize rather than pseudonymous founders. Founders / Sponsors / Investors

  • BlackRock is the world’s largest asset manager (~$10T AUM) and has longstanding regulatory oversight in the U.S. and EU.
  • The BlackRock USD Institutional Digital Liquidity Fund (BUIDL) is issued by BlackRock and distributed/tokenized via Securitize, a regulated digital asset securities firm.
  • Securitize is registered with the U.S. SEC as a transfer agent and operates an alternative trading system through Securitize Markets, indicating higher regulatory scrutiny than typical DeFi platforms. Auditors / Attestations
  • As a BlackRock-managed fund, BUIDL sits inside BlackRock’s standard fund governance and audit framework; however, specific public smart-contract audits for the token wrappers across chains are not easily traceable to standard DeFi auditors (e.g., Certora, Trail of Bits). Not verifiable as of 2026-09-04. Sentiment & Market Position
  • Industry and media coverage is broadly positive, viewing BUIDL as a major proof point for institutional tokenization of real-world assets (RWA) and on-chain cash management.
  • BUIDL is commonly cited as a cornerstone asset in RWA narratives and is integrated on multiple chains via partners such as Coinbase and Securitize. Criticisms & Concerns
  • Main criticisms are *structural*, not fraud-related:
  • Centralization and reliance on off‑chain legal claims to fund shares, meaning on-chain holders depend on traditional custody and transfer-agency records.
  • BlackRock and Securitize maintain KYC/AML and whitelisting, which limits open DeFi composability and raises censorship/blacklisting concerns for some users.
  • Smart contract risk on the bridging/tokenization infrastructure across multiple chains; detailed independent code audits for each chain are not publicly consolidated. Not verifiable as of 2026-09-04. Fraud / Rug / Insolvency / Legal / Sanctions
  • No credible allegations of fraud, rug-pull, or insolvency involving BUIDL, BlackRock, or Securitize’s handling of this product as of 2026-09-04.
  • BlackRock and Securitize are subject to extensive U.S. regulatory oversight; no protocol-specific enforcement actions or sanctions against BUIDL were identified as of 2026-09-04. Unresolved Risk Points for Institutional DeFi
  • Dependence on off‑chain fund records vs. on-chain state.
  • Limited transparency on per-chain smart contract audits and incident response.
  • Counterparty/regulatory risk concentrated in BlackRock and Securitize.
Evidence (6)

Economy

TVL: $3.5B

model

one source

Economic model (as of September 6, 2026): BUIDL is a permissioned, tokenized institutional money-market fund—not a leveraged DeFi strategy. It invests 100% of assets in cash, U.S. Treasury bills and repurchase agreements; yield is therefore organic interest income tied mainly to short-term U.S. rates, not token emissions or liquidity mining.

Dividends accrue daily and are distributed monthly as additional tokens while targeting a $1 NAV. Risk/positioning: Directional to short-term rates and Treasury/repo credit, with no verified evidence of looping, leverage, restaking, yield farming, or external protocol exposure. Because Dune MCP is unavailable, leverage and collateral composition cannot be independently verified on-chain: Not verifiable as of September 6, 2026. No lock-up was identified, but access is restricted to eligible, pre-approved investors; transfers are permitted 24/7/365 only between approved wallets. Primary subscriptions/redemptions and transfer permissions are handled through Securitize. Fees, gates and revenue: DeFiLlama reports management fees of approximately 18–50 bps depending on share class/chain and treats underlying-asset yield plus management fees as gross fees; its current estimate is $509,192 protocol revenue over the last 30 days.

These are aggregator estimates, not audited cash-flow data. TVL / chain exposure: DeFiLlama’s asset page reports $2.778B on-chain market cap: Ethereum $938.63M (33.8%), Solana $937.90M (33.8%), Avalanche $564.23M (20.3%), Aptos $161.34M (5.8%), BSC $136.26M (4.9%), OP Mainnet $26.41M (1.0%), Arbitrum $8.56M (0.3%), and Polygon $4.89M (0.2%). Native yield is shown as 3.57%. Contradiction: DeFiLlama’s protocol page separately reports $3.621B TVL, versus $2.778B on its BUIDL asset page; methodology/snapshot differences are unresolved. Dune total TVL, product-level TVL, chain trend, and Dune-vs-DeFiLlama reconciliation: Not verifiable as of September 6, 2026. APY history is not fully available from the retrieved sources; current reported yield is approximately 3.4–3.57%, with sustainability dependent on short-term rates and fee drag.

Subsidized-vs-organic yield split is Not verifiable as of September 6, 2026.

Evidence (3)

reserves

two sources

Assessment (as of September 6, 2026): BUIDL is a tokenized investment fund, not a conventional DeFi treasury. Its economic reserves are primarily off-chain and held through fund custody arrangements.

  • Size / exposure: DeFiLlama reports $3.621bn TVL, up from the previously recorded $3.562bn. This is an analytics estimate of token balances, not proof of fund NAV or reserves. Chain distribution: Solana $977.9m (27.0%), Aptos $967.1m (26.7%), Ethereum $935.6m (25.8%), Avalanche $564.2m (15.6%), BSC $136.3m (3.8%), OP Mainnet $26.4m (0.7%), Arbitrum $8.6m (0.2%), Polygon $4.9m (0.1%).
  • Composition / reserve policy: BUIDL states that 100% of assets are invested in cash, short-term U.S. Treasury bills and repurchase agreements secured by those assets. Tokens represent fund interests, not direct ownership of specific securities. Exact current percentages, maturities and counterparties are Not verifiable as of September 6, 2026.
  • Custody / control: BNY Mellon is identified as BUIDL’s cash and securities custodian and administrator; BlackRock manages the portfolio. Securitize acts as transfer agent, tokenization platform and placement agent. Investors may use digital-asset custodians including Anchorage, BitGo, Copper, Coinbase Custody and Fireblocks. Transfers and redemptions are subject to eligibility, whitelist and onboarding controls.
  • Addresses / on-chain balances: Specific reserve-wallet addresses and underlying securities balances are not publicly established by the reviewed sources. Dune MCP was unavailable for this run; therefore on-chain balances, wallet composition, liabilities and reserve coverage are Not verifiable as of September 6, 2026. Token contract addresses are not equivalent to reserve addresses.
  • Attestations: A current independent public reserve attestation for BUIDL itself was not located. NAV/holdings disclosure to investors may exist, but a public attestation is Not verifiable as of September 6, 2026. Contradiction / risk finding: DeFiLlama’s $3.621bn TVL should not be treated as verified reserves; the fund’s assets are predominantly off-chain and the difference between token TVL and independently evidenced NAV is unresolved. Structured fields: liquid_reserves_usd: null; liabilities_usd: null
Evidence (4)

tokenomics

two sources

As of September 4, 2026. BUIDL has no native DeFi/governance token. “BUIDL” is the ticker for tokenized Class A shares of BlackRock USD Institutional Digital Liquidity Fund—not an emissions-based protocol asset. Contracts / supply. Reported deployments are: Ethereum 0x7712c34205737192402172409a8f7ccef8aa2aec; Arbitrum 0xa6525ae43edcd03dc08e775774dcabd3bb925872; OP Mainnet 0xa1CDAb15bBA75a80dF4089CaFbA013e376957cF5; Polygon 0x2893Ef551B6dD69F661Ac00F11D93E5Dc5Dc0e99; Aptos 0x50038be55be5b964cfa32cf128b5cf05f123959f286b4cc02b86cafd48945f89; Solana mint GyWgeqpy5GueU2YbkE8xqUeVEokCMMCEeUrfbtMw6phr; Avalanche 0x53fc…6a2f; BSC 0x2d5b…f84f. Full Avalanche/BSC addresses: Not verifiable as of September 4, 2026. DeFiLlama reports approximately $2.76bn supply/TVL at a $1 NAV; third-party market data reports total and circulating supply as equal, implying roughly $2.76bn market cap and FDV.

These are aggregator figures, not on-chain-verified; exact consolidated supply is Not verifiable as of September 4, 2026. Utility / economics. Each token represents a fund share backed by cash, U.S. Treasury bills and repo.

Holders receive daily income/dividends, normally reflected through additional tokens or distributions; there is no staking, buyback, burn-to-value, or protocol revenue-share mechanism. The shares are generally non-voting and do not confer governance over Securitize or BlackRock. Supply, allocations and unlocks. Supply is elastic through subscriptions/redemptions, not a fixed emission schedule.

No team/investor/treasury/community allocation or vesting schedule is applicable to fund shares; announced unlocks are Not verifiable as of September 4, 2026. Controls / concentration / liquidity. Contracts support minting, burning, allowlisting/blacklisting, transfer restrictions, pause/clawback and upgrades; issuer/transfer-agent control is centralized, but the exact controlling wallets are Not verifiable as of September 4, 2026. Top-holder concentration by chain and insider attribution are Not verifiable as of September 4, 2026. Public DEX liquidity is negligible relative to NAV (DeFiLlama shows about $24.6k on a Uniswap V2 pool); primary liquidity is issuer redemption and permissioned wallet-to-wallet transfers, not exchange order books.

Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A collapse in bitcoin below $10,000 is largely *indirect* risk for BlackRock BUIDL, which is a tokenized U.S. dollar money-market fund backed by Treasuries and cash, but it can create *pathways* to stress via collateral use, liquidity, and counterparty risk across DeFi. 1. Core product risk (NAV, peg, underlying assets)

  • BUIDL invests in cash, U.S. Treasury bills, and repo to maintain a stable $1 per token value; its economics are those of a dollar money-market fund, not a crypto-asset.
  • A bitcoin crash does not directly impair the underlying portfolio, unless it triggers broader systemic stress in traditional markets (e.g., forced selling of Treasuries or funding stress), which is second-order.
  • For pure exposure to BUIDL’s underlying assets (off-exchange holdings, primary fund shares), risk from BTC < $10k is therefore *limited and mainly macro* (rates, government credit, liquidity in Treasuries). 2. DeFi / collateral usage channels BUIDL is now integrated into multiple DeFi rails (UniswapX, Binance off-exchange collateral, BNB Chain, multi-chain share classes). Key stress channels if BTC collapses:
  • Collateral rehypothecation risk: BUIDL used as collateral on exchanges or in DeFi could face:
  • Margin calls on positions paired with BTC (e.g., BUIDL/BTC traders), leading to forced liquidation of BUIDL positions.
  • Operational or legal risk if an exchange becomes distressed while holding BUIDL as collateral.
  • Liquidity and secondary market spreads:
  • On UniswapX and other liquidity venues, a BTC crash tends to widen spreads, reduce RFQ depth, and increase slippage, even for “stable” RWAs.
  • BUIDL secondary trading may remain functional but on-chain liquidity could thin out, increasing execution risk for large redemptions or exits.
  • Cross-chain and bridge risk:
  • Expansion to Aptos, Arbitrum, Avalanche, OP Mainnet, Polygon, Solana and BNB Chain depends on cross-chain infrastructure (e.g., Wormhole for BNB).
  • Systemic crypto stress historically increases bridge exploit and de-peg risk; failure or compromise of bridging infrastructure could strand BUIDL share classes or create price dislocations between chains. 3. Counterparty and operational risk
  • Securitize operates as regulated broker-dealer / transfer agent; redemptions and subscriptions remain off-chain and subject to traditional-market plumbing.
  • Extreme crypto stress could still affect:
  • Custody chain (e.g., if stablecoin or USDC rails used to subscribe see disruptions).
  • Regulatory or bank counterparties if they restrict crypto-related flows during a market crisis. 4. Institutional risk posture (for your desk)
  • Treat BUIDL as money-market fund exposure with crypto integration, not as a stablecoin; NAV stability risk is more tied to U.S. government & rates than BTC.
  • In a BTC < $10k scenario, your focus should be:
  • Mapping where BUIDL is pledged as collateral (CEXs, DeFi lending, RFQ venues) and tracing rehypothecation chains.
  • Monitoring cross-chain liquidity and any chain-specific technical or governance incidents.
  • Stress-testing redemption timing, settlement, and FX/stablecoin rails used to enter/exit BUIDL. On-chain verification of actual TVL per chain and specific collateral exposures: Not verifiable as of 2026-09-04.
Evidence (15)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of BUIDL’s collateral (short‑term U.S. Treasuries, cash and repos) is an extreme tail event that would effectively be a 20% NAV shock to what is designed to be a stable, fully collateralized money‑market‑style fund. Under current structures, BUIDL shares target a constant $1.00 NAV, fully backed by these assets. ### 1. Nature of the stress

  • BUIDL represents fractional ownership of a regulated, tokenized money market fund holding short‑duration U.S. government securities and cash equivalents.
  • A 20% collateral devaluation implies NAV ≈ $0.80 per BUIDL until BlackRock can realize recoveries or adjust the portfolio.
  • Because tokens are claims on the off‑chain fund, the economic loss sits in the fund, not in the tokenization wrapper (Securitize) itself. ### 2. Direct protocol impact
  • Token holders: Qualified investors and institutional DeFi users holding BUIDL suffer mark‑to‑market losses on all chains (Aptos, Arbitrum, Avalanche, Ethereum, Optimism, Polygon, Solana, BSC via BNB Chain integrations).
  • Yield protocols / venues:
  • Off‑exchange collateral arrangements (e.g., Binance collateral use) face immediate margin re‑assessment; positions may be forcibly reduced or liquidated.
  • RFQ/UniswapX trading venues that use BUIDL for liquidity see spreads widen, volumes drop, and may restrict quotes as NAV uncertainty rises.
  • Stablecoin‑like usage: Any DeFi strategy treating BUIDL as a near‑risk‑free stable asset experiences:
  • Under‑collateralization of loans against BUIDL.
  • Liquidation cascades where LTV was calibrated assuming near‑zero volatility. ### 3. Cross‑chain and Wormhole bridge risk
  • BUIDL is live on seven+ chains with cross‑chain transfers via Wormhole.
  • A uniform 20% NAV drop applies to every representation of BUIDL; however:
  • Chains with thinner BUIDL liquidity (smaller pools, fewer RFQ counterparts) will see larger price dislocations and slippage.
  • Bridge design assumes fungibility at par; a persistent 0.80 price versus assumed 1.00 can create accounting and oracle mismatches in integrated DeFi protocols. ### 4. Systemic / behavioral effects
  • Confidence shock: A regulated, BlackRock‑backed product depegging 20% would challenge the core narrative that tokenized Treasuries are *near‑cash*.
  • Flight to safety: Institutions may rotate out of BUIDL and similar RWA tokens into conventional Treasuries or on‑chain assets with simpler risk profiles.
  • Regulatory follow‑through: Given SEC‑registered status and institutional investor base, supervisory scrutiny and potential changes to risk, disclosure, and liquidity management frameworks are likely. ### 5. Data caveat
  • On‑chain positions, protocol‑level exposures, and TVL by chain for BUIDL are Not verifiable as of 2026‑09‑04 without direct on‑chain queries and protocol‑specific position data; impact must therefore be assessed qualitatively based on public descriptions of BUIDL’s use in DeFi.
Evidence (15)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

BlackRock BUIDL is a tokenized U.S. Treasury fund issued via Securitize on Ethereum (and wrapped to other chains), where the main economic counterparty is the fund / custodian / issuer complex, not DeFi borrowers. Because Dune/on‑chain queries are unavailable in this run, all on‑chain metrics are: Not verifiable as of 2026‑09‑04. ### 1.

Identify “top counterparty” for stress For BUIDL the critical counterparties are:

  • Issuer / fund manager: BlackRock.
  • Transfer agent / tokenization platform: Securitize.
  • Custodian / bank holding Treasuries and cash for the fund (typically a major U.S. custodian; exact entity not verifiable here). On typical DeFi integrations (Aave, Morpho, etc.), BUIDL is treated as collateral or a yield-bearing asset; DeFi protocols themselves are *secondary* counterparties. ### 2. Stress: issuer–custodian complex insolvent Assume a failure where the custodian or BlackRock vehicle holding the underlying Treasuries becomes insolvent or assets are frozen. Loss path
  • Underlying Treasuries/cash backing BUIDL are impaired or inaccessible.
  • Net asset value (NAV) of the off‑chain fund falls; redemption in USD is halted or deeply haircut.
  • On-chain BUIDL tokens continue to exist but become partially or fully unbacked – a “wrapped claim” with broken linkage. Who absorbs losses
  • Token holders (wallets, CeFi exchanges, DeFi protocols holding BUIDL as collateral) bear economic loss: BUIDL market price de-pegs from 1 USD and can gap toward recovery value (if any).
  • BlackRock/Securitize equity holders may suffer via legal claims, but that is off‑chain; smart contracts do not socialize losses. Compensation
  • Any compensation would be via off‑chain legal/regulatory processes (insurer, SIPC‑like schemes if applicable, court‑ordered recoveries). Not encoded on-chain; therefore DeFi users are unsecured claimants. ### 3. Impact path via smart contracts
  • Core BUIDL ERC‑20 / token contracts:
  • Continue to function; no automatic write‑down logic. Smart contracts cannot detect custodian insolvency. Not verifiable as of 2026‑09‑04.
  • Bridged / wrapped forms on other chains (Arbitrum, Solana, etc.):
  • Bridges maintain 1:1 representation versus Ethereum BUIDL. If Ethereum BUIDL is unbacked, bridged tokens inherit the same economic impairment.
  • DeFi lending / collateral protocols:
  • Oracles typically continue to report near‑par price until secondary markets reprice; once price collapses, positions using BUIDL as collateral are liquidated, spreading losses to liquidators and LPs.
  • AMMs/LPs:
  • Pools holding BUIDL auto-rebalance; LPs end up overexposed to the de‑pegged asset and realize losses. No protocol-level guarantee or automatic compensation mechanism for BUIDL holders could be identified in public docs; any safety net is purely regulatory / legal, not smart-contract based.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

one source

In a committed fraud by DAO/owners scenario for BlackRock BUIDL, the dominant risk is loss of trust, potential asset misappropriation at the tokenization/issuer layer, and rapid unwind of secondary-market liquidity across all chains. 1. Governance / ownership structure (fraud vector)

  • BUIDL is a tokenized U.S. dollar institutional liquidity fund issued by BlackRock, with tokenization and distribution handled by Securitize.
  • Governance is centralized, not a typical DAO: BlackRock controls the fund; Securitize controls tokenization, compliance, and onchain representations.
  • Smart contracts appear to be permissioned and operated by Securitize/BlackRock (whitelists, KYC, transfer restrictions). *Implication:* A “fraud by DAO” stress must be reframed as fraud by issuer (BlackRock) or tokenization platform (Securitize)—e.g., misreporting NAV, misusing underlying assets, or issuing tokens not backed 1:1 by fund shares. 2. On-chain vs off-chain exposure
  • Underlying assets are off-chain money market / short-term U.S. Treasuries, custodied in traditional finance infrastructure.
  • On-chain positions on Aptos, Arbitrum, Avalanche, BSC, Ethereum, OP, Polygon, Solana are merely claims on the off-chain fund, not bearer assets. *Fraud scenario:* If issuer or Securitize misrepresents backing or diverts assets, on-chain holders become unsecured or subordinated claimants in legal resolution. On-chain TVL metrics from aggregators cannot prove backing; they only show token balances—"Not verifiable as of [date]" for true asset coverage. 3. Impact pathways
  • NAV / price gap: Tokens may continue to trade at par on-chain until fraud is revealed; then rapid depeg versus expected $1, with liquidity collapse on all supported chains.
  • Redemption freeze: Issuer can halt redemptions or transfers through centralized controls; holders face gating and legal recourse instead of smart-contract-based recovery.
  • Cross-chain contagion: Protocols using BUIDL as collateral (lending, structured products, RWAs) would mark down positions, triggering liquidations and possible insolvency for leveraged users. 4. Legal / regulatory overlay
  • As a BlackRock product tokenized by Securitize, BUIDL is embedded in U.S. securities regulation (SEC, broker-dealer/ATS rules).
  • Fraud would likely be pursued via regulatory enforcement and civil litigation; on-chain holders rely on off-chain legal outcomes rather than any autonomous recovery mechanism. Risk analyst takeaway: For institutional DeFi users, the key risk is issuer / platform integrity and regulatory oversight, not smart-contract DAO governance. Exposure sizing must treat BUIDL as counterparty risk to BlackRock/Securitize plus legal-claims risk on the fund, with conservative assumptions for recovery in a fraud scenario.
Evidence (2)

stress scenario - primary yield source negative 30d,

two sources

If BUIDL’s primary yield source (short‑term U.S. Treasuries, repos and cash) turns negative over a 30‑day window, the token should still hold ~$1 NAV, but your *income stream collapses or in extremis flips to net costs*, shifting risk from rate to liquidity, counterparty and structural risks. ### What “negative 30‑day yield” means for BUIDL

  • BUIDL invests 100% in cash, U.S. Treasury bills, and repurchase agreements, benchmarked to secured overnight financing and short‑term USD rates.
  • Yield today is around low‑to‑mid single digits annualized, paid as extra BUIDL tokens monthly while targeting stable $1 per token.
  • A negative 30‑day yield scenario = after fees, the fund’s *net* income on T‑bills, repo and cash over that month is ≤0. Operational consequences for a DeFi integration:
  • No monthly rebase / distribution: If net yield ≈0 or <0, Securitize/BlackRock would logically not mint new BUIDL as dividends; you hold the same token count and value stays near $1 absent credit or liquidity stress. This is an inference; exact policy is Not verifiable as of 2026‑09‑04.
  • Protocol‑level yield goes to zero: Any DeFi protocol using BUIDL as its primary yield leg (e.g., vaults that pass through BUIDL’s rate) will see headline APY collapse to 0% or slightly negative over that 30‑day window.
  • Fee drag becomes visible: Management/operational fees that were previously absorbed by positive rates become explicit drag; net return to holders may be slightly negative. Risk re‑assessment for an institutional DeFi user:
  • Interest‑rate risk realization: BUIDL is economically a tokenized money market fund; negative short‑term USD rates or a spike in fees vs. gross yield would directly hit distributions.
  • Liquidity risk: In stress, large redemptions from institutional holders across chains (ETH, BNB, etc.) could force rapid unwinding of T‑bills and repo; on‑chain liquidity pools using BUIDL may see slippage and wider spreads. Specific chain‑level TVL shares are Not verifiable as of 2026‑09‑04.
  • Collateral and rehypothecation risk: Where BUIDL is used as collateral (e.g., CEX margin, DeFi lending), negative yield reduces its attractiveness, potentially tightening collateral haircuts or triggering position re‑pricing. From a pure DeFi risk‑management perspective, the key stress outcome is yield compression to ~0% with preserved principal, plus secondary effects: liquidity stress, fee drag, and tighter collateral terms on all chains where BUIDL is integrated, without direct protection from protocol‑level mechanisms beyond normal money‑market fund safeguards.
Evidence (15)

Governance & Legal

governance

two sources

As of September 13, 2026, BUIDL is centrally controlled by the issuer and service providers, not by a DAO. BlackRock USD Institutional Digital Liquidity Fund Ltd. is a British Virgin Islands limited company formed in 2023 (SEC CIK 0002013810); disclosed directors are Ian Pilgrim, W. William Woods, Noelle L’Heureux and Jennifer Collins.

The BVI corporate registration number is Not verifiable as of September 13, 2026. BlackRock Financial Management, Inc. is investment manager; BNY Mellon is custodian and administrator; Securitize LLC, a Delaware LLC, provides the platform, transfer-agent, registrar and dividend-disbursing functions. Control map: the issuer gives written instructions for issuance and can instruct Securitize regarding transfers; Securitize maintains the register and may process transfers/redemptions under the offering memorandum.

The underlying assets are held in fund accounts with BNY Mellon, subject to the fund board’s supervision. There is no identified public proposal, token-holder voting, DAO constitution, or governance forum controlling upgrades, parameters, issuer instructions, or fund assets. DAO governance is therefore false; any apparent on-chain token ownership is economic exposure, not protocol governance.

Proposal process is corporate/legal—issuer, investment manager, board, custodian and contractual service providers—not community voting. Dune was unavailable in this run. Voting concentration, top holders, contract-admin ownership, proxy/admin history, multisig signers, signer independence, timelock delay, and chain-by-chain exposure are Not verifiable as of September 13, 2026.

No public evidence reviewed establishes a timelock or multisig governance layer. Technical ability of an admin key or contract role to drain or forcibly move user funds is Not verifiable as of September 13, 2026; corporate redemption/transfer authority exists without a DAO vote, but that is not equivalent to verified smart-contract drain capability. BUIDL-specific Terms of Service, company registration number, and directors of Securitize LLC are Not verifiable as of September 13, 2026.

BlackRock’s general website terms use New York law and New York courts, but are not confirmed as BUIDL-specific.

Dao governance
No
Evidence (4)

legal & regulatory

two sources

As of September 4, 2026 Legal structure / entity. BUIDL is not a permissionless DeFi protocol; it is a tokenized private fund. The issuer is BlackRock USD Institutional Digital Liquidity Fund Ltd., incorporated in the British Virgin Islands (BVI) in 2023. BlackRock Financial Management, Inc. is investment manager; Securitize LLC provides platform/transfer-agent services, while Securitize Markets, LLC acts as placement agent.

Classification and restrictions. The issuer filed SEC Form D under Investment Company Act §3(c)(7), and states it is not a registered investment company. This is an exempt/private securities offering, not a retail money-market fund or deposit. Access is limited to eligible institutional/qualified investors; transfers are permissioned and subject to onboarding, contractual restrictions, and applicable securities laws.

The SEC filing expressly warns that the SEC has not reviewed or validated the Form D. KYC/AML and data protection. Securitize publishes AML/CIP disclosures and its regulated broker-dealer materials describe customer onboarding and securities-market compliance. Expect identity, beneficial-owner, sanctions, jurisdiction, accreditation/qualified-purchaser and source-of-funds checks.

Personal and institutional data is therefore concentrated with Securitize and related service providers; the precise BUIDL-specific retention, cross-border transfer, breach-notification and deletion terms were Not verifiable as of September 4, 2026 from the accessible public materials. Warnings/enforcement. No active regulator action against BUIDL or its BVI issuer was identified. BlackRock Advisors did receive an SEC 2023 cease-and-desist/order concerning inaccurate disclosures for a different fund and obtained a waiver; this is sponsor-level historical risk, not a BUIDL enforcement action.

Securitize entities also appear in 2026 Delaware commercial/IP litigation, apparently unrelated to BUIDL. Actual risk. The BVI fund wrapper and regulated U.S. intermediaries reduce—but do not eliminate—issuer, manager, custodian, redemption, sanctions-screening, smart-contract, chain-outage, cross-border insolvency and investor-rights risks. Multichain deployment does not make the underlying shares fungible or unrestricted. Structured fields:

  • active_enforcement: false
  • sanctioned: false (no official entity-level designation identified; address-level screening remains necessary)
  • entity: BlackRock USD Institutional Digital Liquidity Fund Ltd.; manager: BlackRock Financial Management, Inc.; placement/platform providers: Securitize Markets, LLC and Securitize LLC
  • jurisdiction: British Virgin Islands (issuer); United States—Delaware/New York entities (service providers)
Active enforcement
No
Sanctioned
No
Entity
BlackRock USD Institutional Digital Liquidity Fund Ltd. (issuer); BlackRock Financial Management, Inc. (manager); Securitize LLC and Securitize Markets, LLC (service/placement entities)
Jurisdiction
British Virgin Islands for the issuer; United States (Delaware/New York) for principal service providers
Evidence (5)

legal registries

two sources

Legal entity per GLEIF: BLACKROCK FINANCIAL MANAGEMENT INC. (LEI 549300LVXYIVJKE13M84; jurisdiction US-DE; registration ACTIVE). OFAC SDN screening of 'BlackRock Financial Management Inc', 'Securitize LLC', 'Securitize Markets LLC', 'BlackRock BUIDL': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • BlackRock Financial Management Inc
  • Securitize LLC
  • Securitize Markets LLC
  • BlackRock BUIDL
Entity
BLACKROCK FINANCIAL MANAGEMENT INC.
LEI
549300LVXYIVJKE13M84
Jurisdiction
US-DE
Entity status
ACTIVE
Sanctioned
No
Evidence (4)

Stability

stability

two sources

BlackRock BUIDL is not an issued retail fiat stablecoin; it is a tokenized institutional money-market fund share that targets a stable $1 NAV, so own_stablecoin is false. In the retrieved independent sources, no verified historical depeg event for BUIDL was found; the latest market pages still show it at or near $1.00. However, because on-chain verification is unavailable in this run and the sources reviewed do not establish a complete historical price record, depeg_count, last_depeg_date, and max_depeg_pct are not verifiable as of 2026-09-06. stable is set to true based on the fund’s stated stable-NAV design and the absence of any verified depeg in the retrieved sources.

Own stablecoin
No
Stable
Yes
Evidence (5)

Risks & Strengths

risks

two sources

BUIDL is a permissioned tokenized fund, not a decentralized yield protocol: investor access, transfers, redemptions, and token administration depend on BlackRock, Securitize, custodians, and approved counterparties. The principal risks are centralized control, legal/eligibility constraints, liquidity mismatch, operational/security failure, and underlying cash-equivalent asset risk. Current on-chain TVL, chain-by-chain exposure, and cross-chain concentration are Not verifiable as of September 5, 2026 because Dune access is unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Centralized administrative controlSecuritize-controlled roles reportedly include upgrades, issuance, burns, freezes, and transfer-agent functions. Key compromise, insider abuse, or unilateral intervention could block transfers or impair token integrity.HighMediumPermissioned transfers, identity controls, multipermissioned Fireblocks wallets, and reported independent reviews.High: governance and operational trust remain concentrated.
Regulatory and eligibility constraintsThe fund is BVI-domiciled and relies on a Section 3(c)(7) structure; access is restricted to eligible investors and transfers require compliance controls. Regulatory changes or sanctions decisions could force exclusions or redemptions.HighMediumKYC/AML, sanctions screening, whitelisting, transfer-agent oversight, and contractual compliance obligations.Medium-High: legal enforceability varies by jurisdiction.
Liquidity and redemption mismatchA $1 NAV and redemption process do not guarantee continuous secondary-market liquidity; access depends on approved investors, transfer controls, and off-chain settlement. The UniswapX route is explicitly structured around whitelisted participants.HighMediumUnderlying cash, Treasury bills, and repos; formal redemption at stated NAV; additional approved liquidity venues.Medium: stress-period liquidity remains unproven.
Smart-contract and operations failureToken contracts, identity services, custody, transfer-agent systems, and multiple chain deployments create correlated failure points. An exploit, bad upgrade, outage, or integration error could suspend or misdirect transfers.HighMediumReported audits, permissioned architecture, operational controls, and restricted composability.Medium-High: complete audit scope, findings, and current deployment coverage are Not verifiable as of September 5, 2026.
Underlying asset and counterparty riskBUIDL depends on cash, short-term U.S. Treasuries, and repurchase agreements; losses can still arise from issuer, repo-counterparty, custodian, settlement, interest-rate, or valuation events. The investment is not a bank deposit or guaranteed principal.MediumLowShort maturities, high-quality government collateral, custody arrangements, and diversified counterparties are intended to limit loss and liquidity risk.Medium: residual tail risk remains during market or counterparty stress.
Evidence (5)

strengths

two sources

Top 5 strengths of BlackRock BUIDL are: 1) Institutional credibility: it is BlackRock’s tokenized fund, distributed through Securitize, which adds strong brand trust and a regulated issuance stack. 2) Regulated structure: it operates within a compliance-focused framework with whitelisted/permissioned access, which is important for institutional users. 3) Multi-chain reach: it is available across multiple networks, improving accessibility and integration options.

4) On-chain liquidity and settlement: it offers near-instant, 24/7 USDC redemption and faster transfer/settlement than traditional fund rails. 5) Composable treasury asset: it is useful as a tokenized short-duration Treasury product that can serve as collateral and a building block for DeFi/RWA strategies.

Evidence (4)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 22 two independent sources, 13 one source.
  • Oldest fact verification date: 2026-08-30.