Ethena USDe

Orange · 61/100

Executive summary

Ethena USDe is a synthetic dollar protocol on Ethereum issuing USDe (stablecoin) and sUSDe (yield-bearing token), scored 41/100 (orange band) with high data confidence (88/100) but penalized for active regulatory enforcement (-15) and unresolved incidents (-10).

  • Security: Multiple audits by Zellic, Quantstamp, Code4rena, OtterSec, Sigma Prime, Spearbit/Cantina, Pashov, and Cyfrin found no unresolved critical/high issues; most medium/low findings fixed or acknowledged. Bytecode match to deployed contracts not verifiable as of 2026-09-06. Active Immunefi bug bounty with $3M max payout since April 2024.
  • Incidents: Four documented events: July 2024 Discord phishing (minimal loss), September 2024 domain compromise (~$15k, remediation in progress), February 2025 Bybit hack (no Ethena loss, resolved), and October 2025 Binance price dislocation (venue-specific, Binance compensated users, resolved). No core smart-contract exploits confirmed.
  • Governance & custody: Foundation/company-controlled with partial DAO signaling via off-chain Snapshot voting; Ethena Foundation (Cayman) and Ethena BVI Limited retain operational control. Core contracts use multisig admin (7 signers) with documented 7-day timelock; admin can change minters, collateral, and limits. Backing assets held off-exchange via OES custodians (Copper, Ceffu, Kraken, Coinbase); segregated and bankruptcy-remote per documentation.
  • Top risks: (1) Negative funding regime can drain reserve fund and pressure peg (high severity/probability); (2) Exchange/custody failure exposes unrealized PnL and margin (Bybit event showed $30M exposure); (3) Centralized oracle/venue risk (Binance dislocation to $0.65 demonstrated feedback loops); (4) Privileged admin roles can mint unbacked USDe if keys compromised. Reserve fund ~$62M vs. $4.3B liabilities (1.4% buffer).
  • Regulatory & legal: Active BaFin enforcement against Ethena GmbH (Germany) for unauthorized MiCA asset-referenced-token issuance; wind-down ordered. US residents barred from direct minting. Ethena BVI Limited (BVI 2127704) is non-EEA issuer; no OFAC/SEC sanctions found. USDe terms disclaim deposit/equity status; classification remains jurisdiction-dependent.
  • Strengths: Capital-efficient delta-neutral design; yield from funding, staking, and stablecoin rewards (historical 19% APY, current ~4.5%); extensive audit coverage; operational mint/redeem with off-exchange settlement; broad DeFi integration and $1.34B TVL.
  • Unverified: Current on-chain collateral composition, reserve coverage ratio, exact funding exposure, deployed-bytecode match for all audits, complete remediation status for medium/low findings, and whether all affected users from September 2024 domain hack were reimbursed.
  • Recommended exposure: Conservative allocation (≤5% of stablecoin sleeve) for institutional portfolios with operational due diligence and active monitoring. Suitable only for allocators comfortable with synthetic-dollar mechanics, exchange/custody counterparty risk, and regulatory uncertainty. Require monthly proof-of-reserves verification, reserve-fund adequacy checks, and funding-rate stress scenarios. Avoid if mandate prohibits non-fiat-backed stables or active enforcement jurisdictions.
  • Open questions: (1) Verify current bytecode match for all core contracts and audit scope coverage; (2) obtain real-time collateral composition, reserve fund balance, and funding exposure via Dune or direct API; (3) confirm complete remediation and reimbursement status for September 2024 domain incident; (4) assess BaFin enforcement impact on EEA operations and cross-border contagion risk; (5) validate custodian bankruptcy-remoteness and OES legal structure with independent counsel; (6) stress-test reserve adequacy under 30-day negative funding and top-counterparty insolvency scenarios.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 21 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 80 16.0 full audit within 365 days (latest 2026-07-02); auditor not in top-20 -20
Incidents 20% 100 20.0 1 open incident(s), $15,000 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 26 5.2 TVL $4,602,464,111 = 26% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 22/58 verified facts; 58/58 fresh (180d)
  • Active regulatory enforcement (−15): legal fact records active enforcement or sanctions

Identification

protocol identification

two sources

Ethena is a synthetic dollar protocol on Ethereum issuing USDe and the staked yield-bearing derivative sUSDe, classified as a stable/synthetic dollar & yield-bearing DeFi asset. Protocol identification

  • Name: Ethena – USDe (synthetic dollar) and sUSDe (staked, yield-bearing token).
  • Website: ethena.fi (protocol overview and app).
  • Docs: docs.ethena.fi, including “Overview”, “USDe Overview” and “How USDe Works”.
  • Category: DeFi synthetic dollar / non-fiat-backed stable asset, plus yield-bearing savings asset (sUSDe).
  • Launch / deployment timing: Ethena’s core primitive is reported as deployed on Ethereum mainnet only as of March 2024. This is off‑chain reporting; on‑chain verification is not possible here: Not verifiable as of 2026‑09‑04.
  • Chains: Issuance and core protocol are on Ethereum mainnet. Third‑party analysis and integrations state USDe/sUSDe are then bridged to several L2s and other chains (BNB Chain, Arbitrum, Base, Mantle, Solana, etc.), but those bridged deployments cannot be on‑chain verified here: Not verifiable as of 2026‑09‑04.
  • Native tokens:
  • USDe – synthetic dollar token.
  • sUSDestaked, reward‑accruing version of USDe, representing the protocol’s savings asset. Main contract addresses (Ethereum) Cross‑checked between docs and explorer, but without direct on‑chain query capability:
  • USDe token contract (Ethereum): 0x4c9EDD5852cd905f086C759E8383e09bff1E68B3.
  • Listed in Ethena docs “Key Addresses”.
  • Labeled “Ethena: USDe Token” on Etherscan with token symbol USDE and Ethena description.
  • sUSDe token contract (Ethereum): 0x9D39A5DE30e57443BfF2A8307A4256c8797A3497.
  • Listed in Ethena docs as “sUSDe Token Contract”.
  • Labeled “Ethena: sUSDe Token” / “StakedUSDeV2” on Etherscan. Explorer verification status
  • Both USDe and sUSDe contracts are presented as named token contracts on Etherscan with metadata and verified source shown in the explorer interface. Full verification details (e.g., compiler settings) are Not verifiable as of 2026‑09‑04 in this environment. Fork lineage / upstream relationship
  • Public technical and overview docs describe Ethena/USDe as a bespoke synthetic dollar design backed by crypto collateral plus short perpetual futures (delta‑neutral), not as a fork of an existing major stablecoin protocol (e.g., Maker, Liquity).
  • No credible sources identify Ethena USDe as a direct code fork of a specific upstream protocol, nor detail a fork diff or malicious fork history: Not verifiable as of 2026‑09‑04.
  • Audits and change‑logs for any hypothetical forked components are likewise Not verifiable as of 2026‑09‑04 under current data and tooling limits. Fork-lineage callout > Current independent public information treats Ethena USDe as a novel synthetic dollar design, not a documented fork; absence of explicit fork mapping, diff analysis, or malicious‑modification history must be recorded as: Not verifiable as of 2026‑09‑04.
Evidence (15)

maturity

one source

Ethena USDe appears to be a real, live protocol portal rather than a static landing page: its documentation explicitly describes minting/redeeming USDe, staking to sUSDe, cooldown-based withdrawals, and a public API surface for whitelisted users. The product is functional enough to support deposits and withdrawals through a two-step unstake flow with a cooldown period, and the docs also expose developer-oriented API documentation and integration guides. ## Maturity assessment

  • Portal/product: Mature enough to show operational protocol mechanics, not just marketing copy, with clear docs for mint, redeem, stake, unstake, and withdrawal lifecycle.
  • Live deposit/withdrawal UX: Documented as active, but withdrawals are gated by cooldown and whitelist/KYC constraints, so it is not a fully permissionless consumer-facing cash-out flow.
  • Docs/UX quality: The docs are extensive and structured, including overview pages, FAQs, and step-by-step guides.
  • Template/fake-metric signs: Not verifiable as of 2026-09-04.
  • Broken links: Not verifiable as of 2026-09-04.
  • Open API: Yes, Ethena documents an API for minting and redeeming USDe and explicitly references a public API endpoint for whitelisted users. ## Risk note The presence of API documentation does not mean unrestricted public access; the docs say access is limited by whitelisting and KYC/AML requirements, and US users are not able to access the application.
Evidence (3)

Security

bug bounty

one source

Ethena USDe has an active bug bounty program on Immunefi. It launched on 04 April 2024, with scope covering Ethena smart-contract targets including USDe.sol, EthenaMinting.sol V2, StakedUSDe.sol, StakedUSDeV2.sol, and USDeSilo.sol. The program pays in USDC on Ethereum Mainnet, and critical smart-contract bugs are rewarded at 10% of the funds directly affected up to a maximum of USD 3,000,000, with a minimum critical reward of USD 100,000.

High-severity reports are paid on a tiered basis, including website/application criticals up to USD 50,000 and high smart-contract issues up to USD 15,000 or a higher capped range depending on impact. No public payout result set specific to Ethena was identified in the sourced program pages; the program page shows totals and triage status but not an explicit public list of paid cases here. If you need verified payout history, that is Not verifiable as of 2026-09-04 from the gathered sources.

Active
Yes
Platform
Immunefi
Max payout
$3.0M
Since
2024-04-04
Evidence (3)

counterparty risks

unverified

Assessment — Ethena USDe, Ethereum; as of September 6, 2026 Dependency map and failure modes

  • CEXs / derivatives: USDe historically depended on delta-hedged perpetuals across Binance, Bybit, OKX and others. Off-exchange settlement reduces direct asset-loss risk, but does not remove exchange insolvency, withdrawal halts, liquidation, funding-rate inversion, API or settlement risk. Ethena’s October 10, 2025 event showed venue-specific oracle/liquidation feedback: USDe briefly traded near $0.65 on Binance and $0.92 on Bybit.
  • Custodians/OES: Public materials identify Copper and Ceffu as OES providers, with additional custody proposals involving Kraken, Anchorage and Zodia. Custodian failure could delay mint/redemption even if assets are bankruptcy-remote or segregated. Coinbase was reported as a primary custodian, wallet provider and perpetuals venue in June 2026, creating potential concentration risk.
  • Oracles/market structure: Centralized-exchange order-book oracles and lending-market price feeds can create liquidations and reflexive depegs during thin liquidity or exchange outages. The L2 PSM design is explicitly oracle-guarded; its proposed initial float was $20m across two L2s. Current Ethereum-specific bridge/oracle exposure is Not verifiable as of September 6, 2026.
  • External protocols and credit/RWA: The latest quantitative snapshot located is July 3, 2026 and is therefore stale: approximately 46% DeFi lending, 35% liquid stablecoins, 11.2% tokenized CLO exposure (JAAA/STAC), 6.9% institutional lending, and only 1% crypto basis. This indicates material dependence on Aave/Morpho/Kamino/Jupiter, stablecoin issuers, RWA issuers/custodians, and institutional borrowers. Current percentages are Not verifiable as of September 6, 2026. > Contradiction/change: The previously recorded finding characterized CEX derivatives as the primary exposure. Later public reporting shows the basis book reduced to ~1% while DeFi lending, tokenized CLOs and institutional lending became dominant. The older CEX concentration finding should not be reused as the current exposure estimate. Stress scenarios: prolonged negative funding; exchange/custodian insolvency; oracle manipulation; stablecoin or LST depeg; RWA/borrower default; bridge exploit; redemption wave combined with illiquid collateral; and smart-contract or governance failure. The reserve fund is only a partial buffer, not insurance against full counterparty loss. Structured fields
  • dependency_failure_active: false — no currently active public dependency failure identified in the reviewed sources.
  • max_exposure_pct: null — current Ethereum-specific maximum counterparty exposure is Not verifiable as of September 6, 2026.
Dependency failure active
No
Evidence (5)

crypto custody

one source

Ethena USDe custody is organized as off-exchange institutional custody: backing assets are held with regulated custody providers under Off-Exchange Settlement (OES), and Ethena controls the instructions to deposit, withdraw, move between custodians/exchanges, or recall assets for redemption support. Kraken states Ethena’s assets are maintained one-to-one in fully segregated, bankruptcy-remote cold-storage vaults, and Ethena’s documentation says backing assets do not reside directly on exchange partner balance sheets. The practical takeaway is that custody is split between custodians/OES providers holding the backing assets and centralized derivatives venues used for hedging without transferring custody. withdrawal_paused: null segregated_assets: true

Segregated assets
Yes
Evidence (4)

incident

one source

Discord compromise: a community security incident occurred in July 2024, when attackers posted phishing links in Ethena’s Discord under the guise of token bonus offers. Public results do not provide a verified loss amount, affected-user count, or reimbursement/fix details beyond warnings not to interact with the links.

Date
2024-07-01
Cause
Frontend / infrastructure hack
Evidence (1)

incident

one source

Corrected detail: on July 14, 2024, a compromised Discord moderator account posted phishing links falsely offering token bonuses. Ethena removed the malicious post and moderator account and stated that the issue was resolved. No verified user-loss amount, attacker proceeds, affected-user count, or reimbursement is available. Current status: resolved.

Date
2024-07-14
Cause
Frontend / infrastructure hack
Status
resolved
Event id
ethena-discord-phishing-2024-07-14
Evidence (1)

incident

one source

Corrected detail: a phishing site was hosted on the compromised ethena.fi domain for less than two hours and affected approximately 10 wallets. Ethena estimates approximately $15,000 in total user funds were affected; no backend, mint/redeem, or peg impairment was identified. Response: traffic was blocked, the registrar account and malicious site were taken down within approximately two hours, and the domain was migrated to a more secure registrar.

Ethena stated that affected users were being made whole, but completion of all reimbursements is not independently verifiable as of 2026-09-06. Current status: remediation_in_progress.

Date
2024-09-18
Cause
Frontend / infrastructure hack
Loss
$15K
Status
remediation in progress
Event id
ethena-domain-registrar-2024-09-18
Evidence (2)

incident

one source

February 21–28, 2025 — Bybit wallet hack / counterparty stress. Bybit lost approximately $1.4–1.5 billion in assets; Ethena had about $30 million of unrealized PnL exposure through Bybit perpetual positions, but USDe spot backing was held through off-exchange custody and was not stolen. Affected: Ethena’s Bybit hedge exposure, USDe/sUSDe secondary-market pricing, and users redeeming during the stress; more than $120 million of USDe redemptions were processed.

Ethena reduced Bybit exposure from approximately $30 million to zero, used its stablecoin buffer and reserve fund, and maintained normal mint/redemption operations. No confirmed Ethena protocol or user-fund loss; the Bybit attacker’s total proceeds were approximately $1.4–1.5 billion, but proceeds attributable to Ethena were not verifiable as of September 5, 2026. No Ethena reimbursement was required or reported.

Status: resolved; remediation included reducing direct exchange exposure and relying on off-exchange settlement/custody.

Date
2025-02-21
Cause
Exchange incident
Loss
$0
Status
resolved
Recovered
$0
Reimbursed
No
Evidence (3)

incident

one source

Corrected detail: this was a venue-specific Binance pricing/oracle failure during the October 10, 2025 liquidation cascade, not a confirmed USDe protocol loss or smart-contract exploit. Ethena reported orderly redemptions of approximately $1.9 billion across the event window, no Reserve Fund draw, and no material on-chain peg failure. Binance compensated impacted Futures, Margin, and Loan users and announced index changes adding redemption-price inputs, a USDe minimum-price threshold, and more frequent risk-parameter reviews.

Binance reported approximately $283 million of aggregate compensation across USDe, BNSOL, and WBETH; the USDe-specific share and total user loss are Not verifiable as of 2026-09-06. Current status: resolved.

Date
2025-10-10
Cause
Oracle manipulation
Status
resolved
Reimbursed
Yes
Event id
binance-usde-price-dislocation-2025-10-10
Evidence (3)

incident

one source

October 10, 2025 — Binance USDe price dislocation. During a broader market liquidation cascade, USDe traded as low as approximately $0.65 on Binance for roughly 40 minutes because Binance’s pricing/index mechanism relied on a thin, impaired venue order book. USDe remained near its intended value on deeper on-chain and other markets, and Ethena’s backing and primary redemptions continued.

Affected: Binance users holding USDe as futures, margin, or loan collateral; some were forcibly liquidated. Ethena’s protocol loss and the USDe-specific portion of user losses were not verifiable as of September 5, 2026. Binance reported approximately $283 million of aggregate compensation across USDe, BNSOL, and WBETH-related users; this was paid by Binance, not Ethena.

Response/fix: Binance compensated eligible users, incorporated redemption pricing and added a soft price floor to its reference methodology; Ethena published additional proof-of-reserves information. Status: resolved.

Date
2025-10-10
Cause
Other
Status
resolved
Reimbursed
Yes
Evidence (3)

incident

one source

Notable incidents: available web results do not establish a confirmed exploit of the core USDe smart contracts. The clearest documented events are operational/security incidents around Ethena’s communications and infrastructure, plus a market depeg episode. The depeg was described as a secondary-market event during a broader liquidation cascade, while mint/redeem reportedly stayed operational.

Date
2025-10-11
Cause
Liquidity issue
Evidence (2)

incident

one source

Protocol stress event, not a loss event: during the April 2026 rsETH incident, Ethena reported operating without disruption, pausing the LayerZero OFT bridge briefly, then restoring it with hardened DVN settings and the same rate limit. No loss, reimbursement, or fix beyond the bridge hardening is evidenced in the available results.

Date
2026-04-19
Cause
Other
Evidence (1)

key management

unverified

Ethena’s USDe key management is organized around multi-signature control, cold-wallet storage, and role separation. The protocol says the DEFAULT_ADMIN_ROLE and owner roles are held by multisig keys stored in cold wallets, and the multisig approval process is required for major fund transfers. Ethena also states that the smart-contract ownership multisig uses 7 signatures and that its keys are geographically distributed and controlled by distinct individuals, including internal and external stakeholders.

Operationally, Ethena separates powers across roles. A GATEKEEPER_ROLE can pause mint/redeem flows, remove mint/redeem permissions, and add whitelisted custodial addresses, but it cannot re-enable minting and redeeming or perform unrelated privileged actions. The docs also say separate gatekeeper roles exist to detect unusual mint/redeem activity and immediately disable those functions if needed.

For day-to-day custody operations, Ethena says mint/redeem contract keys are generated in an air-gapped manner so no single person can access them, and a small portion of protocol assets may sit in EOA wallets while larger transfers require secure multisig approval. The protocol further states that backing assets are sent only to whitelisted OES/custodial partner addresses, and updating those whitelists requires a multisig transaction by members of Ethena and external responsible parties. In short, the key-management model is: cold multisig for admin control, air-gapped key generation for mint/redeem infrastructure, whitelisted custodial destinations, and role-based circuit breakers.

Evidence (3)

smart-contract

two sources

Scope/as-of: Ethereum mainnet; on-chain verification via Dune was unavailable. Therefore proxy slots, decoded admin events, current role holders, and the exact enforced timelock delay are Not verifiable as of September 6, 2026. Addresses: USDe 0x4c9edd5852cd905f086c759e8383e09bff1e68b3; sUSDe/StakedUSDeV2 0x9d39a5de30e57443bff2a8307a4256c8797a3497; EthenaMinting V1 0x2cc440b721d2cafd6d64908d6d8c4acc57f8afc3; V2 0xe3490297a08d6fc8da46edb7b6142e4f461b62d3; rewards distributor 0xf2fa332bd83149c66b09b45670bce64746c6b439. These addresses are published by Ethena and cross-referenced by an independent indexer. Admin powers: The documented owner/admin model is materially privileged: USDe owner can change the sole minter; DEFAULT_ADMIN_ROLE can grant/revoke minter, redeemer and gatekeeper roles, change supported collateral/custodians and limits; minters can mint USDe and transfer collateral to approved custodians; gatekeepers can disable minting/redemption.

Staking admin/rewarder roles can add rewards, alter restrictions and redistribute fully restricted sUSDe. Upgradeability/proxy: Contradiction: the previous finding described core contracts as upgradeable proxies, but an independent contract framework states canonical USDe, sUSDe and EthenaMinting V2 are not proxy contracts. Without current bytecode/storage-slot verification, the final status is unknown, not confirmed upgradeable. Timelock/admin type: Ethena documents a multisig-controlled, seven-day timelock for core changes; an independent tracker identifies a TimelockController, but the exact delay, proposer/executor/canceller set, and whether every relevant role is covered are Not verifiable as of September 6, 2026. Exit and failure modes: Users can transfer USDe/sUSDe without admin approval, but mint/redemption is whitelist- and gatekeeper-dependent; redemption can be paused. A compromised owner/admin could replace the minter, authorize malicious minters/custodians, freeze redemptions, or cause severe USDe dilution; compromised staking roles could confiscate/reassign restricted sUSDe.

This is a meaningful freeze/rug risk, although documented per-block limits and gatekeepers reduce—rather than eliminate—blast radius. Audits found no unresolved critical/high findings in the reviewed v1/v2 scopes, but current deployment-wide status is not independently verifiable. Architecture: User ↔ USDe ↔ EthenaMinting (mint/redeem, oracle, custody roles) ↔ custodians/venues; User → sUSDe vault → rewards distributor; Multisig/timelock → owner/admin/gatekeeper/rewarder controls.

Admin can drain
Yes
Audited deployment
Yes
Unresolved critical
0
Unresolved high
0
Evidence (9)

audit

two sources

Economic and financial risk audit of Ethena system design and USDe reserve/deleveraging mechanisms.

Auditor
Chaos Labs
Report date
2024-04-11
Scope
System-level economic design, delta-neutrality, reserve sufficiency and risk parameters for USDe.[7][13] Bytecode / deployed-contract coverage not applicable (model-level audit).
Findings
Focused on economics and risk, not code-level bugs; no critical or high-severity technical vulnerabilities reported.[2][7] Detailed quantitative issues not itemized in retrieved summaries.
Fix status
Design recommendations incorporated; no outstanding critical/high economic-risk items flagged in public summaries.[7][13]
Evidence (2)

audit

one source

Checkpoints audit report; file lib/openzeppelin-contracts-upgradeable/audits/2022-10-Checkpoints.pdf in code-423n4/2023-10-ethena (protocol audit catalog).

Auditor
Checkpoints
Report date
2022-10
Scope
protocol
File
2022-10-Checkpoints.pdf
Catalog only
Yes
Evidence (1)

audit

two sources

Public competitive audit (audit contest) of Ethena Labs smart contracts.

Auditor
Code4rena
Report date
2023-10-24
Scope
Ethena Labs Solidity smart contract system audited via Code4rena (V2-era; includes USDe-related contracts).[6][9][11][7] Bytecode-match / coverage of currently deployed contracts: Not verifiable as of 2026-09-04.
Findings
No critical or high-level issues.[7] Four medium-severity issues, 98 low/non-critical issues, and 41 gas optimization recommendations.[7]
Fix status
Reported as fixed or acknowledged; no remaining high/critical issues.[7]
Evidence (3)

audit

one source

Ethena docs list a public Code4rena audit completed on 13 Nov 2023 with no critical or high level issues identified. The Code4rena contest page confirms the protocol was deployed on Ethereum and reports test coverage of 87.56% (373/426 statements), but the provided excerpt does not show a full severity table for all findings, fix status, or whether the report was bytecode-matched to the currently deployed contracts. Those details are not verifiable as of 2026-08-30.

Auditor
Code4rena
Report date
2023-11-13
Scope
Ethereum deployment; contest audit of Ethena Labs contracts
Evidence (2)

audit

one source

Code4rena — Ethena Labs public audit; report publication date: 2023-12-21; contest period: 2023-10-24–2023-10-30; scope: Ethena V1 contracts, including minting and staking. Findings: 0 critical, 0 high, 4 medium, 98 low/non-critical and 41 gas recommendations. Fix status: report documents sponsor/judging outcomes, but complete remediation status is Not verifiable as of 2026-09-05.

Deployed-code bytecode match: Not verifiable as of 2026-09-05.

Auditor
Code4rena
Report date
2023-12-21
Scope
Ethena V1 smart-contract system
Findings
0 critical; 0 high; 4 medium; 98 low/non-critical; 41 gas recommendations.
Fix status
Remediation status incomplete/not fully verifiable; deployed-code match not verifiable.
Evidence (1)

audit

unverified

Ethena docs list a Cyfrin audit completed on 31 Oct 2024 and state that no critical or high level issues were identified. The provided sources do not include the detailed scope, finding severities below high, fix status, or bytecode-match confirmation. These are not verifiable as of 2026-08-30.

Auditor
Cyfrin
Report date
2024-10-31
Scope
Not verifiable as of 2026-08-30
Evidence (1)

audit

one source

Newly confirmed: Cyfrin — Ethena Timelock review, report dated 2025-05-27. Scope: DAO/timelock contracts. Findings: 0 critical, 0 high, 0 medium, 4 low, 4 informational, 1 gas. Remediation and deployed-code bytecode match are Not verifiable as of 2026-09-06.

Auditor
Cyfrin
Report date
2025-05-27
Scope
Ethena DAO and timelock contracts
Findings
0 critical; 0 high; 0 medium; 4 low; 4 informational; 1 gas recommendation.
Fix status
Remediation status and deployed-code match Not verifiable as of 2026-09-06.
Report url
https://github.com/Cyfrin/cyfrin-audit-reports
Report id
doc:1f3f9dcd6b8d3cdc
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly confirmed: Code4rena — Ethena Labs Invitational, report published 2024-12-02; contest ran 2024-11-04–2024-11-11. Scope: four USDtb/UStb contracts, 665 Solidity lines. Findings: 0 critical, 0 high, 2 medium, 5 low/non-critical in the final report. Sponsor remediation is not complete/verifiable; deployed-code bytecode match Not verifiable as of 2026-09-06.

Auditor
Code4rena
Report date
2024-12-02
Scope
USDtb/UStb token and minting contracts
Findings
0 critical; 0 high; 2 medium; 5 low/non-critical; additional informational/code-quality discussion in report.
Fix status
Some findings have sponsor acknowledgements or mitigation discussion; complete remediation and deployed-code match Not verifiable as of 2026-09-06.
Report url
https://code4rena.com/reports/2024-11-ethena-labs
Report id
doc:ad0c92d618dfe8f4
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly confirmed: Guardian — L2 USDe PSM security review, final report issued 2026-07-02. Scope: PSM contract, deployment script, and test suite. Findings: 0 critical, 0 high, 3 medium, 9 low, 9 informational.

Medium findings were acknowledged as operational tradeoffs; most low/informational findings were remediated. Current deployed-code bytecode match is Not verifiable as of 2026-09-06.

Auditor
Guardian
Report date
2026-07-02
Scope
L2 USDe PSM contract, deployment script, and test suite
Findings
0 critical; 0 high; 3 medium; 9 low; 9 informational.
Fix status
3 medium findings acknowledged/accepted as operational tradeoffs; majority of low/informational findings reportedly resolved; full item-level status and deployed-code match Not verifiable as of 2026-09-06.
Report url
https://gov.ethenafoundation.com/t/review-of-the-l2-usde-psm-proposal/810
Report id
doc:d1838b37b8260c44
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

unverified

Newly confirmed: Pashov Audit Group — sENA audit, published/completed 2024-09-02. Scope: Staked ENA (sENA) contracts. Ethena reports no critical or high findings; lower-severity totals and individual remediation statuses are Not verifiable as of 2026-09-06. Deployed-code bytecode match: Not verifiable as of 2026-09-06.

Auditor
Pashov Audit Group
Report date
2024-09-02
Scope
Staked ENA (sENA) contracts
Findings
0 critical; 0 high; medium/low/informational totals Not verifiable as of 2026-09-06.
Fix status
No critical/high findings reported; complete remediation status Not verifiable as of 2026-09-06; deployed-code match not verifiable.
Report url
https://docs.ethena.fi/resources/audits
Report id
doc:fdf4a042a609ae56
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

ERC4626 audit report; file lib/openzeppelin-contracts-upgradeable/audits/2022-10-ERC4626.pdf in code-423n4/2023-10-ethena (protocol audit catalog).

Auditor
ERC4626
Report date
2022-10
Scope
protocol
File
2022-10-ERC4626.pdf
Catalog only
Yes
Evidence (1)

audit

one source

OtterSec conducted a separate security audit of Ethena’s USDe-related contracts on Ethereum. The scope overlaps with Zellic but focuses on additional components such as staking, liquidity management, and protocol configuration contracts that interact with USDe. OtterSec identified 1 High, several Medium and Low issues (exact numeric breakdown in the report tables).

The public summary states that all High and Medium issues were remediated or acknowledged with acceptable mitigations by Ethena before deployment. As with other reports, whether the exact audited bytecode matches the currently deployed Ethereum contracts is Not verifiable as of 2026-09-03 without on-chain tooling, so coverage of *current* live code is uncertain.

Auditor
OtterSec
Report date
2024-03-04
Scope
Ethena protocol smart contracts on Ethereum interacting with USDe: staking, liquidity/position management, configuration and auxiliary contracts as described in OtterSec’s scope section.[2]
Findings
1 High, several Medium and Low issues (see OtterSec finding table). All High and Medium issues are marked as resolved or mitigated in the final report status section.[2]
Fix status
OtterSec’s final report marks the single High severity issue as fixed, and Medium issues as either fixed or mitigated. Low/Informational findings are documented, with some accepted as design choices.[2] Independent on-chain confirmation of remediation status is Not verifiable as of 2026-09-03.
Evidence (1)

audit

unverified

Ethena docs list multiple Pashov audits: 22 Oct 2023, 22 Dec 2023, 23 May 2024, 2 Sept 2024, and 20 Oct 2024. The docs excerpt only states for each that no critical or high level issues were identified. The provided sources do not include the detailed scope, medium/low findings, fix status, or a bytecode-match note, so those items are not verifiable as of 2026-08-30.

Auditor
Pashov
Report date
2024-10-20
Scope
Not verifiable as of 2026-08-30
Evidence (1)

audit

one source

Pashov Audit Group — Ethena V1 audit; report date: 2023-10-21 (Ethena lists completion as 2023-10-22); scope: EthenaMinting, USDe, StakedUSDe, StakedUSDeV2 and SingleAdminAccessControl. Findings: 4 low. Fixes: 2 fixed, 2 acknowledged. Deployed-code bytecode match: Not verifiable as of 2026-09-05.

Auditor
Pashov Audit Group
Report date
2023-10-21
Scope
EthenaMinting, USDe, StakedUSDe, StakedUSDeV2, SingleAdminAccessControl
Findings
0 critical; 0 high; 0 medium; 4 low.
Fix status
2 fixed; 2 acknowledged; deployed-code match not verifiable.
Evidence (1)

audit

two sources

Independent audit of Ethena minting contracts and related USDe components.

Auditor
Pashov Audit Group
Report date
2024-05-20
Scope
EthenaMinting, USDe, StakedUSDe, StakedUSDeV2, SingleAdminAccessControl and related contracts.[4][5] Bytecode-match / coverage of currently deployed contracts: Not verifiable as of 2026-09-04.
Findings
Time-boxed review (May 20–23 2024) on ethena-mint-contract-audit repo: total 3 issues – 1 medium (M-01: some orders can be executed multiple times), 2 low (L-01, L-02); 2 resolved, 1 acknowledged.[4] Earlier independent audit on V2 codebase: 4 low-severity issues (2 fixed, 2 acknowledged), no critical/high/medium issues.[7]
Fix status
For May 2024 review: medium and one low issue resolved; one low acknowledged.[4] For earlier V2 audit: mix of fixed and acknowledged, no remaining medium/high/critical.[7]
Evidence (3)

audit

one source

Pashov Audit Group — Ethena V2 audit; report date: 2024-05-23; scope: V2 synthetic-dollar contracts/repository. Findings: 0 critical, 0 high, 1 medium, 2 low. Individual fix statuses and deployed-code bytecode match: Not verifiable as of 2026-09-05.

Auditor
Pashov Audit Group
Report date
2024-05-23
Scope
Ethena V2 contracts
Findings
0 critical; 0 high; 1 medium; 2 low.
Fix status
Not verifiable as of 2026-09-05; deployed-code match not verifiable.
Evidence (1)

audit

two sources

Audit of Ethena USDe token smart contracts on Ethereum.

Auditor
Quantstamp
Report date
2023-09-20
Scope
USDe token and related Ethena Labs contracts (V2 codebase focus).[3][7] Bytecode-match / coverage of currently deployed contracts: Not verifiable as of 2026-09-04.
Findings
Total 13 findings: 4 medium, 3 low, 6 informational; no critical or high-severity issues.[3][7] Two medium and all three low issues fixed; two medium and two informational acknowledged.[3][7]
Fix status
Mixed: majority fixed, remainder acknowledged; no unfixed high/critical issues reported.[3][7]
Evidence (2)

audit

one source

USDe audit report. The published summary states the report was completed on 18 Oct 2023 and found no critical or high severity issues. The report summary on Certik’s hosted PDF says the audit covered the USDe token, used Solidity, and identified 13 findings total: 4 medium, 3 low, 6 informational, with 9 fixed and 4 acknowledged.

Medium findings included privileged roles/ownership, delegated-signer DoS, and native token withdrawal/deposit inconsistency; the report also says 4 medium findings were fixed and 2 medium findings were acknowledged. Whether the report covers the exact currently deployed bytecode is not verifiable from the provided sources; the docs say it was for the protocol’s audited version, but no bytecode-match note or verified deployment mapping was provided.

Auditor
Quantstamp
Report date
2023-10-18
Scope
USDe token / protocol contracts (Solidity); architecture review, unit testing, functional testing, computer-aided verification, manual review
Evidence (2)

audit

one source

Sigma Prime performed an audit of Ethena’s protocol contracts, including components involved in the USDe system on Ethereum. The report highlights several Medium, Low, and Informational issues; no Critical issues are listed and any High-severity concerns were either not present or downgraded after remediation. Sigma Prime indicates all identified Medium-severity issues were addressed or accepted with clear justification by Ethena.

The report is on pre-deployment code; whether the audited code exactly matches the currently deployed Ethereum bytecode is Not verifiable as of 2026-09-03.

Auditor
Sigma Prime
Report date
2024-03-22
Scope
Ethena protocol smart contracts on Ethereum, including core contracts supporting USDe minting, management, and collateral interactions as listed in Sigma Prime’s scope section.[3]
Findings
No Critical issues reported; Medium, Low and Informational issues identified (exact counts in the Sigma Prime report tables). All Medium severity findings are marked as resolved or otherwise accepted with documented rationale.[3]
Fix status
Sigma Prime’s final status shows Medium items resolved or mitigated; Low/Informational are left as recommendations or accepted risks.[3] Independent verification of fixes on-chain is Not verifiable as of 2026-09-03.
Evidence (1)

audit

unverified

Ethena docs list a Spearbit audit completed on 18 Oct 2023 and state that no critical or high level vulnerabilities were found. The provided sources do not include the detailed scope, findings table, fix status, or any bytecode-match confirmation; those details are not verifiable as of 2026-08-30.

Auditor
Spearbit
Report date
2023-10-18
Scope
Not verifiable as of 2026-08-30
Evidence (1)

audit

one source

Spearbit & Cantina — Ethena audit; date: 2023-10-18; scope: V1 smart-contract system. Findings: 0 critical, 0 high, 0 medium, 2 low, 14 gas optimizations and 8 informational findings. Fix status: Not verifiable as of 2026-09-05 from the published report metadata. Deployed-code bytecode match: Not verifiable as of 2026-09-05.

Auditor
Spearbit & Cantina
Report date
2023-10-18
Scope
Ethena V1 contracts
Findings
0 critical; 0 high; 0 medium; 2 low; 14 gas; 8 informational.
Fix status
Not verifiable as of 2026-09-05; deployed-code match not verifiable.
Evidence (2)

audit

one source

v4.9 audit report; file lib/openzeppelin-contracts-upgradeable/audits/2023-05-v4.9.pdf in code-423n4/2023-10-ethena (protocol audit catalog).

Auditor
v4.9
Report date
2023-05
Scope
protocol
File
2023-05-v4.9.pdf
Catalog only
Yes
Evidence (1)

audit

two sources

Initial audit of Ethena v1 contracts and architecture.

Auditor
Zellic
Report date
2023-03-01
Scope
Ethena v1 core contracts (pre-V2) related to USDe design.[1][2][7] Bytecode-match / coverage of currently deployed V2/V3 contracts: Not verifiable as of 2026-09-04.
Findings
No critical or high-level vulnerabilities reported; detailed issue list not publicly enumerated in retrieved sources.[1][2][7]
Fix status
Reported that no critical/high remained post-audit; lower-severity items presumably fixed/acknowledged but not itemized.[1][2][7]
Evidence (3)

audit

one source

Zellic — Ethena Security Assessment Report; publication date: 2023-07-05; scope: EthenaMinting, EthenaStaking and related EVM contracts. Findings: 0 critical, 0 high, 1 medium, 1 low; both acknowledged and fixed. Covers deployed code: No—the report states the audited code was not deployed to Ethereum Mainnet at review time.

Current bytecode match: Not verifiable as of 2026-09-05.

Auditor
Zellic
Report date
2023-07-05
Scope
EthenaMinting, EthenaStaking and related scoped contracts; V1
Findings
0 critical; 0 high; 1 medium; 1 low. All findings acknowledged and fixed.
Fix status
Fixed; current deployment match not verifiable.
Evidence (1)

audit

one source

According to Zellic’s official audit report for Ethena’s USDe system on Ethereum, Zellic audited the core smart contracts that implement USDe’s synthetic dollar mechanism, staking, and related protocol components. The report lists 3 High, 7 Medium, 4 Low, and several Informational issues. Zellic notes in the summary that all High and Medium severity issues were addressed or mitigated by the Ethena team prior to mainnet launch.

The report explicitly states it covered the production deployment configuration at the time of audit; however, without on-chain bytecode comparison this cannot be independently confirmed and must be treated as unverified marketing claim regarding full coverage of current deployed code. Bytecode match to live Ethereum contracts: Not verifiable as of 2026-09-03.

Auditor
Zellic
Report date
2024-02-27
Scope
Core Ethena/USDe protocol contracts on Ethereum (USDe issuance/redemption logic, staking, collateral/oracle integrations and associated management contracts present in the audited repo at the time). Exact contract list is defined in the Zellic report.[1]
Findings
3 High, 7 Medium, 4 Low, several Informational issues. All High and Medium reported issues were resolved or mitigated in collaboration with the Ethena team, per Zellic’s report.[1]
Fix status
Per Zellic’s report, all High and Medium severity findings were fixed or mitigated before deployment; Low/Informational items were either acknowledged, documented, or accepted as known trade-offs.[1] Independent on-chain confirmation of fixes is Not verifiable as of 2026-09-03.
Evidence (1)

Team & Reputation

founders

two sources

Ethena USDe appears to be a *real, venture-backed team-led protocol*, not an anon “web front.” The public face is Guy Young, identified across multiple independent sources as Ethena’s founder/CEO; those sources also describe prior traditional-finance experience, including hedge funds, investment banking, private equity, and most recently Cerberus Capital Management. Independent coverage also names other visible team members such as Elliot Parker (COO/product background), Conor Ryder (research), and Natalie Morrish (talent), which is consistent with a staffed operating company rather than a solo anonymous deployment.

Evidence (3)

general reputation

two sources

Ethena/USDe has a generally *mixed-to-positive* market reputation: some reviewers and community commentary describe it as innovative and high-growth, while others emphasize that it is a synthetic dollar with structural risks rather than a fully reserved stablecoin. Independent risk/rating sites in the results give it a safer or “SAFE” profile, but these are still aggregator opinions, not on-chain verification. On *founders/investors*, the results indicate Ethena is VC-backed and has been criticized by some commentators as a “VC coin” with tokenomics that may favor insiders, but the provided sources do not verify specific investors or quantify insider control.

On *auditors/security*, one review says Ethena’s smart contracts have been reviewed by Zellic and Trail of Bits, but this is not independently confirmed in the supplied results and should be treated as an *unverified claim* from secondary coverage. The main *criticisms* are consistent across sources: USDe depends on delta-hedged derivatives and perpetual-futures funding rates, so negative funding, exchange/custody failure, liquidity stress, or a severe crypto bear market could impair the peg or economics. Critics also point to centralized wallet/custody management and dependence on derivatives venues as deviations from DeFi’s decentralization ideal and as a systemic risk.

On *fraud/rug/insolvency allegations*, the supplied results do not provide a substantiated fraud, rug-pull, or insolvency finding; one community discussion explicitly says it is “not a scam,” while still warning about risks. On *legal/regulatory*, a 2026 report says Ethena exited the EU/EEA after BaFin barred USDe under MiCA, and another source says USDe sits outside the GENIUS Act’s regulated-issuer lane. I did not find any sanctions allegation in the supplied results, and that remains Not verifiable as of 2026-09-04.

Evidence (13)

Economy

TVL: $4.6B

model

one source

Economic model (as of September 6, 2026). USDe is a crypto-backed synthetic dollar: approved spot collateral (BTC/ETH/LSTs and liquid stablecoins) is paired approximately 1:1 with short perpetual or dated-futures positions. The intended exposure is market-neutral, not directional; the short hedge offsets spot delta. Backing remains with off-exchange-settlement custodians while exchanges receive delegated margin, leaving exchange, custodian, oracle, liquidity, basis and funding-rate risks. Yield. Sources are (1) short-side perpetual funding/basis, (2) staking yield on ETH/LST collateral, and (3) rewards on liquid stablecoin collateral.

Funding is variable and can turn negative; therefore yield is not structurally guaranteed. sUSDe is the reward-bearing product; USDe itself does not automatically accrue protocol yield. External incentives, including rewards from integrations, should be treated as subsidized rather than organic. A defensible current organic-yield percentage is Not verifiable as of September 6, 2026 because the available public data does not separate funding, staking, stablecoin rewards and incentives.

Historical APY has been highly cyclical: Ethena reports 2024 average sUSDe APY of 19%, while DeFiLlama currently reports approximately 4.5% for its tracked USDe yield pool. Leverage/external exposure. Core USDe does not require looping, rehypothecation or restaking; sUSDe deposits are not lent out. Users can nevertheless lever or loop USDe/sUSDe through Aave, Pendle and other venues, creating external liquidation and composability risk. Aggregate protocol leverage is Not verifiable as of September 6, 2026. Liquidity and controls. Direct mint/redeem is KYC/KYB-gated and whitelist-only, uses signed RFQ orders, last-look/oracle checks, per-block caps and can be paused by gatekeepers.

Mint/redeem costs are generally execution and gas reimbursements rather than a stated protocol fee. Large redemptions may require multiple blocks; sUSDe unstaking currently has a 7-day cooldown, while the contract permits governance to set up to 90 days. TVL/revenue. DeFiLlama reports USDe TVL of approximately $4.336B, 100% Ethereum, +11.3% over 30 days; 30-day fees were $21.12M and reported revenue $21.3K. Dune comparison and on-chain TVL/product decomposition: Not verifiable as of September 6, 2026 (Dune unavailable). CONTRADICTION / SCOPE: Parent Ethena TVL is reported around $4.79B because it includes other products; USDe-only TVL is lower.

The USDe figure is the relevant comparison for this protocol slug.

Evidence (5)

reserves

two sources

As of September 6, 2026, the latest disclosed Reserve Fund size is approximately $62M, but the latest detailed composition located is stale (>7 days): $41.98M USDtb and $20.02M in a USDtb/USDC LP, reported for April 2026. The fund is a supplemental buffer—not the principal USDe backing pool—and is intended to cover negative funding/impairment events and act as a last-resort USDe buyer. Address/control: Ethereum Reserve Fund multisig: 0x2B5AB59163a6e93b4486f6055D33CA4a115Dd4D5; 4-of-10 signers. Ethena’s documentation states the keys are held by contributors within Ethena Labs.

The fund’s assets are reported as manually transferred to the multisig; USDtb interest is not automatically accrued. Policy: Historical policy allowed protocol-revenue contributions subject to governance. The April 2026 update showed $0 USDe-fee allocation to the Reserve Fund in March and April, and stated the fund had received no allocation since December 12, 2024. Future USDtb interest was recommended for sUSDe holders while the fund remains above a safety threshold. Custody/attestations: Ethena publishes monthly custodian attestations covering existence, control, and value of backing assets; its documentation states backing assets are not held directly on exchange partners.

The June 2026 update reported refreshed proof-of-reserves checks by Chainlink, Chaos Labs, LlamaRisk, and Harris & Trotter, with collateralization above 100%. Coinbase was reported as primary custodian/provider in June, but this is a governance disclosure, not independently verified here. On-chain/Dune: Not verifiable as of September 6, 2026. Dune MCP was unavailable; no Dune query ID or execution ID can be supplied.

Current reserve-wallet balances and composition therefore remain unverified on-chain. Current liabilities proxy: DeFiLlama reports approximately $4.331B circulating USDe today; this is an analytics-platform figure, not raw on-chain verification. Contradiction: The ~$62M reserve figure is repeatedly reported through June 2026, but no current September 2026 reserve attestation or Dune balance was located. Treat $62M as last disclosed, not current verified NAV.

Liquid reserves usd
$62.0M
Liabilities usd
$4.3B
Evidence (8)

tokenomics

one source

Ethena’s native token is ENA; the stablecoin is USDe (non‑governance). Ethena has a token; USDe does not function as an equity/governance token. ### Core token data (ENA)

  • Chain: Ethereum.
  • Type: ERC‑20 governance/utility token.
  • Contract address: Not verifiable as of 2026‑09‑04 (needs on‑chain/explorer confirmation).
  • Total / max supply: Public sources consistently reference a fixed max supply of 15 billion ENA.
  • Circulating supply: Varies over time; recent figures cluster around ~1.4–1.7 billion ENA in circulation (≈9–11% of max).
  • Market cap / FDV: Market cap derived from circulating supply × price; FDV from max supply × price. Exact figures are time‑varying and not stable; use up‑to‑date market data (e.g. major aggregators) for current numbers. ### Utility and governance
  • Governance role: ENA is used for protocol governance, including parameter changes to Ethena’s synthetic dollar/hedging system, risk framework, and treasury decisions.
  • Protocol utility: ENA is used in staking, where stakers participate in governance and may receive protocol fee distributions or incentive rewards.
  • USDe: Designed as a synthetic dollar backed by delta‑neutral derivatives; it does not represent protocol equity/governance. ### Revenue, rewards, and token flows
  • Ethena generates revenue primarily from funding rates and derivatives yields on its hedged positions.
  • A portion of protocol revenues is allocated to USDe yield and potentially ENA stakers, but exact sharing percentages are parameterized and can change via governance.
  • Staking rewards: ENA staking is incentivized via emissions plus fee share; details are schedule‑dependent and not fully standardized across sources.
  • Buybacks/burns: Ethena has signaled potential buybacks or treasury operations, but hard on‑chain burn mechanics/data are Not verifiable as of 2026‑09‑04. ### Token distribution and emissions
  • Allocations: Public tokenomics materials indicate allocations to core team, investors, ecosystem/community, liquidity and marketing, and treasury/reserves; percentage splits vary by source and are not fully reconcilable without on‑chain data.
  • Emissions schedule: ENA emissions follow a long‑term unlock schedule for team/investor and ecosystem buckets, with cliff + linear vesting typical of DeFi launches.
  • Unlocks: Specific vesting events (team/investor unlocks) are Not verifiable as of 2026‑09‑04 without on‑chain traces. ### Concentration and controls
  • Top‑holder concentration / insider wallets: Not verifiable as of 2026‑09‑04.
  • Admin functions (mint/blacklist/fee‑switch): USDe is a synthetic asset; ENA is a capped token. Detailed admin/mint/blacklist/fee‑switch powers and controlling entities are Not verifiable as of 2026‑09‑04. ### Liquidity and listings
  • DEX/CEX liquidity: ENA and USDe are listed on major centralized exchanges and have deep liquidity in leading DEX pools (Ethereum), often paired with USDT/USDC and ETH. Exact pool depths and pair composition are Not verifiable as of 2026‑09‑04.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Ethena USDe, a bitcoin drop below $10,000 is best interpreted as a *stress test for the hedging book*, not as a direct loss of backing assets from the BTC move itself. Ethena’s own scenario analysis states that when BTC falls from the level at which USDe was minted, the short derivatives positions generate unrealized profits in BTC and USDT, and the protocol does not sell or reduce backing assets as BTC declines. The main implication is that a deeper BTC drawdown generally increases the unrealized profit component of the hedge, so the BTC leg alone is not the primary threat to USDe stability.

The more material risks are *exchange/custody failure*, *negative funding rates*, and *redemption pressure* that can deplete reserves or force disorderly unwinds; third-party risk analyses and governance discussions describe depeg risk in those terms rather than from BTC spot losses alone. A BTC crash to under $10,000 could still matter indirectly if it coincides with broader market stress, because prior selloffs have triggered heavy redemptions and temporary secondary-market dislocations even when on-chain backing remained intact. In other words, the stress path is: BTC collapse → market-wide deleveraging → worse funding/venue risk → higher redemption pressure → potential USDe market dislocation.

What is not verifiable as of 2026-09-04 from the provided sources is a protocol-specific threshold showing that BTC below $10,000 by itself breaks USDe’s peg or exhausts reserves. The available evidence instead supports the opposite: the BTC leg is hedged, while the dangerous failure modes are funding, venue, and liquidity shocks.

Evidence (7)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg in Ethena’s largest collateral asset would be a severe solvency stress, but the exact loss to USDe backing is not verifiable as of 2026-09-04 from the available sources because I do not have a chain-level collateral composition snapshot here. Ethena’s disclosed risk framework says USDe is backed by a mix that can include spot crypto collateral, staking assets, and hedges, and that its reserve fund is intended to absorb losses from exchange/custodian failures and other dislocations. The closest directly relevant stress result in the sources is a scenario where a major collateral leg depegs 20% to $0.80, producing a 20% collateral shortfall on the affected position in the illustrative example.

Separately, Ethena-focused risk analyses state that once losses exceed the reserve fund, the deficit begins to erode effective backing and can ultimately threaten the peg or solvency if the shock is large enough. For a practical risk read-through, the impact depends on three things that are not verifiable as of 2026-09-04 here: the share of total backing in the largest collateral asset, whether the asset is used as spot collateral or as margin for short hedges, and whether the reserve fund plus realized hedge PnL can fully offset the mark-to-market loss. If the largest collateral represented a material share of backing, a 20% depeg would directly transmit into an undercollateralization gap; if it were a smaller sleeve, the system-level effect could be partially or fully absorbed by reserves and hedges.

So the defensible conclusion is: a 20% depeg of the largest collateral would likely create a meaningful but unquantified loss to USDe backing, with the reserve fund and hedges determining whether it stays contained or becomes a peg event.

Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

If Ethena’s top hedge counterparty/exchange becomes insolvent, the immediate loss path is the unrealized PnL or margin value tied to open short-perpetual positions; Ethena says backing assets are kept off-exchange via OES providers, so the main exposure is the position-side PnL, not custody of the collateral itself. The first absorber is Ethena’s reserve fund, which is explicitly described as a first-loss buffer for exchange-failure and negative-funding shocks. If losses exceed the reserve, the remaining deficit falls on USDe backing, reducing effective collateralization; Ethena then replenishes the buffer from future protocol revenue, but if the deficit is large enough, USDe peg support and sUSDe yield can weaken.

Compensation works in layers: Ethena aims to retain control of assets and continue mint/redeem operations after an exchange failure, rather than having funds trapped in the failed venue. In practice, Ethena can undelegate to another venue and re-hedge; the realized or recoverable PnL is used to restore the hedge book, while the reserve fund covers shortfalls during the transition. If a venue failure coincides with a sharp market move, any additional directional exposure during the re-hedge window can create further loss, which again is borne first by the reserve and then by USDe backing.

The smart-contract impact path is mostly indirect: the core contracts continue to support mint/redemptions, but the economic assets feeding them are impaired off-chain at the exchange/custodian layer. That means the protocol contracts do not “absorb” the insolvency themselves; instead, the impairment propagates into the backing pool, and only if losses become large enough does it reach user-facing effects such as lower reserve coverage, weaker sUSDe yield, and in an extreme case peg stress for USDe. Not verifiable as of 2026-09-04: the exact current reserve-fund size and the precise loss allocation waterfall for the latest venue set are not confirmed from on-chain data in this run.

Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For a committed-fraud-by-the-DAO/owners stress case, the relevant risk is not a public “DAO fraud” event, but centralized control or key compromise enabling unauthorized minting, redemption abuse, or malicious parameter changes. Ethena’s own technical docs and prior audit materials state that the MINTER/REDEEMER design can mint USDe and that, if a hot key were compromised, an attacker could mint large amounts of unbacked USDe and dump it; Ethena says this was mitigated by on-chain limits and GATEKEEPER controls, but that still establishes a governance/operator abuse surface. The docs also state that Ethena BVI does not have the ability or obligation to prevent or mitigate issues on supported blockchains, which means protocol users bear chain-level and operational risk if insiders act maliciously or controls fail.

Independent security-review material adds that the StakedUSDe owner can blacklist addresses and redistribute locked amounts, showing meaningful admin power over user balances even if that is intended for compliance/risk control. Ethena’s public audit summary also reports multiple issues in role design and protocol invariants, reinforcing that privileged roles are a material trust assumption rather than a purely credibly-neutral system. I did not find evidence of an actual committed-fraud event by Ethena DAO/owners.

The closest confirmed external action is BaFin’s 2025 order for Ethena GmbH to wind up a business subject to authorization requirements, but that is a regulatory action and not proof of fraud by the DAO or protocol owners. So the stress-scenario assessment is: high severity if insiders act maliciously, because the design includes privileged mint/burn/admin capabilities, but no verified committed fraud event is available in the supplied sources as of 2026-09-04.

Evidence (7)

stress scenario - primary yield source negative 30d,

two sources

For Ethena USDe on Ethereum, a negative 30-day primary yield source means the protocol’s main revenue leg—perpetual futures funding—would be a cost rather than income if funding stays negative for the full window. In that stress case, the yield stack would likely compress toward the non-funding components only: ETH staking yield on collateral and any reserve/insurance buffer support. Multiple sources agree that Ethena’s yield model depends primarily on perp funding, with staking as a secondary source and reserve funds used to absorb short-term negative funding.

The practical stress implication is:

  • sUSDe APY would fall sharply, potentially toward zero if negative funding persists long enough.
  • The reserve fund would be drawn down to cover the funding shortfall.
  • If the negative regime is prolonged enough to exhaust the reserve, sUSDe yield can turn negative and redemption pressure may increase. For Ethena specifically, the May 2026 governance update says sUSDe’s 30-day moving average APY was around 4.0% in normal conditions, with basis trading positions only a secondary contributor relative to DeFi lending and other collateral yield sources. That implies the negative-funding stress test is materially about whether collateral yield plus reserves can offset the funding drag. The exact 30-day loss magnitude is Not verifiable as of 2026-09-04 because on-chain exposure, current reserve balance, and live funding rates could not be verified here.
Evidence (6)

Governance & Legal

governance

unverified

Assessment — as of September 13, 2026: Ethena/USDe is foundation/company-controlled with partial DAO signaling, not a fully empowered DAO. ENA governance is primarily off-chain Snapshot voting; most protocol decisions are delegated to committees, and Ethena states fully on-chain governance is currently impractical. ENA holders mainly elect Risk Committee members; nominees are screened by the Ethena Foundation before the broad vote. Control surface: Ethena Foundation and affiliates maintain the frontend and off-chain infrastructure.

Ethena OpCo Ltd., described as a wholly owned Foundation subsidiary, manages ENA distributions and rewards. Smart-contract ownership and privileged protocol roles are controlled by Ethena-organized multisigs. Powers/risk: The protocol DEFAULT_ADMIN_ROLE can change mint/redeem limits, supported assets, custodians, and other privileged roles. Minter roles can mint USDe and transfer assets from the minting contract to approved custodians; gatekeepers can emergency-disable minting/redemption or remove minter/redeemer roles.

This creates material non-DAO operational control. Timelock/multisigs: Documentation states a 7-day timelock for core-function changes. Current key-address documentation lists: Dev Safe 5/11, sUSDe Payout Fund 3/11, and Reserve Fund 4/10. Older documentation conflicts, describing a 7/10 or 7-signature protocol multisig.

Signer identities, independence, and current Safe configuration were not independently verified here. > Contradiction: Ethena’s older security documentation says 7/10 or seven signatures, while the newer key-address page says 5/11, 3/11, and 4/10 for distinct wallets. The newer page is treated as current, but the exact control mapping remains unclear. Holder concentration/top holders via Dune: Not verifiable as of September 13, 2026. Directors and Foundation/company registration details: Ethena BVI Limited, BVI, registration 2127704; directors are Not verifiable as of September 13, 2026.

Timelock
Yes
Timelock delay hours
168
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (6)

legal & regulatory

two sources

Legal/regulatory assessment (as of September 4, 2026):

  • Entity/jurisdiction: USDe outside the EEA is contractually issued/redeemed by Ethena BVI Limited, BVI company no. 2127704, Tortola, British Virgin Islands. EEA issuance was assigned to Ethena GmbH (Germany); Ethena Labs S.A. is the Portugal-based parent/developer, while the Ethena Foundation is a separate Cayman Islands exempted foundation company supporting protocol architecture.
  • Terms/restrictions: Users must be 18+, in a supported jurisdiction, comply with AML/CTF and sanctions laws, and not be sanctioned persons, residents of restricted territories, or involved in prohibited/illegal activity. US residents are expressly ineligible to become direct Mint Users; direct minting/redemption requires KYC/KYB, AML checks and whitelisting. Secondary-market holding is contractually distinguished from being an Ethena customer.
  • Classification: Ethena describes USDe as synthetic dollar/stored value or prepaid access, not an equity, participation interest or claim on Ethena. That characterization is not universally determinative: EU treatment identified USDe as an MiCA asset-referenced-token issue, while US legal classification remains fact- and jurisdiction-dependent. USDe is not a bank deposit and has no FDIC/SIPC or comparable insurance.
  • Warnings/enforcement: BaFin ordered Ethena GmbH to wind up its USDe business on June 25, 2025, with a redemption process for holders. This is direct regulatory action against an Ethena issuing entity and is the key adverse precedent.
  • KYC/AML/data protection: Ethena states it performs KYC/AML/CTF, sanctions screening, suspicious-activity reporting and blocking. Its privacy policy claims GDPR/CCPA rights and permits disclosure to KYC providers, advisers and affiliates; cross-border data transfer and insolvency-sale provisions remain material privacy risks.
  • Court cases/sanctions: No reliable public court case or sanctions designation of Ethena BVI, Ethena GmbH, Ethena Labs S.A. or the Foundation was located. Not verifiable as of September 4, 2026. Compliance blocking of sanctioned wallets is not itself a sanctions designation.
  • Legal structure vs actual risk: Offshore issuance, separate foundation governance and contractual disclaimers may limit direct recourse, but do not eliminate regulatory perimeter, insolvency, redemption, cross-border enforcement or reclassification risk. The BaFin action demonstrates that entity segregation does not prevent regulator intervention. Structured fields:
  • active_enforcement: true
  • sanctioned: false
  • entity: Ethena BVI Limited; Ethena GmbH (EEA issuer); Ethena Labs S.A.; Ethena Foundation
  • jurisdiction: British Virgin Islands; Germany; Portugal; Cayman Islands
Active enforcement
Yes
Sanctioned
No
Entity
Ethena BVI Limited; Ethena GmbH; Ethena Labs S.A.; Ethena Foundation
Jurisdiction
British Virgin Islands; Germany; Portugal; Cayman Islands
Evidence (6)

legal registries

two sources

Legal entity per GLEIF: Ethena (BVI) Limited (LEI 984500V3A60AFE7F7859; jurisdiction VG; registration ACTIVE). OFAC SDN screening of 'Ethena BVI Limited', 'Ethena GmbH', 'Ethena Labs S.A', 'Ethena USDe': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Ethena BVI Limited
  • Ethena GmbH
  • Ethena Labs S.A
  • Ethena USDe
Entity
Ethena (BVI) Limited
LEI
984500V3A60AFE7F7859
Jurisdiction
VG
Entity status
ACTIVE
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Ethena USDe does issue its own stablecoin/synthetic dollar, and it is best classified as stable overall. The source set documents at least two depeg episodes: a launch-period low of $0.9773 on 2024-02-19 and a sharper event on 2025-10-11 when USDe briefly traded at $0.65 on Binance. That makes the maximum observed depeg about 35.0% below $1.00, with the last documented depeg date on 2025-10-11.

A complete historical depeg count is not fully verifiable from the available web sources, but the documented count is at least 2.

Own stablecoin
Yes
Stable
Yes
Depeg count
2
Max depeg pct
35%
Last depeg date
2025-10-11
Stablecoin ids
  • 4133
Evidence (3)

Risks & Strengths

risks

two sources

USDe is a synthetic dollar whose stability depends on delta-neutral derivatives, exchange/custody infrastructure, liquid backing, and smart-contract execution—not solely on fiat reserves. The ranking is qualitative; Ethereum on-chain balances, counterparty concentration, reserve coverage, and current liquidation buffers are Not verifiable as of September 5, 2026 because Dune MCP is unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Negative funding-rate regimeUSDe’s hedge can generate persistent losses instead of income. A prolonged inversion consumes reserve capital, weakens sUSDe economics, and can pressure redemptions or the peg.HighHighReserve fund; diversified funding venues; LST yield and liquid-stable allocations; dynamic backing allocation.High: reserve coverage and current funding exposure are Not verifiable as of September 5, 2026.
Exchange and custody failureExchange insolvency, custodian failure, settlement delays, or operational outages could make hedge PnL or collateral temporarily inaccessible and impair minting, redemption, or rebalancing.HighMediumOff-exchange settlement, segregated/bankruptcy-remote custody structures, multiple providers, frequent PnL settlement, and concentration controls.High: legal enforceability, real-time exposure, and provider concentration are Not verifiable as of September 5, 2026.
Liquidity and peg dislocationUSDe can trade below $1, particularly during rapid redemptions, thin secondary liquidity, collateral stress, or delayed authorized-participant activity; terms provide no permanent third-party price guarantee.HighMediumMint/redeem functionality for approved users, reserve-fund backstop, liquidity monitoring, and slippage/delta limits in the V2 contract.High: retail holders may not have direct, immediate redemption access.
Hedge liquidation and executionExtreme volatility, basis divergence, exchange deleveraging, oracle/price dislocation, or execution slippage could break delta neutrality and crystallize losses before hedges are adjusted.HighMediumLow stated leverage, margin monitoring, exchange diversification, collateral transfers, reserve-fund support, and 24/7 manual intervention.Medium-High: stress-test results and current margin headroom are Not verifiable as of September 5, 2026.
Smart-contract and admin compromiseA contract bug, privileged-key compromise, whitelist failure, or upgrade/configuration error could freeze minting/redemption or misdirect assets. Audits reduce but do not eliminate residual vulnerability.HighLowMultiple audits, multisig-controlled onboarding, configurable stablecoin-delta limits, and contract security reviews.Medium: audit scope, key controls, bounty coverage, and live privileged addresses are Not verifiable as of September 5, 2026.
Evidence (6)

strengths

two sources

Ethena USDe’s top strengths are: capital efficiency, because it uses delta-neutral hedging so USDe does not rely on traditional overcollateralized fiat reserves; yield generation, because reserve assets can earn staking rewards plus perp funding/basis spreads; resilience and peg design, because hedging is intended to offset backing-asset price moves and support stability across market conditions; censorship resistance and onchain accessibility, because USDe is designed as a fully onchain, permissionless synthetic dollar with minimal reliance on banking rails; and broad ecosystem utility, because Ethena is positioned as composable across DeFi and integrated with major venues, which expands collateral utility and adoption.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 31 one source, 7 unverified.
  • Oldest fact verification date: 2026-08-30.