Ondo Yield Assets

Green · 78/100

Executive summary

Ondo Yield Assets is a multi-chain tokenized real-world-asset protocol offering yield-bearing products (USDY, OUSG) backed by U.S. Treasuries and money-market instruments, scoring 68/100 (orange band) with high data confidence (86/100).

  • Security: Extensive multi-firm audit coverage (Code4rena, Cyfrin, Cantina, Spearbit, Halborn, FYEO, Zellic) from 2021–2025; historical findings included 1 critical (Solana program, fixed), multiple high-severity issues (user-fund loss in redemptions, USDC depeg minting risk, Solana attestation flows—most fixed, 2 high in Nov-2025 Solana audit marked Open); bytecode-match to deployed contracts across 10 chains Not verifiable as of Sept 2026; active Immunefi bug bounty up to $1M.
  • Incidents: No protocol-level exploit or user loss verified; Oct-2021 SushiSwap vault swap bug resolved with manual recovery (no user loss); Apr-2026 Drift hack exposed $537k USDY which Ondo froze/preserved (no realized Ondo loss); no depeg events for USDY/OUSG verified.
  • Governance & custody: Primarily company-controlled (Ondo Finance Inc., Ondo Global Markets BVI, Ondo USDY LLC) rather than DAO-governed; ONDO token governs Flux Finance but not core yield products; underlying assets held by regulated institutional custodians in bankruptcy-remote SPVs; exact admin multisig composition, custody allocation, and withdrawal permissions Not verifiable as of Sept 2026.
  • Top risks: (1) Legal/regulatory—USDY relies on Reg S (non-US), OUSG on Reg D 506(c)/qualified purchasers; enforcement or sanctions could freeze access. (2) Counterparty/oracle—NAV depends on off-chain fund administrators, Coinbase custody, BlackRock BUIDL; oracle staleness or admin-key compromise could disrupt redemptions. (3) Centralized admin powers—audits note unrestrained setters, token retrieval, and pause functions; malicious operator could alter behavior or restrict exits. (4) Cross-chain bridge risk—LayerZero OFT with Ondo-operated DVN; unaudited mint or rate-limit bypass possible. (5) Redemption friction—instant flows capped ($50M global daily); non-instant redemptions next-business-day, subject to KYC/eligibility; US persons restricted.
  • Strengths: Institutional-grade structure with daily reserve verification ($2.2B underlying, 105.55% collateralization as of Sept-2026); 24/7 onchain mint/redeem and DeFi composability; broad multichain reach (10 chains); access to organic U.S. Treasury yield (~4–5% historical) rather than subsidized emissions; strong VC backing (Pantera, Founders Fund, Coinbase Ventures); transparent legal framework with Ankura Trust as collateral agent.
  • Unverified: Chain-by-chain contract deployment and bytecode verification; exact custody allocation among Komainu, Zodia, Copper; current admin multisig signers and quorum; fix status for 2 high-severity Solana findings (Nov-2025 FYEO); on-chain exposure and reserve balances per chain (Dune unavailable); whether all announced ONDO token unlocks occurred; DAO proposal activity (conflicting reports of active vs. paused governance).
  • Recommended exposure: Conservative allocation (≤5% of DeFi portfolio) for qualified institutional allocators comfortable with regulatory/legal risk and centralized custody; prioritize Ethereum deployment (most audited); verify KYC/eligibility before commitment; monitor daily reserve reports and redemption queue depth; avoid if exposure to admin-key risk or cross-chain bridge failures is unacceptable; treat as rate-sensitive Treasury proxy, not decentralized stablecoin.
  • Open questions: (1) Confirm bytecode-match for all 10 chains and verify current ProxyAdmin ownership/timelock on each. (2) Obtain current multisig signer list, quorum, and HSM/MPC setup from Ondo. (3) Verify remediation status of Nov-2025 Solana high findings and request post-fix audit. (4) Review Ankura Trust collateral-enforcement procedures and historical response time. (5) Stress-test redemption flow under $500M+ simultaneous exit scenario. (6) Clarify DAO governance status and ONDO token utility for yield products. (7) Confirm current custody allocation and insurance coverage with named custodians.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 25 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-02-01)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 15 3.0 TVL $2,563,086,213 = 15% of reference ($17,538,184,136)
Data confidence 86 7/7 critical categories; 19/59 verified facts; 59/59 fresh (180d)

Identification

protocol identification

two sources

Ondo Yield Assets is Ondo Finance’s RWA/tokenized-yield protocol, with official website ondo.finance and docs at docs.ondo.finance; the docs also expose a contract-address registry. It is described as operating across 10 chains in one independent profile: Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, and XRPL. The native governance token for the broader Ondo ecosystem is ONDO; the yield-assets product itself is centered on assets like USDY and OUSG rather than a separate protocol token.

The most directly identifiable contract/address references found were the Ethereum OFT Adapter 0xa6275720b3fB1Efe3E6EF2b5BF2293148852307D, the Solana OFT Adapter 7YNReenG6AXgVUfmSizt6hoVXrznS4zDdgCj1UTLJ2S3, and the USDon token ZPFtoCe7WWqG4N3ZFRccS8T9SMBeHsd1Vmgv2i7ondo; the docs page is the authoritative source for these addresses, while explorer links are embedded for verification. A second-source cross-check for multi-chain presence is provided by DIA’s protocol profile, which matches the same 10-chain set. Explorer verification status: partially verifiable from the docs-linked explorer destinations, but not fully confirmable here for all chains/addresses without live explorer review.

Launch timing is not cleanly verifiable from the gathered sources for the entire yield-assets protocol as a single release date; the web results only support product milestones such as USDY’s earlier launch and later chain expansions, so the protocol launch date is Not verifiable as of 2026-09-04. On fork lineage, I found no reliable evidence that Ondo Yield Assets is a fork of another protocol. The available material instead frames it as an original Ondo Finance product with omnichain adapters and asset-specific deployments; therefore fork status is not established.

Any claim that it is a fork, or that there was a malicious-modification history comparable to notorious fork incidents, is Not verifiable as of 2026-09-04. I also found an audit reference in secondary sources, but not enough independent audit-report detail in the gathered results to confirm exact scope or whether every chain-specific deployment was covered. Ondo Finance docs, smart contract addresses; DIA protocol profile for Ondo Yield Assets; Ondo docs API reference for contract addresses; Ondo USDY page / timeline snippets; secondary profile noting audits and deployments.

Evidence (5)

maturity

two sources

Ondo Yield Assets looks like a real, live product suite rather than a pure landing page: the official Ondo site and docs describe active mint/redeem flows, onboarding, and direct investment paths, and the site includes product pages for USDY and OUSG rather than only marketing copy. The docs also describe atomic on-chain-style entry/exit mechanics for USDY/OUSG and give explicit minimums, which is a stronger maturity signal than a static brochure. For UX, the public docs are substantial and product-specific, with FAQ/basic/yield pages and separate coverage for qualified-access and general-access products; that said, the discovered pages do not confirm a fully self-serve flow for every network in the slug.

The USDY page explicitly says mint/redeem on Sui, Aptos, Stellar, XRP, Noble, or Tempo requires contacting support, which suggests some chains are operational but not fully self-serve in the public UI. Open API: yes, there is a documented Yield API surface exposed by docs.yield.xyz, including integration IDs and methods such as getStakeArguments and atomic subscribe/redeem flows. That is a clear sign of an open developer API, though it is documented under a third-party integration/docs domain rather than presented as a consumer-facing public API on the main marketing site.

Broken links, fake metrics, and template signs: not verifiable as of 2026-09-04. The available pages do not provide enough evidence to confirm widespread broken links or template-site artifacts, and no on-chain validation was possible in this run. Overall: high product maturity, real portal, documented API, and mixed self-serve availability by chain; full live deposit/withdraw status across all listed chains is not verifiable as of 2026-09-04.

Evidence (6)

Security

bug bounty

two sources

Ondo Finance has an active bug bounty program on Immunefi. It was live since 07 March 2023. The program requires KYC and a proof of concept for reports, and rewards are tied to Immunefi’s severity classification system.

Critical smart-contract bugs can earn 10% of directly affected funds up to $1,000,000, with a minimum of $50,000; high-severity vulnerabilities involving theft or permanent freezing of unclaimed yield/royalties are rewarded from $11,000 to $50,000. The scope page also shows expanding multi-chain coverage across Ondo assets and contracts. Publicly visible program records do not show a separate disclosed tally of paid-out results in the retrieved sources.

A 2022 social post mentioned a $250,000 bug bounty then, which is a contradiction with the later Immunefi live program details and should be treated as an earlier or superseded arrangement rather than the current program.

Active
Yes
Platform
Immunefi
Max payout
$1.0M
Since
2023-03-07
Evidence (3)

counterparty risks

one source

Assessment (as of September 6, 2026): No currently active protocol failure was identified. Ondo’s status page reports all services online; a July 12–13, 2026 upstream-vendor incident affected GM trading, not evidence of USDY/OUSG loss. Primary counterparties: OUSG depends on off-chain NAV calculation, fund administrators/custodians, Coinbase for USDC settlement/custody, and underlying funds including BlackRock BUIDL plus Fidelity, Franklin Templeton and WisdomTree products. USDY is issued through a bankruptcy-remote SPV and invests in U.S.

Treasuries and bank demand deposits; default/redemption failure is intended to trigger Ankura Trust collateral enforcement and liquidation. These protections are primarily protocol/legal-document claims and are not independently verified here. Oracle/manipulation risk: USDY uses an on-chain dynamic redemption-price oracle populated from configured rates; OUSG NAV is updated off-chain and published on-chain. Historical audit findings identified oracle staleness, SHV/NAV basis risk, and USDC-depeg risk; Ondo states the USDC issue was mitigated with a Chainlink USDC/USD check that pauses minting/redemptions below a threshold.

Administrative control, stale data, incorrect NAV, or compromised update keys remain material risks. Bridges and chain dependencies: USDY’s current Ondo Bridge uses LayerZero OFT, Canary DVN, LayerZero DVN and an Ondo-operated DVN, with per-pathway rate limits. This reduces unaudited mint risk but creates dependency on LayerZero, DVN/RPC infrastructure and Ondo’s own verifier; the proprietary DVN is a concentration point. Documented bridge support is Ethereum, Arbitrum, Mantle and Solana, while the broader ecosystem lists additional deployments/integrations. Scenario analysis: Likely loss paths are delayed/blocked redemption, USDC or bank-deposit depeg, custodian/issuer insolvency or operational failure, stale/manipulated NAV, and cross-chain supply divergence.

No LST/restaking dependency was identified. CEX/market-maker exposure beyond Coinbase-related settlement is Not verifiable as of September 6, 2026. Chain-level exposure percentages and maximum counterparty concentration are Not verifiable as of September 6, 2026 because Dune/on-chain verification was unavailable. > Contradiction / data gap: Broad multi-chain availability is marketed, but verified bridge coverage is narrower; the difference is not quantifiable without on-chain analysis.

Dependency failure active
No
Evidence (4)

crypto custody

two sources

Ondo Yield Assets use a layered custody model: the underlying backing assets are held off-chain by regulated institutional custodians and fund managers, while users hold on-chain tokens that represent economic exposure rather than direct legal title to the assets. Public materials also describe the structure as bankruptcy-remote, with assets of the issuing vehicle held separate from Ondo and its affiliates, including Ondo USDY LLC for USDY. Independent materials further state that custody is segregated from the custodian’s proprietary assets and other customers’ assets, but a complete protocol-wide, chain-by-chain custody map is not verifiable as of 2026-09-06 from the available evidence.

Withdrawal status is not verifiable as of 2026-09-06.

Evidence (6)

incident

unverified

On October 28, 2021, a bug in Ondo’s SushiSwap vault strategy reversed reward-token swaps, exchanging approximately 387 ETH for 118,474 CVX and 542 ETH for 236,601 YGG. The affected vaults were ETH/CVX and ETH/YGG. Ondo manually sold the mistakenly acquired tokens for approximately 1,053 ETH, covering approximately 936 ETH owed to depositors; it stated customer principal remained safe and planned manual distribution of reward tokens and excess ETH.

Response/fix: guardian-admin actions, manual asset rescue, redemption support, expanded testing, and migration of sensitive admin functions to a 3-of-5 multisig. No attacker or realized user/protocol loss was reported. Status: resolved.

No reimbursement was required; depositors were made whole through the recovery/distribution process.

Date
2021-10-28
Cause
Other
Loss
$0
Attacker proceeds
$0
Status
resolved
Recovered
$0
Reimbursed
Yes
Event id
ondo-2021-sushiswap-vault-swap-bug
Evidence (1)

incident

one source

On April 1, 2026, Drift Protocol on Solana suffered an administrative-control compromise involving social engineering and pre-signed Solana durable-nonce transactions. Drift’s recovery report listed 477,375.42 USDY worth $536,721.64 among assets extracted from Drift. Ondo paused USDY transfers where appropriate and froze the attacker-held USDY.

The USDY exposure was therefore contained: no realized loss to Ondo Yield Assets users or the protocol is evidenced, and the frozen amount was preserved rather than paid out as attacker proceeds. Response/fix: blocklisting/freezing, targeted pauses, continuous monitoring, isolated signing infrastructure, clearer transaction signing, and timelocks for administrative actions. Status: resolved for Ondo’s USDY exposure; Drift-wide recovery remained under a recovery framework, and its status after the April 16, 2026 update is Not verifiable as of September 6, 2026.

Users were not reimbursed because the USDY was frozen/preserved and no realized USDY loss is evidenced.

Date
2026-04-01
Cause
Key compromise
Loss
$0
Attacker proceeds
$0
Status
resolved
Recovered
$537K
Reimbursed
No
Event id
ondo-usdy-drift-2026-04-01
Evidence (3)

incident

one source

No clearly attributable protocol-level exploit, hack, or depeg incident was verifiable from the gathered sources for Ondo Yield Assets since launch. The main security disclosure available is a 2026 Ondo post describing a paused/frozen response during a broader attack context and a plan to expand the bug bounty, but it does not establish a user-loss incident for the yield assets themselves.

Date
2026-04-23
Cause
Other
Evidence (1)

incident

two sources

Key-person risk is present and likely elevated because the structure depends on off-chain legal entities, custodians, and admin/security operations, but a definitive list of key holders or succession controls was not verifiable. An independent media result explicitly framed Ondo as facing succession/keyholder challenges, but that is commentary rather than an audited control assessment.

Date
2026-08-11
Cause
Other
Evidence (2)

incident

one source

Bug bounty exists and is public. Immunefi lists Ondo Finance bug bounties with rewards of 10% of directly affected funds up to a cap; another independent security page says Ondo also publishes a vulnerability disclosure policy. Exact current cap and scope should be treated as stale if used for a formal risk memo, but the existence of a bounty program is verifiable.

Date
2026-08-19
Cause
Other
Evidence (2)

incident

two sources

Key management and custody are materially centralized off-chain. Gathered sources indicate Ondo relies on regulated custodians and institutional asset managers for underlying assets, and an independent search result notes SPV-style legal segregation. However, the exact operational key hierarchy, signer quorum, HSM/MPC setup, and incident-breakglass controls were not verifiable from the gathered sources.

Date
2026-09-02
Cause
Other
Evidence (2)

key management

unverified

Ondo Yield Assets appears to use a hybrid key-management model rather than a fully decentralized signer set. On the product side, the tokenized assets are administered through smart contracts with compliance, custody, audit, and access controls, while the underlying assets are held by third-party custodians and a regulated vehicle structure. For USDY specifically, transfer restrictions are enforced by allowlist, blocklist, and sanctions-list contracts, so operational control is split across on-chain policy contracts and off-chain identity/compliance systems.

For the protocol’s core vault architecture, Ondo’s published code shows a role-based access-control design: the repository notes that there are 9 defined access-control roles, and that a strategist can call migration functions in managed vault workflows. That indicates key management is organized around permissioned operator roles for vault administration, not around broad public signer participation. Across chains, the available sources describe Ondo’s products as working via cross-chain issuance and administration, but they do not provide enough detail to verify whether the same keyset, multisig, or separate chain-specific administrators control contracts on Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, and XRPL. Not verifiable as of 2026-09-04 whether key management is uniform or chain-specific across those networks.

In practical risk terms, the organization appears to be: contract-layer controls for mint/redeem/transfer policy, off-chain custodians for reserve assets, and restricted internal roles for operations and upgrades.

Evidence (5)

smart-contract

one source

As of September 6, 2026: Dune MCP was unavailable, so proxy-admin ownership, decoded admin events, role membership, renouncement, timelock delay, and current pause state are Not verifiable as of September 6, 2026. No on-chain query ID/execution ID is available. Verified address references (protocol documentation; not independently on-chain verified): Ethereum USDY 0x96F6eF951840721AdBF46Ac996b59E0235CB985C; Ethereum rUSDY 0xaf37c1167910ebC994e266949387d2c7C326b879; Ethereum USDY_InstantManager 0xa42613C243b67BF6194Ac327795b926B4b491f15; Ethereum oracle wrapper 0x87b126e5518b6a1Bb8465779b4607C45C643DF90; Ethereum blocklist 0xd8c8174691d936E2C80114EC449037b13421B0a8; Arbitrum USDY 0x35e050d3C0eC2d29D269a8EcEa763a183bDF9A9D; Mantle USDY 0x5bE26527e817998A7206475496fDE1E68957c5A6. Architecture: User → USDY/rUSDY proxy → implementation; ProxyAdmin → proxy upgrade; USDY/rUSDY → allowlist + blocklist + sanctions checks; InstantManager/Manager → subscribe/redeem → oracle + fee + registry + custodian/redemption rails. Ondo’s repository explicitly documents EIP-1967 Transparent Upgradeable Proxies, separate ProxyAdmin contracts, upgradeable allowlists, and owner-controlled blocklists. Privileged capabilities: the published ABI exposes role-controlled pause/unpause for subscriptions and redemptions; oracle, fee, registry, router, rate-limiter, accepted-token, minimum-amount, and admin-subscription configuration; token-retrieval functionality; and role grant/revoke/renounce functions.

A compromised upgrade/admin path could replace implementations, alter pricing/compliance/fees, freeze transfers or redemptions, blacklist holders, or introduce arbitrary minting/drain logic. The instant manager also includes administrative subscription and token-retrieval functions. Exit/rug assessment: users may have a code-level redeem path, but access is permissioned and redemptions depend on pausing, eligibility, oracle, liquidity/custodian, and off-chain settlement. Admin-controlled upgrades and blocklisting create material freeze and governance risk.

Direct admin drainage authority, exact timelock protection, and whether all users can exit without administrator cooperation are Not verifiable as of September 6, 2026. Audits are documented for USDY/Ethereum and related Ondo Funds deployments; deployment-to-audit matching and current unresolved severity status are not fully independently verified.

Admin can drain
Yes
Audited deployment
Yes
Upgradeable
Yes
Evidence (5)

audit

one source

Smart contracts for early Ondo Protocol (Ethereum).

Auditor
CertiK
Report date
2021-04-19
Scope
Ondo Protocol Solidity smart contracts (early Ethereum deployment; tranche tokens and UniswapStrategy, not chain‑specific to later Arbitrum/Mantle/etc.). Coverage of currently deployed Ondo Yield Assets contracts on listed chains: Not verifiable as of 2026-09-03 (no bytecode‑match data available).
Findings
April 12–19, 2021 audit of Ondo Protocol smart contracts. - Total issues: 27.[5] - Critical: 0.[5] - Major: 0.[5] - Medium: 4 (e.g., missing zero‑address checks on initializers; exposure of Uniswap interactions to potential sandwich attacks).[5] - Low/minor and informational issues: remainder, including missing noPanic checks in certain token functions and incorrect handling of excess tokens in UniswapStrategy.[5]
Fix status
Report describes issues and recommendations but does not explicitly confirm all fixes; current fix status and bytecode match to deployed contracts: Not verifiable as of 2026-09-03.
Evidence (1)

audit

one source

Auditor: Code4rena; publication: January 2023; scope: Ondo V2 CASH and related contracts. Findings: 1 high, 5 medium, 54 low/non-critical, 24 gas. High: user-fund loss in CASH redemptions. Fix status: report-level remediation status not verified. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Code4rena
Report date
2023-01
Scope
Ethereum CASH/Ondo V2 contracts
Findings
1 high, 5 medium, 54 low/non-critical, 24 gas
Fix status
Not verifiable as of September 5, 2026.
Evidence (1)

audit

one source

Ondo Finance smart contract system in Solidity (competitive audit).

Auditor
Code4rena
Report date
2023-09-07
Scope
Ondo Finance Solidity system (Ethereum). Exact contract list in contest README; mapping to current Ondo Yield Assets contracts across chains Not verifiable as of 2026-09-04.
Findings
4 unique vulnerabilities, all medium severity; 34 low/non‑critical issues; 21 gas optimization reports.[10] No critical/high issues reported.[10]
Fix status
Code4rena report does not itself certify fixes; post‑contest remediation Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Auditor: Code4rena; publication: September 2023; scope: Ondo Ethereum contracts. Findings: 0 critical/high, 4 medium, 34 low/non-critical, 21 gas. Fix status: report-level remediation status not verified. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Code4rena
Report date
2023-09
Scope
Ethereum Ondo contracts
Findings
0 critical, 0 high, 4 medium, 34 low/non-critical, 21 gas
Fix status
Not verifiable as of September 5, 2026.
Evidence (1)

audit

one source

Auditor: Code4rena; publication: April 2024; scope: OUSG/OUSGInstantManager. Findings: 1 high, 4 medium, plus 64 low/non-critical. High: excessive OUSG minting during USDC depeg. Fix status: report-level remediation status not verified. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Code4rena
Report date
2024-04
Scope
Ethereum OUSG/OUSGInstantManager
Findings
1 high, 4 medium, 64 low/non-critical
Fix status
Not verifiable as of September 5, 2026.
Evidence (1)

audit

two sources

Security review of Ondo Finance Solidity smart contract system, categorized under Ondo funds/USDY on Ethereum rather than specifically branded as "Ondo Yield Assets". The contest report states 4 unique vulnerabilities of medium severity, 34 low/non‑critical issues, plus 21 gas‑optimization reports. The public report notes issue findings but does not itself assert whether fixes were deployed; subsequent ecosystem‑wide audit meta‑reviews describe this work as part of a multi‑firm coverage across Ondo Global Markets and USDY.

Bytecode‑match to currently deployed Ondo Yield Assets contracts is Not verifiable as of 2026-08-30.

Auditor
Code4rena (audit contest)
Report date
2023-09-07
Scope
Ondo Finance Solidity contracts (funds/USDY on Ethereum; not chain‑specific to Arbitrum, Mantle, Noble, etc.)
Evidence (2)

audit

two sources

Ondo Finance smart contracts, primarily Funds and USDY on Ethereum plus bridge/instant manager components over time.

Auditor
Code4rena (C4)
Report date
2023-01-06
Scope
Ethereum-based Ondo Funds & USDY contracts; bridge infrastructure; OUSG/rOUSG managers and related tokens. These audits primarily cover Ethereum smart contracts; coverage of implementations on Arbitrum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL (if any) and whether they reuse identical bytecode is Not verifiable as of 2026-09-03.
Findings
Multiple competitive audits: 1) January 2023 contest (Ondo Funds & USDY, Ethereum): aggregated 6 unique vulnerabilities — 1 HIGH, 5 MEDIUM, plus 54 LOW/non‑critical and 24 gas optimizations.[6] 2) September 1–7, 2023 contest (bridge infrastructure including DestinationBridge.sol): 4 unique vulnerabilities, all MEDIUM; plus 34 LOW/non‑critical and 21 gas optimizations.[9][7] 3) March–April 2024 contest (OUSG/bUIDL/rOUSG stack): scope included ousgInstantManager.sol, rOUSG.sol, rOUSGFactory.sol, with tokens BUIDL, USDC, OUSG, rOUSG in scope; detailed findings hosted in separate findings repo.[11][12][15] Severity distribution in that round: Not verifiable as of 2026-09-03 (summary counts not in retrieved snippet).
Fix status
C4 contests normally require sponsor triage and responses, and a findings repo exists for 2024 round,[15] but explicit confirmation that all HIGH/MEDIUM issues are fixed and that audited code exactly matches currently deployed bytecode across Ethereum/Arbitrum/Mantle/Noble/Osmosis/Sei/Solana/Stellar/Sui/XRPL is Not verifiable as of 2026-09-03.
Evidence (5)

audit

one source

Auditor: Cyfrin; publication: April 18, 2024; scope: OUSG, rOUSG, OUSGInstantManager and rate limiters. Findings: 0 critical/high/medium, 7 low, 7 informational, 10 gas. Fix status: all low findings mitigated; informational/gas items mixed resolved/acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Cyfrin
Report date
2024-04-18
Scope
Ethereum OUSG/rOUSG and managers
Findings
0 critical, 0 high, 0 medium, 7 low, 7 informational, 10 gas
Fix status
All low findings mitigated; remaining items mixed resolved/acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.
Evidence (1)

audit

one source

Ondo Global Markets smart contracts v2.0 (includes USDon) – protocol powering tokenised yield products used by Ondo Yield Assets.

Auditor
Cyfrin
Report date
2025-07-14
Scope
Ondo Global Markets v2.0 smart contracts on Ethereum and potentially other EVM chains, including USDon mint/redeem and transfer compliance logic.[14] Whether bytecode exactly matches currently deployed Ondo Yield Assets contracts on each chain Not verifiable as of 2026-09-04.
Findings
12 issues total; report text highlights 2 low‑severity issues: missing role grant during USDon deployment; discrepancy between compliance checks for mint/redeem vs transfers.[14] Full severity distribution Not verifiable as of 2026-09-04.
Fix status
The report narrative suggests issues were reported for remediation, but explicit final fix status per issue Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Newly verified published report.

Auditor
Spearbit
Report date
2025-06-17
Scope
Ondo RWA Internal / Global Markets, commit 88353254.
Findings
0 critical, 0 high, 2 medium, 2 low, 3 informational.
Fix status
6 fixed; 1 acknowledged.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/report-cantinacode-ondo-0224-2.pdf
Report id
doc:15f73eef3752f92f
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified published report.

Auditor
Cantina
Report date
2025-12-06
Scope
Global Markets limit-order protocol, commit 0e8bc196.
Findings
0 critical, 0 high, 0 medium, 0 low, 1 informational, 4 gas optimizations.
Fix status
All 5 findings fixed; fixes verified.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/GM-LimitOrder-Protocol-Cantina-12-02-2025.pdf
Report id
doc:3b19f7fb2c56ab46
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified published report.

Auditor
FYEO
Report date
2025-09-08
Scope
Ondo Solana program updates: whitelist/blocklist, sanity checks and role code.
Findings
0 critical, 0 high, 1 medium, 0 low, 1 informational.
Fix status
Both findings marked Open.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/GM-Solana-FEYO-09-08-2025.pdf
Report id
doc:78d84cc442cf4599
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified published report.

Auditor
Cantina
Report date
2025-10-09
Scope
Ondo BridgeRegistrar.sol and USDonConverter.sol, commit 18afc35a.
Findings
0 critical, 0 high, 1 medium, 2 low, 5 informational.
Fix status
7 fixed; 1 acknowledged.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/GM-USDonConverter-BridgeRegistrar-Cantina-10-06-2025.pdf
Report id
doc:91eebf565721a83e
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified published report.

Auditor
Cantina
Report date
2025-11-21
Scope
SyntheticSharesOracle.sol and related tests, commit c79a762e.
Findings
0 critical, 0 high, 0 medium, 1 low, 4 informational.
Fix status
2 fixed; 3 acknowledged.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/GM-SyntheticShares-Cantina-11-18-2025.pdf
Report id
doc:9e8013d3fb6748f1
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified published report.

Auditor
Cantina
Report date
2025-12-18
Scope
Ondo GM Solana program, commit 3f96676f.
Findings
1 critical, 4 high, 8 medium, 30 low, 16 informational.
Fix status
58 fixed; 1 acknowledged.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/report-cantinacode-ondo-1121.pdf
Report id
doc:bad9d7b5c690336b
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified published report.

Auditor
FYEO
Report date
2025-11-05
Scope
Ondo Solana program updates, including attestation-based mint/burn flows and rate limits.
Findings
0 critical, 2 high, 0 medium, 2 low, 2 informational.
Fix status
All six findings marked Open.
Report url
https://docs-v2-git-prod-ondo-docs.vercel.app/pdf/GM-Solana-FYEO-11-05-2025.pdf
Report id
doc:c860d452ffe6284a
Covers deployed code
No
Unresolved critical
0
Unresolved high
2
Evidence (1)

audit

one source

Community smart‑contract audit of a specific Ondo Solidity contract on Ethereum, dated April 18, 2024 (audit work performed May 18, 2024). Scope is one contract linked to ondo.finance, not the full Ondo Yield Assets cross‑chain stack. Findings: 0 critical, 0 high, 0 medium, 0 low, 2 very low issues.

Overall assessment marked contracts as "Secured" with owner‑control present. Fix status: report does not clearly state whether very‑low issues were remediated; current deployment bytecode equivalence is Not verifiable as of 2026-08-30.

Auditor
EtherAuthority
Report date
2024-04-18
Scope
Single Ondo Solidity contract (Ethereum), community audit
Evidence (1)

audit

one source

Community smart‑contracts audit for Ondo smart contract from ondo.finance.

Auditor
EtherAuthority
Report date
2024-05-18
Scope
Specific Ondo contract(s) audited April–May 2024, likely Ethereum.[9] Coverage of all Ondo Yield Assets contracts across Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL Not verifiable as of 2026-09-04.
Findings
0 critical, 0 high, 0 medium, 0 low; 2 very‑low‑level issues identified.[9]
Fix status
Report indicates no meaningful vulnerabilities; handling of 2 very‑low issues Not verifiable as of 2026-09-04.
Evidence (1)

audit

two sources

Ondo Funds and USDY on Ethereum and Noble chains; additional Aura module.

Auditor
Halborn
Report date
2024-07-01
Scope
Funds & USDY on Ethereum; additional Aura module and USDY/Funds on Noble.[1][3] Multi-chain coverage beyond Noble (e.g., Arbitrum, Mantle, Osmosis, Sei, Solana, Stellar, Sui, XRPL) cannot be confirmed from available data: Not verifiable as of 2026-09-03.
Findings
Specific issue counts and severities for Halborn’s Ondo audits are not in the retrieved snippets; only that audits exist for Funds & USDY (Ethereum) from 2023–2025 and an additional module on Noble (June–July 2024).[1][3][4] Therefore detailed critical/high/medium breakdown: Not verifiable as of 2026-09-03.
Fix status
Protocol documentation claims completed audits and ongoing review, but without direct issue/fix mapping; concrete fix status and bytecode match for deployed contracts on Arbitrum/Ethereum/Mantle/Noble/Osmosis/Sei/Solana/Stellar/Sui/XRPL is Not verifiable as of 2026-09-03.
Evidence (3)

audit

one source

Auditor: Halborn; publication: February 14, 2025; scope: Ethereum sources, recipients and instant-redemption contracts. Findings: 0 critical/high, 1 medium, 1 low, 3 informational. Fix status: medium, low and 2 informational solved; centralization risk acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Halborn
Report date
2025-02-14
Scope
Ethereum sources, recipients and instant redemptions
Findings
0 critical, 0 high, 1 medium, 1 low, 3 informational
Fix status
Mostly fixed; centralization item acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.
Evidence (1)

audit

two sources

Multiple audits across Ondo Global Markets, funds, and USDY on Ethereum and Noble, described in a comprehensive ecosystem review. The review summarizes that: (i) Ondo smart contracts have been reviewed by Cantina, Zellic, Spearbit, Cyfrin, FYEO, Halborn across multiple rounds in 2025–2026, with Ethereum and Noble explicitly mentioned for USDY and funds. (ii) A February 2026 Cantina audit targeted Ondo Global Markets contract upgrades and cross‑chain expansion; December 2025 Zellic+Cantina audits examined cross‑chain capabilities; September–November 2025 FYEO, Cyfrin, Spearbit performed in‑depth reviews of multiple products, including yield‑bearing and treasury‑backed tokens.

Public meta‑sources state that audit coverage is "top‑tier" and attaches firm‑by‑product tables, but individual PDF reports, detailed severities, and explicit fix tracking for each chain (Arbitrum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL) are Not verifiable as of 2026-08-30. Likewise, bytecode‑match to live Ondo Yield Assets contracts per chain is Not verifiable as of 2026-08-30.

Auditor
Multi‑firm set (Spearbit, Cyfrin, FYEO, Cantina, Zellic, Halborn)
Report date
2025-09-01
Scope
Ondo Global Markets, funds & USDY (ETH, Noble) and cross‑chain architecture; high‑level coverage only
Evidence (3)

audit

two sources

Ongoing and multi‑round smart‑contract audits for Ondo Global Markets, Ondo Funds and USDY on Ethereum, and cross‑chain expansions.

Auditor
Multiple (Cantina, Zellic, Spearbit, Cyfrin, FYEO, Halborn, Code4rena)
Report date
2023-01-01
Scope
Broad coverage of Ondo smart‑contract stack: Ondo Global Markets (including USDon and synthetic shares), Solana contracts, limit order protocol, funds/treasury tokens and USDY, plus cross‑chain expansions.[1][7][12] Explicit coverage of all deployed contracts for Ondo Yield Assets on Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL – and bytecode matching – Not verifiable as of 2026-09-04.
Findings
Individual reports (Cantina, Zellic, Spearbit, FYEO, Halborn, multiple Code4rena rounds) contain issue breakdowns, but only some are directly accessible here.[1][7] DIA profile notes Ondo Yield Assets has been independently audited with no recorded security incidents, and points to a CertiK project page.[15] Specific critical/high/medium counts for each named round Not verifiable as of 2026-09-04 from snippets.
Fix status
Bug‑bounty page states that issues in past audits are not bounty‑eligible, implying at least partial remediation, but detailed per‑issue fix tracking Not verifiable as of 2026-09-04.[7]
Evidence (4)

audit

one source

Smart‑contract audit of Ondo Finance.

Auditor
Nethermind
Report date
2023-04-19
Scope
Ondo Finance contracts (likely Ethereum) – precise scope requires full PDF review; association with current Ondo Yield Assets deployment on multi‑chains Not verifiable as of 2026-09-04.
Findings
Detailed issue list is inside PDF; snippet does not state counts or severities.[8] Full breakdown Not verifiable as of 2026-09-04 from available snippet.
Fix status
Remediation status not stated in snippet; Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Auditor: Nethermind; publication: April 24, 2023; scope: Flux/CASH/RWA oracle contracts. Findings: 0 critical/high, 1 medium, 4 low, 4 informational, 2 best-practice. Fix status: 7 fixed, 4 acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Nethermind
Report date
2023-04-24
Scope
Flux and CASH oracle contracts
Findings
0 critical, 0 high, 1 medium, 4 low, 4 informational, 2 best-practice
Fix status
7 fixed; 4 acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.
Evidence (1)

audit

one source

Ondo Finance V2 yield aggregator strategy smart contracts.

Auditor
Quantstamp
Report date
2021-09-03
Scope
Ondo Finance V2 yield aggregator strategy contracts including SushiStakingV2Strategy.sol on Ethereum.[2] Bytecode-match to currently deployed contracts Not verifiable as of 2026-09-04.
Findings
Total 15 issues: 0 critical, 0 high, 4 medium, 6 low, 4 informational, 1 undetermined risk.[2] Example medium: QSP-1 “Mid-Term LP deposits allow for risk-free profits”. All issues marked unresolved at time of report.[2]
Fix status
Unclear; Quantstamp report lists all 15 issues as unresolved at audit time. Whether they were later fixed is Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Auditor: Spearbit; publication: March 2025; scope: Ethereum OUSG/rOUSG, managers, fee/rate-limit and token-source contracts. Findings: 0 critical/high, 1 medium (subscription/redemption DoS), 6 low, 11 informational, 7 gas. Fix status: medium and 5/6 low fixed; 1 low acknowledged; 8/11 informational and 6/7 gas fixed, remainder acknowledged.

Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Spearbit
Report date
2025-03
Scope
Ethereum Ondo Funds/USDY contracts
Findings
0 critical, 0 high, 1 medium, 6 low, 11 informational, 7 gas
Fix status
Partially fixed; remaining items acknowledged. Deployed-code match: Not verifiable as of September 5, 2026.
Evidence (1)

audit

two sources

Ongoing multi-round security reviews of Ondo Global Markets, cross‑chain expansion contracts, and Ondo Funds & USDY on Ethereum.

Auditor
Spearbit / Cantina / Cyfrin / FYEO / Zellic
Report date
2026-02-01
Scope
Ondo Global Markets core contracts and cross-chain expansion; Ondo Funds & USDY primarily on Ethereum, with some cross-chain elements.[3][4] Chain-specific scope for Arbitrum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL cannot be fully delineated: Not verifiable as of 2026-09-03.
Findings
Independent reviews indicate: - Ondo Global Markets contracts audited by Spearbit, Cyfrin, FYEO, Cantina, Zellic between June 2025–Feb 2026.[3] - Cross-chain expansion contracts audited by Zellic and Cantina in Dec 2025.[4] - Multi-product continuous review by FYEO, Cyfrin, Spearbit Sept–Nov 2025.[4] Detailed vulnerability counts and severity breakdowns (critical/high/medium) from these firms are not publicly summarized in retrieved content: Not verifiable as of 2026-09-03.
Fix status
Media and Ondo docs describe audits as completed and part of continuous review,[1][3][4] but do not provide direct per-issue remediation status or bytecode‑match evidence to current deployments on each chain; therefore fix status and coverage of deployed code: Not verifiable as of 2026-09-03.
Evidence (3)

audit

one source

Security review of Ondo Finance protocol smart contracts (early Ondo protocol).

Auditor
Trail of Bits
Report date
2022-10-01
Scope
Ondo Finance Solidity smart contracts on Ethereum, including invest logic, rescueTokens, PSM, fee and parameter configuration.[5] Bytecode-match to currently deployed Ondo Yield Assets contracts on listed chains Not verifiable as of 2026-09-04.
Findings
8 issues: 2 high, 2 low, 4 informational.[5] Examples: (1) Risk of DoS attacks due to rate limits (high). (2) Risk of accounting errors due to missing check in invest function (high). Other issues include arbitrage opportunity in PSM contract and lack of upper bounds for fees.[5]
Fix status
Report summary does not state final remediation status; fix tracking Not verifiable as of 2026-09-04.
Evidence (1)

audit

unverified

Auditor: Zokyo; publication: August 2023; scope: Ondo Finance smart-contract codebase. Findings: 0 critical; detailed severity/fix breakdown unavailable from the accessible report copy. Deployed-code match: Not verifiable as of September 5, 2026.

Auditor
Zokyo
Report date
2023-08
Scope
Ondo Finance smart contracts
Findings
0 critical; remaining findings not verifiable as of September 5, 2026.
Fix status
Not verifiable as of September 5, 2026.
Evidence (1)

Team & Reputation

founders

two sources

Ondo Yield Assets appears to be the Ondo Finance product line, and the team is clearly public rather than anonymous: Ondo’s site lists Nathan Allman as founder, Ian De Bode as CEO, Justin Schmidt as advisor, and other named executives; Ondo also announced Allman’s unexpected death in 2026 and said De Bode would serve as CEO. Public biographies and third-party profiles describe Allman as a former Goldman Sachs digital-assets professional, and multiple independent profiles say Ondo was founded in 2021 by Allman with Pinku Surana, also from Goldman Sachs. Reality check: the business looks real, not a pure web-front.

Ondo has a public corporate footprint, a named New York headquarters on LinkedIn, and a substantial management team spanning legal, product, engineering, and institutional business development. Independent profiles also place Ondo in New York and describe it as a regulated/institutional-leaning finance company rather than an anonymous DeFi team. I did not find reliable evidence in the gathered sources of an offshore-only structure or a hidden anonymous team.

One caution: some secondary writeups conflict on the founder list and corporate history, with a few naming only Allman while others add Pinku Surana and different executives. The most consistent, source-backed reading is that Ondo has a public, professionally staffed team with ex-Goldman credibility and a real New York presence, but the exact legal structure and whether any subsidiaries are offshore are Not verifiable as of 2026-09-04.

Evidence (7)

general reputation

two sources

Ondo Yield Assets (Ondo Finance’s RWA/yield product suite) currently has a generally positive, compliance‑oriented reputation, with notable institutional backing and extensive auditing, but with structural and regulatory‑policy risks that remain under discussion rather than evidence of fraud or insolvency. Founders, investors, positioning

  • Ondo Finance was founded in 2021 by Nathan Allman and has raised tens of millions from Pantera Capital, Founders Fund, Coinbase Ventures, Tiger Global and other well‑known VCs, reinforcing an institutional image.
  • The protocol is widely framed as a leading real‑world‑asset (RWA) tokenization platform focused on U.S. Treasuries and other securities across multiple chains. Audits, bug bounties, technical reputation
  • Smart contracts have undergone multiple third‑party reviews, including Code4rena and other firms, with identified issues reportedly fixed or acknowledged.
  • Historical audits found several medium/high‑severity vulnerabilities (e.g., bridge‑related risks, admin limitations), which were later mitigated, contributing to a perception of active, iterative security management rather than neglect.
  • Ondo runs an ongoing bug bounty program via Immunefi, with maximum payouts in the high six‑ to seven‑figure range, signaling openness to external scrutiny. Regulatory / legal reputation
  • The U.S. SEC conducted a multi‑year investigation (starting 2023–24) into Ondo’s tokenization of Treasuries and the status of the ONDO token, then formally closed the probe with no charges. This is widely reported as a major positive compliance signal.
  • Ondo highlights adherence to Bank Secrecy Act/AML, counter‑terrorist financing, and OFAC‑sanctions requirements through its SPVs and AML program—these are self‑reported but consistent with external analyses of its structure.
  • Tokenized assets (e.g., USDY, OUSG, tokenized equities) are issued through bankruptcy‑remote SPVs, which independent commentary frames as investor‑protective in case Ondo Finance Inc. becomes insolvent. Criticisms, structural risks, sentiment
  • Key criticisms focus on custodian concentration risk: USDY reserves and other RWAs rely on a small set of custodians; a custodian failure or regulatory freeze could disrupt redemptions even if assets remain solvent.
  • RWA tokenization inherently faces jurisdictional/regulatory uncertainty; while the SEC outcome is positive, future policy changes could still affect products.
  • No credible reports of fraud, rug pulls, or insolvency have surfaced; ongoing discussion is mainly about design trade‑offs and systemic/counterparty risk rather than misconduct. Unresolved concerns
  • On‑chain distribution across chains (Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL) and per‑chain TVL, holder concentration, and treasury positions are Not verifiable as of 2026‑09‑04 under current tool constraints.
Evidence (14)

Economy

TVL: $2.6B

model

one source

Economic model — as of September 6, 2026

  • Strategy/assets in–out: Ondo Yield Assets tokenizes short-duration U.S. Treasuries, government money-market funds/ETFs and cash reserves. Users contribute USDC (and, for some products, USD wire); they receive yield-bearing tokens such as USDY/rUSDY and OUSG, redeemable for USDC or USD subject to eligibility and rail restrictions.
  • Yield source / profile: Yield is principally coupon and money-market income from the underlying securities, less fees—not crypto lending emissions. This is economically directional to short-duration U.S. rates and USD/custody infrastructure, not market-neutral. No product-level leverage, looping or restaking is identified; OUSG can separately be used as collateral in Flux Finance, creating external lending exposure.
  • Organic vs subsidized: The return appears fundamentally organic because it derives from Treasury/MMF income. Exact organic-versus-subsidized percentage is Not verifiable as of September 6, 2026; organic_yield_pct=null.
  • Lock-ups/withdrawals: OUSG supports instant atomic mint/redemption, normally with a $5,000 minimum, plus non-instant $100,000 subscription/$50,000 redemption minimums. Instant flows are capped (documented $50m global and $25m individual daily mint limits); non-instant redemption is typically next business day. OUSG is restricted to onboarded qualified purchasers. USDY has jurisdictional/KYC restrictions and $5,000 minimums on several networks; USDY/rUSDY wrapper balances are locked until unwrapped.
  • Fees/revenue: OUSG’s stated management fee is 0.15% (waived through July 1, 2026 in the cited documentation). DeFiLlama reports $7.17m fees/30d but $0 protocol revenue/30d—a material fee-to-revenue conversion gap.
  • TVL: DeFiLlama reports $2.528b for the product, essentially flat over 30 days. Approximate chain shares: Ethereum 51.5%, Stellar 21.1%, Sei 10.2%, XRPL 7.6%, Solana 7.1%, Mantle 1.1%, Sui 0.6%, Noble 0.6%, Arbitrum 0.1%, Aptos 0.1%; Polygon/Plume $0. Osmosis is not listed. Product-level TVL by token and historical APY volatility are Not verifiable as of September 6, 2026 without Dune/API history. Contradiction: Parent Ondo Finance TVL is $3.496b, while Ondo Yield Assets is $2.528b; parent TVL includes other products and must not be treated as this strategy’s TVL. Dune on-chain verification, latest block/as-of timestamp, collateral balances, and Dune-vs-DeFiLlama reconciliation are Not verifiable as of September 6, 2026.
Evidence (5)

reserves

unverified

As of September 6, 2026: Reserve size / composition. The latest accessible USDY portfolio snapshot is as of September 3, 2026, 19:59:59 EDT. It reports $2,205,052,977 of underlying assets, $2.14B of USDY outstanding, and a 105.55% collateralization ratio. Composition: US Treasuries $2,146,874,145 (97.36%); Ondo Stocks issued USDY $57,712,040 (2.62%); Silicon Valley Bank bank deposits $461,418 (0.02%); other cash/cash equivalents $5,374 (<0.01%). Addresses / on-chain balances. Reserve-wallet addresses and per-chain reserve balances are Not verifiable as of September 6, 2026 because Dune MCP is unavailable in this run.

The public contract/address registry identifies token, redemption, bridge, and operational addresses—not the full off-chain Treasury, brokerage, or bank-account reserve set. It does identify the Ethereum Coinbase Prime USDC deposit address 0xbDa73A0F13958ee444e0782E1768aB4B76EdaE28; this is a deposit/operational address, not evidence of total reserves. Custody and control. Ondo states USDY is issued by a limited-purpose, bankruptcy-remote entity and backed by short-term Treasuries and bank deposits. Ankura Trust is described as verification and collateral agent, with authority—subject to the governing documents and acceleration conditions—to take control of collateral and repay holders.

Institutional custody support is publicly announced through Komainu, Zodia, and Copper; the exact allocation among custodians is not disclosed. These custody and control descriptions are primarily issuer disclosures and should be treated as unverified marketing claims unless confirmed by independent attestations. Reserve policy / attestations. Ondo’s stated policy is daily reserve reporting, overcollateralization, and third-party oversight. The current report implies a 5.55% asset buffer, superseding the previously recorded secondary-source estimate of 4%; the original product materials described an approximately 3% minimum buffer.

Daily and monthly report repositories are publicly linked, but the underlying account-level evidence is not independently verifiable here. Contradiction / limitation: No independent, current, on-chain verification of total reserves, liabilities, or custodian account balances was possible. Exact liabilities are not disclosed in the accessible snapshot beyond the rounded “$2.14B outstanding.”

Liquid reserves usd
$2.2B
Evidence (5)

tokenomics

two sources

As of September 4, 2026. Ondo Yield Assets has a native token: Ondo (ONDO). Canonical Ethereum contract: 0xfaba6f8e4a5e8ab82f62fe7c39859fa577269be3; representations on the listed chains were Not verifiable as of September 4, 2026. Supply/valuation: total and maximum supply are 10.0B ONDO; circulating supply is 4.869B.

CoinGecko reports approximately $1.734B market cap and $3.561B FDV at the latest page update. Outstanding supply is estimated at 7.624B, but this is an analytics estimate, not an on-chain verification. Allocation and announced vesting: Community Access Sale 2.0%; Ecosystem Growth 52.1%; Protocol Development/core contributors 33.0%; Private Sales 12.9%. The Foundation’s schedule specified immediate/near-immediate CoinList release, while team and private-sale allocations had a 12-month minimum lock followed by releases over approximately four years; ecosystem tokens had staged unlocks.

Whether each announced unlock actually occurred on-chain: Not verifiable as of September 4, 2026. Utility/governance: ONDO is primarily a governance token. Contradiction: the original token description says ONDO governs Ondo Finance, while independent contract/governance analysis reports that tokenholders do not control core OUSG, USDY, or Global Markets contracts; company multisigs control those systems. Value accrual: no verified revenue share, buyback, burn, or staking-reward mechanism for ONDO holders was identified. No active fee switch or DAO treasury was identified.

Admin/security: independent analysis reports an active MINTER_ROLE and DEFAULT_ADMIN_ROLE held by a team multisig; no ONDO blacklist, freeze, pause, or seizure function was identified. Mint authority therefore remains a material inflation/governance risk. Top-holder concentration and insider-wallet attribution: reported ~59% in a team multisig, but raw on-chain verification was unavailable in this run; Not verifiable as of September 4, 2026.

DEX liquidity depth: Not verifiable as of September 4, 2026. Main reported listings include Coinbase, Binance, and Kraken.

Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 would be a severe *risk-off* shock for Ondo Yield Assets, but the impact would be product-specific rather than uniform across the whole protocol. The most likely immediate effects are a sharp drop in secondary-market prices and liquidity for tokenized yield products, wider bid-ask spreads, and potential delays or frictions in redemptions or transfers under stressed conditions. For Ondo’s yield-bearing products, the main economic risk is not necessarily direct exposure to Bitcoin, but market-wide contagion: if BTC collapses that far, broader crypto liquidity, sentiment, and market-making capacity would likely deteriorate, which can weaken pricing and exit conditions even for assets backed by Treasuries or other off-chain collateral.

The yield on products like USDY and OUSG is described as tied to short-term U.S. Treasury rates, so a BTC crash would not mechanically destroy that yield stream; however, extreme stress could still reduce demand, slow TVL growth, and tighten spreads in secondary markets. What is not verifiable as of 2026-09-04 from the provided sources is Ondo’s exact chain-by-chain exposure across Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, and XRPL, or the protocol’s actual loss profile under a BTC-$10k scenario.

The available sources are mostly commentary and risk summaries, not on-chain balances or audited stress tests. The cleanest institutional reading is:

  • Bitcoin below $10k = systemic crypto stress, likely severe liquidity impairment.
  • Ondo yield assets = likely price/distribution stress, but underlying yield assets may remain fundamentally linked to non-BTC collateral.
  • Protocol solvency = Not verifiable as of 2026-09-04 without on-chain and issuer-level data. A dedicated contradiction note: any headline claim that Ondo yield assets would “crash because Bitcoin crashed” is too broad; the evidence supports a more precise statement that BTC stress would primarily hit *market liquidity, redemption conditions, and secondary pricing*, not automatically the collateral value of Treasury-backed products.
Evidence (4)

stress scenario - largest collateral depegs 20%,

unverified

For Ondo Yield Assets, a 20% depeg in the largest collateral asset is a severe stress event, but the exact loss transmission to users is not verifiable as of 2026-09-04 because the required on-chain exposure by chain and collateral mix could not be verified here. Ondo’s USDY is documented as overcollateralized by short-term U.S. Treasuries and bank demand deposits, with an approximately 3% first-loss buffer, while OUSG is described as backed mainly by BlackRock’s BUIDL plus other cash/liquidity holdings.

Under this stress, the immediate risk is collateral value impairment: if the largest collateral asset is the dominant backing component, a 20% mark-down can push positions toward liquidation thresholds and widen secondary-market discounts, especially where redemption is slow or restricted. In practice, the worst-case outcome is usually forced deleveraging and liquidity stress, not automatic 20% user loss, because overcollateralization and first-loss buffers absorb part of the shock before creditors/tokens absorb losses. Across the supported chains listed for USDY/Ondo yield distribution, the key question is where collateral is actually posted and rehypothecated; that chain-level concentration is Not verifiable as of 2026-09-04 from the available web results.

The protocol-level risk factor is clear, though: if a large collateral asset depegs sharply, liquidation cascades can occur across DeFi markets using that asset as collateral, with the protocol’s redemption and custody structure determining how much of the shock reaches holders. So the stress verdict is: high contagion risk, uncertain direct loss magnitude, and likely liquidation/repricing pressure first; precise loss-to-holders and chain-by-chain exposure are not verifiable here.

Evidence (7)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Ondo Yield Assets, a top-counterparty insolvency is primarily a legal-custody loss event, not a pure smart-contract failure: the on-chain tokens can keep functioning, but redemption value depends on the off-chain issuer/SPV, custodian, and collateral-agent structure. Expected loss path: if the backing issuer, custodian, or collateral agent fails, the asset’s NAV/redemption value can be impaired first at the legal wrapper level, then at the token level if recoveries are delayed or partial. The most explicit published recovery language I found is for USDY, where an independent security agent (Ankura Trust) can take possession of collateral, sell it, and distribute proceeds to tokenholders in specified issuer-default events; one secondary source also states a first-loss position / overcollateralization buffer is intended to absorb the initial shock. Who absorbs it: first loss is intended to sit with the issuer/collateral structure, then any reserve or collateral buffer, then tokenholders through delayed or reduced redemption proceeds if recoveries are insufficient. If the parent company itself becomes insolvent, another source says the SPVs are bankruptcy-remote and ring-fenced for token holders, so parent-creditor claims should not directly reach the assets; that is a legal-protection claim, not an on-chain guarantee. Compensation: compensation comes from collateral liquidation / recovery distributions under the legal documents, not from an autonomous protocol insurance pool.

I did not find verifiable evidence of a protocol-level socialized loss fund for this scenario. Impact path through smart contracts: the smart contracts are the transfer/mint/burn and redemption interface, but the distress mechanism appears to be triggered off-chain through the issuer/default legal process; the contract layer mainly enforces token ownership and redemption flows once recovery assets are available. If the issuer cannot perform, the chain-side effect is typically halted or delayed redemptions rather than an automatic on-chain bailout. Chain note: this same legal-risk pattern applies across the supported deployments, but the exact exposure split by chain is Not verifiable as of 2026-09-04 without on-chain data.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For a DAO/owner committed fraud stress scenario, the primary risk is malicious governance or administrative misuse rather than a conventional smart-contract exploit. Ondo’s own materials state that ONDO holders govern the DAO, while USDY is issued through a dedicated SPV with limited activities, which reduces—but does not eliminate—direct treasury-style commingling risk. The most relevant red flags are admin/operator powers and centralized operational controls.

Ondo’s 2024 codebase review explicitly notes that admins can call “unrestrained setters,” rOUSG burns, a retrieveTokens function, and a multicall function, and frames “malicious admin/operator” as a key attack idea. That means a dishonest controller could, in a stress case, alter contract behavior, restrict redemptions, or move assets in ways users did not expect if controls are abused. A fraud scenario would also be amplified by Ondo’s multi-chain footprint and the need for bridge, issuer, and custody coordination across assets and chains.

If owners or DAO decision-makers acted fraudulently, losses would likely depend on which product is affected: governance-token holders face economic and reputational loss, while token holders in SPV-backed products face potential redemption disruption, freeze risk, or legal recovery delays rather than automatic protection. What is not verifiable as of 2026-09-04 from the available sources is whether Ondo has any actual DAO- or owner-related fraud incident, insider theft, or governance abuse. The available material supports only that the structure contains centralized control surfaces that could be abused in a fraud stress case.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For a stress scenario with the primary yield source negative over 30 days, the relevant interpretation is that Ondo’s yield-bearing products would likely show lower or possibly zero distributable yield, because Ondo states that 30-day yield is based on the average net income earned over the prior 30 calendar days and that yields reflect past performance, not guarantees. Ondo also says USDY’s yield comes from the performance of its underlying assets, namely short-term U.S. Treasuries and bank deposits, minus fees.

A sustained negative 30-day primary yield would therefore imply a compression of payout rates, and if the negative contribution were severe enough, the product’s displayed 30-day yield could turn negative *in economic terms*; however, whether the public product page would actually display a negative number is Not verifiable as of 2026-09-04 from the provided sources. This is a source-risk stress, not a chain-specific one: no on-chain data was available in this run, so chain-by-chain exposure across Arbitrum, Ethereum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, and XRPL is Not verifiable as of 2026-09-04. The primary on-web evidence supports only the general mechanism that yield is variable and tied to the underlying income stream.

Evidence (3)

Governance & Legal

governance

two sources

Assessment — as of September 13, 2026. Governance is primarily company-controlled, not ONDO-tokenholder-controlled. Ondo Finance Inc. controls the website/frontend and technical interfaces under its Terms of Service; product issuers and affiliates control issuance, eligibility, redemption, KYC/blocklisting and related legal functions. USDY is issued by Ondo Global Markets (BVI) Limited; OUSG is managed through Ondo I LP and wholly owned Delaware subsidiaries. DAO/process. ONDO governance is documented mainly for Flux Finance and DAO-level functions such as selecting an admin, treasury management, emissions and arbitrary calls—not for OUSG, USDY or Global Markets.

For core products, reported governance is multisig/admin execution without tokenholder votes; therefore the DAO is symbolic for this protocol scope. Voting concentration/top holders: Not verifiable as of September 13, 2026. Dune MCP was unavailable, so no Dune query ID or execution snapshot exists; do not treat third-party holder figures as on-chain verified. Contract control. Reported role mapping indicates OUSG and USDY upgrade/admin authority held by company multisigs, while Global Markets uses a company-controlled TimelockController. Reported configurations include 4-of-7 multisigs for OUSG/USDY and ONDO roles, and Global Markets roles of 4-of-7 proposer, 1-of-8 executor plus an EOA, and 5-of-9 timelock admin.

These are heterogeneous controls, not one protocol-wide multisig, and were not independently re-run on-chain here. Signer identities, independence and current membership: Not verifiable as of September 13, 2026. Timelock/emergency risk. A 2-hour delay is reported for Global Markets only; no equivalent delay was verified for OUSG/USDY. Admin-controlled upgrades, role changes, minting and compliance controls can bypass tokenholder governance.

Whether any admin can directly drain every product’s user funds is not verifiable as of September 13, 2026; upgrade/admin authority nevertheless creates material governance and loss-of-control risk. Legal entities. Ondo Finance Inc. is a Delaware corporation with principal place of business in New York; its registration number and directors were not verified. Ondo Global Markets (BVI) Limited is a BVI company, registry number 2174192; a 2025 prospectus names Nathan Allman, Dion Degrand and Gareth Thomas as directors.

Timelock
Yes
Timelock delay hours
2
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Ondo Yield Assets are part of the broader Ondo Finance ecosystem, which issues tokenized yield products such as USDY, OUSG and Ondo Global Markets (OGM) stock tokens across multiple chains. Legal and regulatory exposure is driven by the issuing entities and wrappers, not the chains themselves. Entity & jurisdiction

  • USDY: Issued by *Ondo USDY LLC*, which is registered as a Money Services Business (MSB) with FinCEN in the US.
  • OUSG (tokenized short‑term US Treasuries): Issuer is *Ondo I LP*, a Cayman Islands limited partnership; OUSG is structured under US law via Rule 506(c) of Regulation D and Investment Company Act §3(c)(7) for qualified purchasers.
  • Ondo Global Markets (OGM) tokenized stocks: Issuer *Ondo Global Markets (BVI) Limited* in the British Virgin Islands, offering tokens only to non‑US persons under Regulation S and with additional jurisdictional restrictions. Overall, the core regulatory nexus is US (FinCEN + securities exemptions), Cayman Islands, and BVI. Classification & offering restrictions
  • USDY is offered under Regulation S as an unregistered securities exemption for non‑US investors.
  • OUSG is a private fund/security sold to “qualified purchasers” under Reg D 506(c and 40 Act §3(c)(7).
  • OGM stock tokens are treated as tokenized securities entitlements, restricted to non‑US persons and subject to resale limits into the US. These wrappers imply securities‑law risk (exemption reliance) rather than “utility token” positioning. KYC/AML & sanctions
  • Ondo USDY LLC operates KYC/AML and sanctions compliance programs under the US Bank Secrecy Act, including customer due diligence and suspicious activity reporting.
  • OGM requires full KYC onboarding, wallet/transaction screening, and imposes jurisdictional and eligibility restrictions to comply with sanctions, AML/CFT and securities laws.
  • OUSG purchasers must pass KYC, AML, and accreditation review before mint/redeem. Regulatory interactions, warnings, enforcement
  • The US SEC conducted a two‑year investigation into Ondo Finance concerning tokenized Treasuries and ONDO token classification, and closed it without charges in December 2025.
  • Ondo has engaged the SEC via no‑action request submissions and policy letters on tokenized securities (including OGM).
  • There are no reported sanctions listings or direct enforcement actions against Ondo Finance entities as of the latest sources; SEC closure without charges is a positive but not permanent regulatory clearance. Data protection & residual legal risk
  • KYC/AML processes imply collection of personal data (IDs, residency proof, accreditation), governed by US Bank Secrecy Act and general privacy law, but detailed data‑protection frameworks are not independently documented beyond Ondo’s own materials.
  • Key residual risks: dependency on US securities exemptions, evolving treatment of tokenized RWAs, cross‑border offering rules, and potential re‑assessment of ONDO token status. On‑chain verification
  • Detailed, chain‑level legal structuring per Arbitrum, Mantle, Noble, Osmosis, Sei, Solana, Stellar, Sui, XRPL is Not verifiable as of 2026‑09‑04; exposure is primarily via the legally wrapped issuers above.
Active enforcement
No
Sanctioned
No
Entity
Ondo USDY LLC; Ondo I LP; Ondo Global Markets (BVI) Limited
Jurisdiction
United States (FinCEN MSB; securities exemptions), Cayman Islands, British Virgin Islands
Evidence (11)

legal registries

two sources

No exact GLEIF LEI record for 'Ondo USDY LLC', 'Ondo I LP', 'Ondo Global Markets Limited', 'Ondo Yield Assets'. OFAC SDN screening of 'Ondo USDY LLC', 'Ondo I LP', 'Ondo Global Markets Limited', 'Ondo Yield Assets': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Ondo USDY LLC
  • Ondo I LP
  • Ondo Global Markets Limited
  • Ondo Yield Assets
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Ondo Yield Assets does not issue its own stablecoin; USDY is described by Ondo as a yieldcoin/tokenized note, not a stablecoin. The protocol’s operating flows reference USDC (and in some cases PYUSD/RLUSD for related products), but no reliable web evidence in this run verified any depeg event for the stablecoin used by the protocol, so depeg count, last depeg date, and max depeg % are not verifiable as of 2026-09-06.

Own stablecoin
No
Evidence (6)

Risks & Strengths

risks

unverified

Ondo Yield Assets combine regulated off-chain securities, centralized service providers, token contracts, oracles, and cross-chain messaging; the dominant risks are therefore legal enforceability, redemption operations, and infrastructure failure rather than underlying Treasury credit alone. On-chain exposure by chain, reserve coverage, and current concentration are Not verifiable as of September 5, 2026 because Dune access is unavailable in this run.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Regulatory and eligibility breachUSDY relies on Regulation S and non-US distribution; OUSG is limited to qualified purchasers and accredited investors. Enforcement, sanctions, or jurisdictional changes could restrict transfers, freeze access, or force product restructuring.HighMediumKYC/AML and sanctions screening, investor eligibility checks, restricted issuance/redemption workflows, and separate legal entities are documented.High legal uncertainty and potential loss of access remain.
Issuer and custodian concentrationTokenholder protection depends on Ondo entities, custodians, administrators, collateral agents, banks, and asset managers performing correctly. Failure, insolvency, fraud, or operational disruption could delay recovery despite stated security interests.HighMediumSPV/fund structures, security interests, third-party verification or collateral-agent roles, and Treasury-focused assets are described.Recovery remains legally and operationally dependent on intermediaries.
Redemption and liquidity mismatchRedemptions may require bank wires, eligibility checks, minimum amounts, business-day processing, or specific settlement rails. Secondary-market liquidity can disappear while the underlying assets remain off-chain or settlement-dependent.HighMediumDocumented redemption processes, instant-manager functionality for selected products, and stated default/wind-down mechanics are in place.No guaranteed immediate or permissionless exit across all chains.
Cross-chain bridge compromiseUSDY transfers use burn-and-mint OFT messaging through LayerZero DVNs. A verifier collusion event, configuration error, message failure, or destination-chain exploit could cause unauthorized minting, loss, or prolonged transfer blockage.HighMediumMultiple DVNs, configurable rate limits, emergency pause capability, and pathway caps are documented.Bridge and third-party verification risk remains material.
Oracle and contract failureToken valuation and integrations depend on smart contracts, dynamic price oracles, wrappers, and operational updates. Bugs, privileged-key compromise, stale prices, or manual-update errors could misprice collateral, impair transfers, or enable loss.HighMediumMultiple audits, published contract addresses, rate controls, and operational pricing procedures are documented; audits are not guarantees.Full current implementation coverage and live chain-state correctness are Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Ondo Yield Assets’ main strengths are: 1) institutional-grade structure and compliance, with yield products designed around regulated, bankruptcy-remote, investor-protection frameworks; 2) access to U.S. Treasury yield onchain, which gives users exposure to short-duration Treasury income rather than volatile crypto-native yield; 3) broad multichain distribution, including availability across major ecosystems such as Ethereum, Arbitrum, Solana, Stellar, and others, which improves reach and utility; 4) 24/7 onchain minting/redemption and composability, making the assets easier to use in DeFi, treasury, and payments workflows than traditional funds; and 5) transparency and daily verification, with reserves described as independently verified daily and token values tracked onchain, which supports user confidence and operational monitoring.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 24 two independent sources, 29 one source, 6 unverified.
  • Oldest fact verification date: 2026-08-30.