OpenEden TBILL

Orange · 61/100

Executive summary

OpenEden TBILL is a tokenized U.S. Treasury bill vault with a 61/100 score (orange band), offering regulated, KYC-gated exposure to short-dated T-bills across Ethereum, Arbitrum, and other chains, but carrying unresolved incident penalties and centralized operational risks.

  • Security: Multiple audits by Hacken and Verichains since March 2023; most recent (Dec 2024) found 0 critical/high issues, but earlier audits identified 2 critical findings (since fixed) and a July 2025 HackenProof contest disclosed 1 high-severity undercollateralization risk in fee-claim logic with no public remediation confirmation as of Sept 2026.
  • Incidents: February 2026 DNS/frontend hijack redirected users to a wallet drainer; no confirmed protocol or user losses, resolved within 24 hours. One disclosed smart-contract vulnerability (fee-claim undercollateralization) remains unverified for remediation, triggering the -10 penalty.
  • Governance & custody: Upgradeable vault with multisig + 24h timelock controls; admin can drain funds under role-based permissions. Underlying T-bills held by BNY (custodian/manager) in segregated accounts; independent fund administrator co-signs on-chain movements. No DAO governance over fund operations; OpenEden Governance (launched Jan 2026) covers only incentives/participation, not core custody or contracts.
  • Top risks: Centralized administration (pause, fees, upgrades), off-chain NAV/oracle dependency, counterparty/custody concentration (BNY, Coinbase Prime, fund administrator), redemption liquidity gating, and unverified reserve composition (T-bills + money-market funds/repos/BUIDL; exact allocation not disclosed). Smart-contract upgrade and oracle manipulation remain residual high risks despite audits.
  • Strengths: Direct U.S. T-bill exposure with instant on-chain mint/redeem, BVI-regulated professional fund structure, institutional custody (BNY), mandatory KYC/AML, multi-chain support, and transparent monthly attestations/audits. Short duration (<3mo WAM) supports cash-management use cases.
  • Unverified: Deployed-code bytecode match to audit scope, current reserve allocation and legal priority, chain-by-chain TVL/exposure (Arbitrum/Ethereum/Solana/XRPL), remediation status of July 2025 high-severity finding, multisig signer identities/threshold, and whether any user losses occurred in the Feb 2026 frontend hijack.
  • Recommended exposure: Limit to <5% of portfolio for institutional allocators comfortable with permissioned RWA and centralized custody; suitable only for KYC-compliant, accredited/professional investors. Avoid if exposure to admin-key risk, off-chain valuation, or unverified reserve composition is unacceptable. Monitor for remediation confirmation of the disclosed undercollateralization issue before increasing allocation.
  • Open questions: (1) Has the July 2025 HackenProof high-severity fee-claim issue been fixed on deployed contracts? (2) What is the current reserve breakdown (T-bills vs. money-market funds/repos/BUIDL) and legal claim priority? (3) Who are the multisig signers, what is the threshold, and are they independent? (4) Were any user funds lost in the Feb 2026 DNS hijack, and if so, were users reimbursed? (5) What is the exact bytecode-match status for audited code vs. live deployments on all chains?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 13 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 30 6.0 last full audit 2024-05-01 is older than a year; auditor not in top-20 -20
Incidents 20% 100 20.0 1 open incident(s), $0 at risk (1 with unknown loss) = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 1 0.2 TVL $245,844,065 = 1% of reference ($17,538,184,136)
Data confidence 86 7/7 critical categories; 13/44 verified facts; 43/44 fresh (180d)

Identification

protocol identification

two sources

Protocol identification OpenEden TBILL is a tokenized U.S. Treasury bills product delivered via a smart‑contract vault called the OpenEden TBILL Vault. It is categorized as RWA / tokenized Treasuries / tokenized money market fund.

  • Website / App: openeden.com and app.openeden.com (TBILL section).
  • Docs: Technical/product docs at docs.openeden.com/tbill.
  • Category: Tokenized U.S. T‑bill fund / RWA yield vault.
  • Launch date: Token TBILL launch given as 18 Oct 2023. The Arbitrum TBILL Vault was “officially launched in March 2024”.
  • Chains (DeFi usage): Ethereum and Arbitrum are explicitly live for vault mint/redeem. TBILL is also reported on BNB Smart Chain by Token Terminal. XRPL and Solana are referenced in the user query but are Not verifiable as of 2026-09-04 from independent sources; XRPL app page exists but only reproduces fund boilerplate without clear on‑chain details.
  • Native token: TBILL – an EIP‑20 compliant, yield‑bearing token representing interest in a fund holding short‑dated U.S. Treasury bills plus a USD cash buffer. Main contract addresses (cross‑checked ≥2 sources)
  • Ethereum TBILL token: 0xdd50C053C096CB04A3e3362E2b622529EC5f2e8a
  • Labeled “OpenEden T‑Bills (TBILL)” on Etherscan.
  • Same address listed for Ethereum on Coinbase asset page.
  • Arbitrum TBILL token: 0xF84D28A8D28292842dD73D1c5F99476A80b6666A
  • Listed as Arbitrum TBILL address on Coinbase.
  • Arbitrum STEP application and OpenEden materials identify TBILL on Arbitrum as the vault token; direct address not printed there but consistent with exchange listings and category. Explorer verification: Ethereum token contract is verified on Etherscan and clearly named “OpenEden T‑Bills (TBILL)”. Arbitrum address is recognized by major exchanges as TBILL; direct explorer verification status is Not verifiable as of 2026-09-04 without live explorer access. Fork lineage / code provenance OpenEden TBILL is presented as a bespoke smart‑contract vault and regulated fund structure, not as a fork of another DeFi protocol; no credible source describes it as a fork of MakerDAO, Compound, Ondo, etc.
  • Token Terminal and OpenEden docs treat TBILL as a proprietary tokenized fund with its own vault contracts.
  • No public mention of upstream protocol name, fork relationship, or “based on X” in Arbitrum governance, docs, or external RWA analyses. Accordingly, fork status, specific upstream changes, and any malicious‑modification history in similar forks are Not verifiable as of 2026-09-04 from independent technical or audit sources. Audit coverage of the vault contracts is referenced in marketing and rating claims (e.g., “Moody’s A‑rated smart contract vault” on DeFiLlama) but the underlying audit reports and scope are Not verifiable as of 2026-09-04. Contradiction callout
  • Chains: Token Terminal lists Ethereum, Arbitrum, BNB Smart Chain for TBILL. The user’s chain list includes Solana and XRPL; independent confirmation of active TBILL smart contracts there is Not verifiable as of 2026-09-04, so Ethereum/Arbitrum (plus possibly BNB) should be treated as the primary DeFi exposure set.
Evidence (13)

maturity

two sources

OpenEden TBILL appears to be a real, live product portal rather than a pure landing page: the app domain exposes TBILL and portfolio pages, and the documentation describes actual subscription/redemption flows through the app interface or smart contract. The docs also describe operational features such as whitelisted onboarding, minimum deposits, on-chain USDC deposits/withdrawals, and FIFO redemption processing, which are maturity signals beyond simple marketing copy. The user experience is not fully public or open: several core actions are gated to whitelisted/"onboarded" investors, and the portfolio page explicitly asks users to connect a whitelisted wallet to view transactions on XRPL, so live functionality exists but is permissioned.

The docs include an API-like pattern for querying markdown pages with an ask parameter, but there is no evidence here of a public product API for deposits, withdrawals, or programmatic vault access beyond the smart contract interface and documentation endpoints. I did not see strong template/placeholder signs in the surfaced pages, but the site does present multiple product surfaces (TBILL, USDO, portfolio) and detailed docs, which argues against a simple fake landing page. There are no verifiable signs in the gathered material of broken links or fake metrics, but that cannot be confirmed exhaustively from this sample, so those items are not verifiable as of 2026-09-04.

Overall: mature, permissioned DeFi product with live deposit/redemption mechanics and documentation, but no clearly documented open public API for the vault itself, only the app UI, smart contracts, and docs endpoints.

Evidence (3)

Security

bug bounty

two sources

OpenEden TBILL appears to have an active bug bounty / audit contest on HackenProof with the program page showing OpenEden Smart Contract Audit Contest and in-scope contracts limited to OpenEdenVaultV4Impl.sol, KycManager.sol, and DoubleQueueModified.sol. The listed reward structure is bounty-based with severity tiers; the page states only accepted impacts are in scope and rewards are distributed per issue. The program page also shows reported activity with at least 186 submissions, 6 valid findings accepted, and $5,000 in rewards allocated on the HackenProof platform, while individual disclosed findings show low-severity payouts of $83.

The exact on-chain security posture and token-holder impacts are not verifiable as of 2026-09-04 because on-chain checks were unavailable in this run.

Active
Yes
Platform
HackenProof
Max payout
$8K
Since
2025-10-10
Evidence (4)

counterparty risks

one source

As of September 6, 2026, no dependency failure, custodian insolvency, bridge exploit, depeg, or oracle incident was identified in the reviewed sources; this is not an on-chain verification. dependency_failure_active is therefore set to false, subject to monitoring. Core counterparties: TBILL is issued by Treasury Bills Institutional Liquidity Limited, a BVI professional fund. BNY affiliates were appointed investment manager/sub-manager and primary custodian in August 2025. Other disclosed dependencies include Coinbase Prime for fiat on/off-ramp, Protege Fund Services (administrator), TJ Assurance Partners (fund auditor), KPMG, Harneys, Elliptic/Chainalysis, LSEG market data, and River Labs as vault developer.

These create concentrated operational, custody, valuation, legal-enforcement, and redemption dependencies. RWA/SPV and reserve ambiguity: OpenEden documentation describes backing primarily as U.S. T-bills and USD; related OpenEden risk disclosures also mention money-market funds, repos, and BlackRock BUIDL. DeFiLlama additionally identifies a bankruptcy-remote Cayman SPV, OpenEden Cayman Limited.

The exact current reserve allocation and legal priority of token holders are Not verifiable as of September 6, 2026. This is a material disclosure inconsistency, not evidence of loss. Oracle / smart-contract risk: NAV pricing depends on an on-chain price oracle and off-chain financial-market data feed. Price guards, timelocks, multisig controls, and audits reduce but do not eliminate stale-price, administrator-key, valuation, or contract-exploit risk.

Current auditor coverage, signer set, oracle operator, and bridge design for Solana/XRPL are Not verifiable as of September 6, 2026. Stablecoin / chain exposure: subscriptions and redemptions use USDC, creating USDC depeg, freeze, and settlement risk. Analytics indicate approximate TBILL distribution of 72.9% Ethereum, 26.7% XRPL, 0.4% Solana, and <0.1% Arbitrum; these are aggregator figures, not on-chain-verified. No LST/restaking or external DeFi leverage dependency was verified. Maximum exposure: Not verifiable as of September 6, 2026; reserve-by-counterparty percentages and exploitable bridge exposure are not disclosed in verifiable primary data.

Dependency failure active
No
Evidence (6)

crypto custody

unverified

OpenEden TBILL uses split custody: TBILL tokens are self-custodied by investors in their own wallets, while the underlying U.S. Treasury bills and any USD reserves are held off-chain by regulated custodians, with the fund assets described as being held in segregated accounts for the benefit of token holders. OpenEden’s docs and BNY’s announcement both state that BNY serves as investment manager and primary custodian for the underlying TBILL assets.

Withdrawal pause status is Not verifiable as of 2026-09-06.

Segregated assets
Yes
Evidence (3)

incident

two sources

On February 16, 2026, OpenEden’s openeden.com and portal.openeden.com experienced a DNS/frontend hijack. The attacker obtained unauthorized registrar/DNS control, redirected traffic to attacker infrastructure, issued fresh SSL certificates, and deployed the AngelFerno wallet drainer. Affected parties were website visitors and users who might connect wallets to the counterfeit frontend; OpenEden’s TBILL smart contracts, core application, custody systems, and reserve assets were reported unaffected.

No realised protocol or user loss was publicly confirmed: Not verifiable as of September 6, 2026. Attacker proceeds: Not verifiable as of September 6, 2026. OpenEden warned users not to access or interact with the domains, investigated with security and infrastructure providers, restored DNS control, and implemented additional domain/infrastructure safeguards.

The incident was reported remediated within approximately 24 hours, with normal operations restored by February 19, 2026. Recovered amount: 0 confirmed. User reimbursement: Not verifiable as of September 6, 2026.

Current status: resolved.

Date
2026-02-16
Cause
Frontend / infrastructure hack
Status
resolved
Recovered
$0
Event id
openeden-dns-frontend-hijack-2026-02-16
Evidence (3)

incident

two sources

A Hacken report identified a critical smart-contract issue in OpenEden’s fee-claim logic: claiming fees from the underlying token balance would undercollateralize TBILL and break the TBILL/USDC rate function. This is a disclosed vulnerability, but the available sources do not confirm that it was exploited or caused user losses.

Date
2026-08-28
Cause
Smart-contract exploit
Status
remediation in progress
Evidence (2)

key management

two sources

Key management in OpenEden TBILL appears to be organized as a layered control model rather than a single key-holder setup. On-chain asset movement is governed by a multisig TBILL Vault that requires multiple private keys, including an independent third-party fund administrator, to authorize transactions; OpenEden also says a timelock applies when changing the vault treasury wallet address and that on-ramp/off-ramp actions are limited to authorized OpenEden representatives via multisig operations. Off-chain assets are held with regulated custodians, and any action initiated by one core team member must be checked and confirmed by another core team member before authorization, with the independent fund administrator overseeing fund movements across on-chain and off-chain assets.

Investors themselves self-custody TBILL tokens in their own private wallets, and the tokens are transferable only between whitelisted wallets after KYC/KYB onboarding. OpenEden also states the TBILL fund is managed by BNY Investments, while BNY serves as custodian/manager for underlying Treasury assets, adding an institutional custody layer outside the protocol’s own operational keys. The precise internal signer roster, threshold split, and wallet custody architecture for each chain in scope are not publicly verifiable as of 2026-09-04.

Evidence (6)

smart-contract

two sources

As of September 6, 2026. Dune MCP was unavailable; therefore privileged-address ownership, decoded admin events, timelock execution history, renounced roles, and current implementation state are Not verifiable as of September 6, 2026. Addresses / verification

  • Ethereum TBILL proxy: 0xdd50C053C096CB04A3e3362E2b622529EC5f2e8a; Etherscan identifies it as an ERC1967Proxy, implementation 0xc4545Bf8...3Dab7c048.
  • Arbitrum TBILL proxy: 0xF84D28A8D28292842dD73D1c5F99476A80b6666A; Arbiscan identifies it as an ERC1967Proxy, implementation 0x78365404...471727a07.
  • Solana mint: 4MmJVdwYN8LwvbGeCowYjSx7KoEi6BJWg8XXnW4fDDp6; XRPL issuer/currency: rJNE2NNz83GJYtWVLwMvchDWEon3huWnFn / TBL. These are independently cross-listed, but program/issuer-admin verification is Not verifiable as of September 6, 2026. Architecture and privileged controls EVM design comprises an upgradeable ERC-4626-style vault, Controller, FeeManager, KYC Manager, T-Bill price oracle, and OpenZeppelin TimelockController. The audited design assigns Controller admin/operator pause rights; FeeManager owner fee and limit controls; vault owner treasury, oracle, KYC, controller, operator and upgrade controls; operator off-ramp, withdrawal-queue processing, epoch and service-fee functions; and oracle admin/operator price controls. User USDC → Vault proxy → implementation → TBILL ↘ Controller / KYC / FeeManager / Oracle ↘ operator → off-ramp / treasury / redemption queue ↘ Timelock → treasury-address changes (claimed 24h delay) Risk assessment
  • Users cannot rely on fully permissionless exits: wallets are whitelisted, redemptions may enter a queue, and operators process withdrawals.
  • A compromised admin/operator set could pause deposits/withdrawals, alter fees and limits, redirect treasury/off-ramp destinations, manipulate oracle parameters, or upgrade the EVM implementation. The documented 24-hour treasury timelock is a mitigation, not proof of current on-chain enforcement.
  • Worst case: frozen redemptions, dilution or arbitrary token behavior after upgrade, redirected on-chain liquidity, and loss of access to the off-chain redemption process. Most backing assets are reportedly held with custodians, limiting—but not eliminating—smart-contract drain exposure. Contradiction / evidence gap: OpenEden describes contracts as publicly verifiable and audited, while current explorer pages show proxy deployments and “No Contract Security Audit Submitted”; audit scopes are historical code commits, not demonstrated current deployments.
Admin can drain
Yes
Upgradeable
Yes
Evidence (6)

audit

one source

Corrected publication metadata and findings for Hacken’s OpenEden ERC20 audit.

Auditor
Hacken
Report date
2023-10-18
Scope
Ethereum; OpenEdenVaultV2, Controller, FeeManager, TBillPriceOracle, Timelock and related contracts; repository commit 4aed24dac07c442ad0fca131b4749d950465d5be.
Findings
2 critical; 0 high; 1 medium; 6 low; 14 observations.
Fix status
16 resolved; 7 accepted; 0 mitigated. Critical findings Missing KYC Verification in deposit() and withdrawal-queue DoS were marked fixed.
Report url
https://hacken.io/audits/openeden/sca-openeden-erc20-oct2023/
Report id
doc:026c4c22c741aac9
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Hacken smart-contract security assessment of OpenEden Vault V4.

Auditor
Hacken
Report date
2024-12-10
Scope
Ethereum, Arbitrum and Base; OpenEdenVaultV4Impl and related contracts; repository commits 980995254706f34187440f9755c3507b6f647588 to 1299050d098a626fffa2a652545ee40abb9f1d7a.
Findings
0 critical; 0 high; 2 medium; 1 low; 4 observations.
Fix status
3 resolved; 1 accepted; 3 mitigated. Oracle-output validation and fee-transfer observations were fixed; KYC-ban and weekend-check issues were mitigated; integer casting was accepted.
Report url
https://hacken.io/audits/openeden/sca-openeden-vault-nov2024/
Report id
doc:206a49db2f71170b
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Hacken smart-contract security assessment of OpenEden Vault V3.

Auditor
Hacken
Report date
2024-02-16
Scope
EVM/Solidity; OpenEdenVaultV3Impl, FeeManager, PartnerShip and interfaces; repository commit d09f86cb9827242dc6e76033a60c7a464aebe27d.
Findings
0 critical; 0 high; 1 medium; 1 low; 4 observations.
Fix status
1 resolved; 5 accepted; 0 mitigated. tx.origin authorization was fixed; underlying-token withdrawal capability was accepted.
Report url
https://hacken.io/audits/openeden/sca-openeden-vault-jan2024/
Report id
doc:30092f817ff6f1cf
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published HackenProof contest finding for OpenEdenVaultV4.

Auditor
HackenProof
Report date
2025-07-22
Scope
OpenEdenVaultV4Impl, KycManager and DoubleQueueModified at commit d18288e944df21729b18d430b2afec2da99b6287.
Findings
0 critical; 1 high; 0 medium; 0 low. Service-fee claim can undercollateralize TBILL and cause protocol-wide denial of service.
Fix status
Not verifiable as of 2026-09-06; report state is disclosed, with no public remediation confirmation.
Report url
https://hackenproof.com/reports/OPENEDSC-153
Report id
doc:360c88275630715c
Covers deployed code
No
Unresolved high
1
Evidence (1)

audit

one source

Verichains Public Audit Report, version 1.1.

Auditor
Verichains Lab
Report date
2023-03-31
Scope
EVM TBILL Vault; BaseVault.sol, OpenEdenVault.sol, KycManager.sol and ChainlinkAccessor.sol.
Findings
Critical: 0; high: 0; medium: 0; low: 0 publicly reported.
Fix status
No reported vulnerabilities; post-deployment remediation status is Not verifiable as of 2026-09-06.
Report url
https://github.com/verichains/public-audit-reports/blob/main/Verichains%20Public%20Audit%20Report%20-%20OpenEden%20Vault%20-%20v1.1.pdf
Report id
doc:75b8752f69181d34
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Verichains Public Audit Report, version 1.0.

Auditor
Verichains Lab
Report date
2023-03-29
Scope
EVM TBILL Vault; BaseVault.sol, OpenEdenVault.sol, KycManager.sol and ChainlinkAccessor.sol.
Findings
Critical: 0; high: 0; medium: 0; low: 0 publicly reported.
Fix status
No reported vulnerabilities; post-deployment remediation status is Not verifiable as of 2026-09-06.
Report url
https://openeden.com/static/Verichains%20Public%20Audit%20Report%20-%20OpenEden%20Vault%20-%20310323.pdf
Report id
doc:a1e18002d6a8a229
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Independent audit of TBILL Vault critical operations and process controls—off‑chain fund and operational procedures, including KYC processes, valuation methodologies, and asset transfer and custody procedures. This is a traditional financial/process audit, not a smart contract code audit.

Auditor
Ernst & Young
Report date
2024-05-01
Scope
Off‑chain operations of TBILL Fund/Vault: KYC, valuation methodologies, asset transfer and custody controls, and related fund‑manager processes. Does **not** cover deployed smart contract bytecode; coverage of on‑chain contracts is Not verifiable as of 2026-09-04.[4][11][14]
Findings
Protocol materials state that Ernst & Young’s audit of TBILL Vault processes resulted in **no critical or high risk findings**.[1][4][14] Detailed issue list (if any medium/low process observations) is Not verifiable as of 2026-09-04.
Fix status
Reported as a satisfactory audit with no critical or high‑risk findings; any lower‑severity recommendations and their remediation status are Not verifiable as of 2026-09-04.[4][14]
Evidence (2)

audit

one source

Smart contract code review and security analysis of OpenEden TBILL Vault smart contracts, including Arbitrum deployment, conducted by Hacken OÜ. The earlier report (Oct 2023) and a later report (Jan–Feb 2024) assess vault smart contract security, documentation, code quality, and test coverage.

Auditor
Hacken
Report date
2023-10-09
Scope
TBILL Vault smart contracts on Ethereum and Arbitrum (and possibly other EVM chains) governing minting, redemption, and vault control logic. Exact chain coverage and bytecode-match to all current deployed contracts on Ethereum, Arbitrum, Solana, and XRPL are Not verifiable as of 2026-09-04.[2][7][9][10]
Findings
Oct 2023 audit: Hacken identifies **1 medium** and **1 low** severity issue; no critical or high vulnerabilities, with an overall security score of 9/10.[7] Jan–Feb 2024 audit: Hacken reports **0 critical, 0 high, 1 medium, 1 low** severity issues, leading to a security score of 10/10 on code security and an overall project score of 9.6/10.[9] Specific issues mentioned include a function that allows withdrawal of tokens including the underlying (accepted risk) and an authorization pattern using `tx.origin` (fixed).[9]
Fix status
For the Jan–Feb 2024 audit, Hacken notes one issue as **Accepted** (business/architectural decision) and one as **Fixed**, indicating remediation of at least part of the findings.[9] The Oct 2023 report mentions medium and low issues but the detailed post‑audit remediation status is not fully described in the brief snippet; overall, Hacken considers the project high‑security with remaining issues documented.[7][9]
Evidence (3)

audit

one source

OpenEden TBILL smart-contract audit. The report states 0 critical, 2 high, 1 medium, and 5 low findings in the audit table for the October 2023 review, and says remediation for at least one issue was completed by adding KYC validation to deposit(). The report scope is the OpenEden Vault v2 audit repository at commit 4aed24d..., which indicates the report covers specific code at that commit; deployed-code bytecode match is Not verifiable as of 2026-08-29 from the provided sources.

Auditor
Hacken
Report date
2023-10-17
Scope
OpenEden vault smart contracts in repository https://github.com/OpenEdenHQ/openeden.vault.v2.audit at commit 4aed24dac07c442ad0fca131b4749d950465d5be
Evidence (1)

audit

one source

Hacken — Smart Contract Code Review and Security Analysis Report for OpenEden, published October 31, 2023. Scope: OpenEdenVaultV2, Controller, DoubleQueueModified, FeeManager, KycManager and interfaces at commit 4aed24d. Findings: 2 critical, 0 high, 1 medium, 6 low, 14 observations.

Status: 16 resolved, 7 accepted. Covers deployed code: Not verifiable as of 2026-09-04; commit-to-bytecode match not established. EVM only; Solana/XRPL not covered.

Auditor
Hacken
Report date
2023-10-31
Scope
Ethereum/Arbitrum EVM TBILL Vault V2; repository commit 4aed24d
Findings
2 critical; 0 high; 1 medium; 6 low; 14 observations
Fix status
16 resolved; 7 accepted; 0 mitigated; deployed-bytecode match not established
Evidence (1)

audit

one source

Financial statement audit of the TBILL Fund (professional fund structure), conducted annually in line with regulatory reporting requirements. This is a traditional fund financial audit, not a DeFi smart contract security audit.

Auditor
TJ Assurance Partners PAC
Report date
2024-05-01
Scope
Off‑chain **fund financials** (balance sheet and financial statements) of TBILL Fund; no indication of smart contract code review or bytecode-match coverage. Deployed on‑chain code coverage is Not verifiable as of 2026-09-04.[11][14]
Findings
Publicly available snippets only confirm that TJ Assurance performs annual financial audits; specific findings (critical/high/medium) are Not verifiable as of 2026-09-04.[14]
Fix status
Not verifiable as of 2026-09-04; no detailed remediation discussion is publicly visible in retrieved materials.[14]
Evidence (2)

audit

one source

Smart contract security audit of the OpenEden TBILL Vault (OpenEden smart contracts providing tokenized US Treasury Bill exposure). The report describes automated scanning plus manual review of the vault smart contract code and design for security flaws, focused on the version of the OpenEden smart contract provided for review.

Auditor
Verichains
Report date
2023-03-31
Scope
On-chain smart contracts for the TBILL Vault (token minting/redemption and related logic). Exact contract addresses and bytecode-match to currently deployed contracts are Not verifiable as of 2026-09-04.[2][3][5]
Findings
Verichains reports **no vulnerabilities** in the audited version of the OpenEden TBILL Vault smart contract.[3][5] No critical, high, medium, or low issues are listed; the contract version in scope was assessed as free of identified security flaws.[3][5]
Fix status
No issues identified; no remediation required. The report does not discuss post‑deployment fixes, only that the audited version had no findings.[3][5]
Evidence (2)

audit

one source

TBILL Vault smart contract audit; OpenEden’s docs say the vault was formally audited by Verichains for potential security flaws. The linked report is dated March 2023 and is the earliest TBILL Vault smart-contract audit in the current source set. Fixedness/fix status for individual findings is not fully verifiable from the snippets provided.

Bytecode-match to deployed code: Not verifiable as of 2026-08-29.

Auditor
Verichains
Report date
2023-03
Scope
TBILL Vault smart contract
Evidence (2)

Team & Reputation

founders

two sources

OpenEden’s TBILL product is run by a small, fully public team of ex‑Gemini APAC executives with a regulated fund structure and a real-world corporate footprint, not an anonymous web-only project. Founders & senior team

  • Jeremy Ng – Founder/CEO of OpenEden and portfolio manager of the TBILL Fund’s asset manager.
  • Former Gemini APAC CEO, set up Gemini’s Singapore office in 2020 and built the team to ~50.
  • ~24 years in institutional finance, fintech and digital assets.
  • Eugene Ng – Co‑founder of OpenEden.
  • Previously Head of Business Development, Asia Pacific at Gemini.
  • Additional staff (e.g., product lead Timothy Chong) are listed on startup directories, reinforcing that the team is public, not anonymous. Prior projects, track record, hacks
  • Both founders were part of the founding team of Gemini APAC, with roles in regional leadership and business development.
  • No evidence in retrieved sources of prior protocol hacks or catastrophic failures linked to their past work. Not verifiable as of 2026-09-04. Corporate structure, offices, onshore/offshore
  • TBILL tokens are issued by Treasury Bills Institutional Liquidity Limited, a BVI‑regulated professional fund; tokens are offered only to “Professional Investors” under BVI law.
  • OpenEden describes itself as a group of entities including:
  • A BVI regulated professional fund (TBILL Fund).
  • A Bermuda‑licensed digital asset business registered as a segregated accounts company.
  • Jeremy Ng is also CEO and Chief Portfolio Manager of Adam Eve Capital, a wholly owned fund manager regulated by the Monetary Authority of Singapore (MAS) that manages the TBILL Fund.
  • Company profiles list Singapore as the base for OpenEden/River Labs Pte Ltd (TBILL Vault developer), indicating a real onshore presence alongside offshore fund vehicles. Real business vs. web front – credibility signals
  • Regulated entities in BVI, Bermuda, and MAS‑supervised Singapore suggest a substantive compliance footprint rather than a pure web shell.
  • Partnerships and coverage by major industry players (e.g., Ripple’s $10m allocation to TBILL on XRPL, BNY appointed for custody/management) indicate institutional engagement.
  • Docs explicitly separate the tech developer (River Labs Pte Ltd) from the regulated fund issuer, consistent with institutional structuring. No physical office address was found in the retrieved data; precise office location is Not verifiable as of 2026-09-04.
Evidence (13)

general reputation

one source

OpenEden TBILL is generally perceived as a regulated, institutional-facing tokenized T‑bill product with Singapore regulatory framing, but it remains a relatively new player with limited independent track record and some unresolved risk questions. Founders / team / investors

  • OpenEden was co‑founded by Eugene Ng (ex‑Gemini, ex‑J.P. Morgan) and Jeremy Ng (former CEO Asia of Gemini), both public, finance‑background profiles.
  • The protocol positions itself as an institutional product with regulated SPVs in Singapore investing in U.S. Treasury bills, and markets relationships with regulated custodians and service providers.
  • Specific equity investors and cap table details are Not verifiable as of 2026‑09‑04 from independent sources. Audits / external reviews
  • Smart‑contract audits are mentioned in marketing material but detailed reports and auditor names are not consistently available via independent repositories; where referenced, they appear limited in scope to token contracts rather than the full legal‑structural stack.
  • No comprehensive independent DeFi risk review (e.g., DefiSafety‑style) was found; Not verifiable as of 2026‑09‑04. Regulatory / legal posture
  • OpenEden states that TBILL tokens represent shares in a Singapore‑incorporated, regulated fund structure holding short‑term U.S. Treasuries, aimed at being compliant with Singapore securities laws.
  • There are no publicly reported regulatory enforcement actions, sanctions listings, or court cases against OpenEden, its TBILL product, or named founders in major databases and news as of the latest searches. Criticisms, sentiment, and unresolved concerns
  • Market sentiment in crypto media and institutional commentary is cautiously positive, emphasizing tokenized T‑bills for on‑chain yield and the professional pedigree of the founders.
  • Key structural risks raised by independent commentators include:
  • Off‑chain SPV and custody risk (insolvency of issuer or custodian; segregation of assets).
  • Regulatory perimeter risk: reliance on Singapore regime; questions about treatment for non‑Singapore investors and secondary trading on various chains.
  • Transparency gaps: limited real‑time disclosure of underlying portfolio, auditor of the fund/SPV, and full legal documents via independent sources.
  • No credible allegations of fraud, rug pull, or current insolvency tied specifically to OpenEden TBILL were found as of 2026‑09‑04. Overall, reputation is professionally positive but still thin, with trust resting heavily on founders’ TradFi/crypto backgrounds and Singapore regulatory framing, while transparency around off‑chain structures and comprehensive audits remains an unresolved concern for institutional risk teams.
Evidence (5)

Economy

TVL: $245.8M

model

one source

Economic model — OpenEden TBILL (reviewed September 6, 2026)

  • Strategy/assets in: Investors deposit USDC and mint TBILL, an NAV-based claim on a professionally managed fund holding short-duration U.S. Treasury bills and a small USD liquidity reserve. Target weighted-average maturity is under three months; bills are rolled as they mature.
  • Yield source: T-bill discount accretion/reinvestment, reflected through rising NAV/token price, less expenses. This is primarily organic Treasury yield, not emissions or staking rewards. Exact organic/subsidized percentage is Not verifiable as of September 6, 2026; organic_yield_pct is therefore null.
  • Risk profile: Directional exposure to short-duration USD sovereign rates and U.S. sovereign/custody/liquidity risk; not market-neutral. Interest-rate mark-to-market losses remain possible before maturity. No disclosed leverage, looping, restaking, or external DeFi strategy; the actual leverage ratio is Not verifiable as of September 6, 2026 and is null.
  • Access/lock-up: Permissioned product requiring KYC/KYB; minting, redemption, and transfers are limited to whitelisted wallets. No stated fixed lock-up, but liquidity is gated by eligibility and redemption processing. First deposit is at least 100,000 USDC; later deposits and redemptions generally have a 1 USDC minimum.
  • Withdrawals/fees: TBILL is burned and USDC is paid at the processing-time NAV, net of fees. Redemptions use FIFO and are typically processed on the next U.S. business day. Fees are 30 bps annual TER plus 5 bps on subscription/redemption.
  • Revenue/collateral: The 30-bps TER funds management, custody, compliance, audits, and operations. DeFiLlama reports annualized fees of $662,472, 30-day fees of $54,301, and cumulative fees of $509,052; these are aggregator fee metrics, not confirmed protocol net revenue.
  • TVL: DeFiLlama reports $286.09m: Ethereum $194.94m (68.1%), XRPL $75.22m (26.3%), Solana $10.13m (3.5%), Arbitrum $5.80m (2.0%). Product-level and historical trend data are not exposed in the fetched page. Dune comparison and on-chain TVL are Not verifiable as of September 6, 2026.
  • APY: DeFiLlama shows 3.42% average APY across four pools and “Stable 96” 30-day stability. Longer APY history, volatility, and sustainability are Not verifiable as of September 6, 2026. Contradiction: An older user agreement states redemption can take T+3 U.S. business days, while current documentation says typically one business day. Treat the current documentation as the operational description, but confirm against executed fund documents.
Evidence (5)

reserves

two sources

Status as of September 6, 2026 — reserve verification

  • Liquid reserves: null
  • Liabilities: null
  • Reserve composition: OpenEden describes TBILL as backed 1:1 by short-dated U.S. Treasury bills plus a limited USD liquidity reserve. The T-bills are reportedly managed by BNY Investments and held in segregated custody with BNY; fiat liquidity is held off-chain with regulated custodians or remains in transit. This is an issuer disclosure, not an independently verified reserve figure.
  • Custody / legal structure: The issuer is Treasury Bills Institutional Liquidity Limited, a BVI professional fund. OpenEden states that assets are held in segregated, bankruptcy-remote arrangements and that a third-party fund administrator provides daily NAV and monthly net-asset reports.
  • Control: On-chain assets are governed through multisignature approvals, including the independent fund administrator, with role-based permissions, a 24-hour timelock for treasury-address changes, and price-guard controls. Off-chain asset movements require dual authorization and administrator oversight.
  • Addresses: Public token/vault references include Ethereum TBILL 0xdd50C053C096CB04A3e3362E2b622529EC5f2e8a and Arbitrum TBILL 0xf84d28a8d28292842dd73d1c5f99476a80b6666a; these are token/vault addresses, not reserve-custody addresses. Solana and XRPL token identifiers are published by analytics/explorer sources, but reserve-wallet ownership and balances are not established. Contradiction / data-quality callout: DeFiLlama currently displays approximately $239.02m of on-chain market capitalization and includes BSC, while the supplied chain set excludes BSC; RWA.xyz previously showed approximately $87.19m. These are aggregator figures, not reserve attestations, and are materially inconsistent. No raw Dune query or reproducible reserve-wallet balance was available in this run. On-chain balances via Dune: Not verifiable as of September 6, 2026. Reserve policy / attestations: Daily NAV and monthly administrator statements are claimed; an EY controls audit is also described. The underlying reports were not independently retrieved and matched to a current reserve amount.
Evidence (5)

tokenomics

one source

OpenEden TBILL does not have a native governance/tokenomics token in the usual DeFi sense. The core product is a tokenized U.S. T‑Bill instrument, typically referenced as TBILL or “OpenEden TBILL token,” representing claims on short‑term U.S.

Treasuries held by a regulated SPV. Because Dune/on‑chain queries are unavailable in this run, all on‑chain specifics fall under: Not verifiable as of 2026‑09‑04. ### 1. Native token, supply, market cap

  • Native token: A yield‑bearing tokenized T‑Bill asset (TBILL) rather than a speculative protocol token.
  • Contract addresses (Ethereum, Arbitrum, Solana, XRPL): Not verifiable as of 2026‑09‑04.
  • Total vs circulating supply, market cap, FDV: Not verifiable as of 2026‑09‑04. Public information and listings (e.g., DefiLlama, centralized exchange pages) focus on OpenEden’s T‑Bill token/notes structure, not a governance token with an FDV curve. ### 2. Utility, governance, revenue
  • Utility: TBILL represents tokenized exposure to U.S. Treasury bills; holders earn the underlying T‑Bill yield (net of fees) rather than emissions or inflationary rewards.
  • Governance role: No evidence of a separate governance token; governance appears driven by corporate/legal structures, not token voting.
  • Revenue share / buybacks / burns / staking rewards: OpenEden charges fees at the SPV/product level; there is no evidence of protocol‑token buybacks, burns, or staking rewards linked to a native token. Any claims of additional token utility beyond representing T‑Bill exposure would be unverified marketing claim unless backed by independent sources; none were found. ### 3. Emissions, unlocks, allocations
  • Emissions schedule & unlocks: No native emissions or vesting schedules identified; OpenEden materials and analytics platforms describe a tokenized security‑like instrument, not an inflating DeFi token.
  • Team/investor/treasury/community allocations: Not verifiable as of 2026‑09‑04; no credible breakdowns surfaced in independent sources. ### 4. Concentration, controls, liquidity
  • Top‑holder concentration & insider wallets: Not verifiable as of 2026‑09‑04.
  • Admin/mint/blacklist/fee‑switch controls: TBILL is issued via a regulated issuer; issuance/redemption and potential transfer restrictions are likely governed by legal and KYC/AML processes, but exact smart‑contract control schema is not independently documented.
  • DEX liquidity, main listings: Specific pools, depth, and pair addresses across Ethereum, Arbitrum, Solana, and XRPL are Not verifiable as of 2026‑09‑04. Overall, OpenEden TBILL should be treated as tokenized real‑world asset exposure with regulatory and off‑chain control, not a typical DeFi governance token with emissions and FDV.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 is primarily a market stress event, not a direct protocol-level failure for OpenEden TBILL. TBILL is structured as a tokenized U.S. Treasury Bills vault with token price tied to NAV, not to Bitcoin, so the direct asset-price link to BTC is weak. Likely impact under stress:

  • TBILL token NAV: No direct mechanical impairment from BTC falling below $10,000 is stated in the available sources; TBILL is backed by U.S. T-Bills and USD custody, and its price reflects NAV.
  • Redemptions / liquidity: A sharp crypto selloff can reduce market liquidity and risk appetite, which could pressure on-chain flows into yield products, but this is an inference rather than a directly verified OpenEden-specific outcome. Not verifiable as of 2026-09-04.
  • USDC settlement / pricing: OpenEden states TBILL is denominated in USD and its USDC price tracks the USDC/USD exchange rate; if USDC de-pegs, TBILL’s USDC-denominated price would rise accordingly, and holders may redeem into other digital assets if USDC is unavailable.
  • Underlying asset risk: The relevant economic risk for TBILL is not BTC direction but U.S. Treasury price/yield risk and custody/counterparty risk, since bond prices fall when interest rates rise and OpenEden explicitly notes that TBILL value can fall with rising rates. What cannot be verified from the provided sources:
  • Chain-by-chain exposure across Arbitrum, Ethereum, Solana, and XRPL.
  • Current TVL, reserve composition, or redemption utilization by chain.
  • Any BTC-triggered covenant, liquidation, or oracle dependency for TBILL. Not verifiable as of 2026-09-04. Bottom line: a BTC crash below $10,000 would likely affect OpenEden TBILL only through second-order market stress—liquidity, investor sentiment, and broader crypto deleveraging—while the core TBILL asset value should remain anchored to Treasury/NAV mechanics rather than Bitcoin itself.
Evidence (5)

stress scenario - largest collateral depegs 20%,

unverified

OpenEden TBILL is described as being backed 1:1 by a pool of U.S. T-bills and USD, with token price based on NAV per token. Under a stress scenario where the largest collateral component depegs by 20%, the protocol’s own docs imply the token price would not remain unchanged, because TBILL’s price is defined off total assets less claimable fees divided by circulating supply.

The direction and size of the impact depend on which asset is depegging: if the depegging asset is the USDC/liquidity leg, OpenEden says TBILL in USDC terms would rise when USDC depegs, since TBILL is denominated in USD and redemption can be in other digital assets if USDC is unavailable. If the depegging asset is the reserve asset side (for example, Treasury exposure or another backing asset losing value), then NAV would fall and TBILL price would fall proportionally to the impaired collateral value, but the exact post-shock price is Not verifiable as of 2026-09-04 from the available sources. OpenEden’s materials do not provide a chain-by-chain collateral breakdown for Arbitrum, Ethereum, Solana, or XRPL in the retrieved sources, so the exposure split is Not verifiable as of 2026-09-04.

A key risk note from Hacken is that even a small reduction in underlying backing can create undercollateralization and break core functions that depend on the rate oracle, which means a 20% collateral shock could plausibly trigger severe operational stress rather than just a mark-to-market loss.

Evidence (8)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Stress scenario: top counterparty becomes insolvent For OpenEden TBILL, the loss path is primarily off-chain at the reserve layer, not inside the on-chain vault code. The TBILL reserve assets are described as short-term U.S. T-bills plus money market fund units, repo agreements, and BUIDL tokens held in custodian accounts; OpenEden’s own risk disclosure says defaults by repo counterparties can cause failure to repurchase securities and may reduce the value of the underlying issuer’s assets.

If the insolvent counterparty is a repo counterparty or another reserve-asset counterparty, the immediate economic loss is borne by the TBILL Fund / issuer-level reserve pool, not by the smart contract itself. Who absorbs it:

  • First, the reserve portfolio absorbs the impairment through mark-to-market loss or realized shortfall.
  • If losses exceed the reserve cushion, TBILL token holders are economically exposed, because the token is backed by the fund’s assets rather than a promised third-party guarantee.
  • The docs do not disclose any external insurer, sponsor guarantee, or explicit compensation waterfall that makes users whole in a counterparty default. Compensation / recovery path:
  • Recovery would come from counterparty bankruptcy proceedings, collateral liquidation, or whatever contractual repossess/close-out rights exist at the fund level; this is not described as automatic on-chain compensation.
  • OpenEden states the fund’s assets are segregated from group companies, so operational affiliates are not meant to commingle capital with reserve assets.
  • The public materials reviewed do not provide a verified, detailed loss-allocation schedule beyond segregation and custody controls. Smart-contract impact path:
  • The on-chain contracts are mainly a mint/redeem wrapper around off-chain assets; a counterparty insolvency does not by itself trigger an on-chain liquidation mechanism.
  • The likely contract-level effect is price/oracle adjustment, paused minting/redemptions, or slower redemptions if the fund’s NAV falls or liquidity is impaired; audits note the presence of admin controls, pausing, and a withdrawal queue/failover concerns.
  • Because the reserve assets are mostly held with regulated custodians, a smart-contract breach is not the primary transmission channel for this stress; the main channel is NAV impairment at the fund layer. Cross-chain note: the available web evidence does not verify chain-by-chain exposure breakdown or different loss mechanics across Ethereum, Arbitrum, Solana, and XRPL. Not verifiable as of 2026-09-04.
Evidence (8)

stress scenario - committed fraud by the DAO or owners

two sources

Committed fraud by the DAO or owners is not verifiable as of 2026-09-04. The strongest available evidence instead shows a regulated, KYC-gated RWA structure with audited smart contracts and custody described by OpenEden, but those are *self-reported* and do not independently prove absence of misconduct. What can be said for the stress scenario:

  • There is no direct evidence in the provided sources that the DAO or owners committed fraud.
  • The protocol’s stated design includes regulated custodians, KYC/AML screening, and multisig controls, which may reduce operational fraud risk, but these are unverified marketing / protocol claims unless independently corroborated.
  • Independent security reports do show smart-contract weaknesses and potential denial-of-service or misconfiguration risks, including issues around fee claims, access control, and withdrawal handling; however, these are code-risk findings, not evidence of fraud by the DAO or owners.
  • The Arbitrum application also states the system can cancel and re-issue misappropriated TBILLs, which indicates an operational response mechanism, but this remains a protocol claim. Bottom line: for a “committed fraud by the DAO/owners” stress case, the event is Not verifiable as of 2026-09-04 based on the provided sources. The plausible risk to model is governance / operator abuse or custody failure, but that cannot be confirmed here as an actual historical fraud event.
Evidence (7)

stress scenario - primary yield source negative 30d,

two sources

For a 30d negative primary-yield stress, OpenEden TBILL is exposed mainly to the risk that the underlying Treasury-bill portfolio’s value or token price declines when rates rise; OpenEden states that if interest rates rise, the fund’s portfolio value and the TBILL token price may decline. In that scenario, the product’s yield distribution would not be a positive carry source over the stress window, and holders could see lower 30d total return or even a negative mark-to-market outcome, depending on the size and speed of the rate move. This stress does not appear to create a separate leverage or reflexive on-chain yield loop in the materials reviewed; TBILL is described as direct exposure to short-dated U.S.

T-bills with 1:1 backing, and the Arbitrum governance post says there is no first-loss equity provided by the issuer. The practical downside is therefore primarily asset-price / NAV compression, not an endogenous DeFi reward-collapse mechanism. A few constraints are not verifiable as of 2026-09-04 from the available non-onchain sources: chain-by-chain exposure split across Arbitrum, Ethereum, Solana, and XRPL; current TVL by chain; and whether TBILL’s 30d realized yield is actually negative versus merely below a benchmark.

One data point on RWA.xyz shows TBILL at 30D APY of 3.30% and 7D APY of 3.08%, which is inconsistent with a negative 30d yield claim; however, this is an aggregator view and not raw on-chain verification. So, under this stress, the protocol’s key risk for users is capital impairment / lower NAV, while the yield engine itself remains fundamentally tied to U.S. Treasury rates rather than crypto-native emissions.

Evidence (6)

Governance & Legal

governance

one source

As of September 13, 2026, TBILL governance remains primarily company/fund-controlled, not DAO-controlled. The issuer is Treasury Bills Institutional Liquidity Limited, a BVI-regulated professional fund; the vault developer is identified as River Labs Pte Ltd. The fund, custodians, administrator and OpenEden operational team control issuance, redemption, treasury movements, compliance, and regulated operations.

OpenEden Governance launched January 28, 2026. EDEN must be staked into xEDEN and delegated; proposals are discussed in Discord and voted on through Tally. At launch, only OpenEden Foundation-submitted proposals were eligible.

The stated scope concerns incentives, participation and selected product initiatives, and explicitly does not replace legal or regulatory oversight. It is therefore a real but constrained governance layer, not control over the TBILL fund, issuer, custodians, contracts or frontend. The TBILL vault uses role-based controls and a multisig.

The independent fund administrator is included in fund-flow approvals and has oversight over on-chain and off-chain asset movements. A 24-hour timelock applies to changing the treasury-wallet address. Because authorized multisig/admin signers can approve fund movements without a token-holder governance vote, admin_can_drain is assessed true under the requested definition, despite custody segregation and operational checks.

Multisig threshold, complete signer list, signer identities, independence, emergency modules/bypass, and voting concentration/top holders: Not verifiable as of September 13, 2026. Dune MCP was unavailable for this run, so no on-chain signer, holder, or proposal-execution claims are made. Solana and XRPL control arrangements are likewise Not verifiable as of September 13, 2026.

CONTRADICTION: the supplied user-agreement evidence names “Treasury Bills International Liquidity Limited,” while the BVI regulator lists “Treasury Bills Institutional Liquidity Limited.” The discrepancy requires legal-document reconciliation; the regulator listing is the stronger source for current entity status. Registration number and directors: Not verifiable as of September 13, 2026.

Timelock
Yes
Timelock delay hours
24
Admin can drain
Yes
Dao governance
No
Evidence (5)

legal & regulatory

two sources

OpenEden TBILL appears to be issued by Treasury Bills Institutional Liquidity Limited (the “TBILL Fund”), described as a professional fund incorporated in the British Virgin Islands and regulated by the BVI Financial Services Commission. OpenEden also describes an affiliated Singapore fund-management entity, but the exact operating entity behind all products is not fully verifiable from the available web sources alone. The strongest supported jurisdictional picture is BVI for the issuer/fund and Singapore for an affiliated manager.

Access is restricted: TBILL is stated to be available only to Professional Investors under BVI law and U.S. Accredited Investors, with mandatory KYC/AML (and in some sources KYT) screening before wallet whitelisting. Transfers are limited to whitelisted wallets, and blacklisting of addresses is described in the Arbitrum governance material.

The available materials also include broad restrictions on persons in prohibited jurisdictions and a forum language stating the product is not offered where licenses would be required. OpenEden’s site further states that disputes arising from product terms are litigated only in the courts of the relevant entity’s jurisdiction. I found no credible evidence in the retrieved sources of a regulator enforcement action, court case, or sanctions designation against OpenEden TBILL itself or its issuer/entity.

Not verifiable as of 2026-09-04. Data protection is addressed by an OpenEden privacy policy, but the specific legal entity responsible for all personal-data processing was not fully clear from the retrieved excerpts. Not verifiable as of 2026-09-04.

Legal-structure vs actual-risk note: the structure is a regulated BVI fund with an off-chain custody/whitelisting model, so the main risks are not “protocol code only” but issuer, custody, eligibility, and transfer-control risk. Claims about exact investment protection or enforceability beyond the stated fund/legal wrapper are not verifiable from the available sources.

Sanctioned
No
Entity
Treasury Bills Institutional Liquidity Limited (TBILL Fund); affiliated OpenEden Pte Ltd / Adam Eve Capital Pte Ltd mentioned in sources
Jurisdiction
British Virgin Islands (issuer/fund); Singapore (affiliated manager)
Evidence (5)

legal registries

two sources

GLEIF LEI registry unavailable at scan time. OFAC SDN screening of 'Treasury Bills Institutional Liquidity Limited', 'affiliated OpenEden Pte Ltd', 'OpenEden TBILL': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Treasury Bills Institutional Liquidity Limited
  • affiliated OpenEden Pte Ltd
  • OpenEden TBILL
Entity
Treasury Bills Institutional Liquidity Limited
LEI
9845001C7D9E8F6BD929
Jurisdiction
VG
Entity status
ACTIVE
Sanctioned
No
Evidence (3)

Stability

stability

one source

OpenEden TBILL is not its own stablecoin; OpenEden’s separate stablecoin product is USDO, while TBILL is a tokenized U.S. Treasury bill vault token minted against stablecoin deposits. A documented depeg history for the relevant stablecoin could not be verified from the gathered sources, so depeg_count, last_depeg_date, and max_depeg_pct are Not verifiable as of 2026-09-06.

The protocol-level stability answer is therefore also not verifiable as of 2026-09-06.

Own stablecoin
No
Stablecoin ids
  • USDO
Evidence (4)

Risks & Strengths

risks

two sources

OpenEden TBILL provides regulated-fund exposure to short-dated U.S. Treasury assets, but the principal risks are centralized administration, off-chain valuation, redemption liquidity, custody/legal access, and smart-contract control. The strongest residual concerns are that key operational powers and valuation dependencies remain centralized, while audited code does not eliminate upgrade, oracle, or execution risk.

On-chain TVL, balances, and chain-by-chain exposure: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Privileged contract administrationThe vault is upgradeable; administrators can pause operations, alter fees, withdraw tokens, and control redemption execution. Hacken notes fees could theoretically reach 100%, and the owner can withdraw USDC from the contract.HighMediumThird-party audits, role separation, pause controls, and operational monitoring are stated controls.High: audit coverage does not remove governance-key, upgrade, or insider-risk exposure.
Oracle and NAV dependencyTBILL pricing relies on an off-chain price process; the oracle and KYC components were outside Hacken’s audit scope. Incorrect or unavailable pricing could misprice minting or redemption.HighMediumPrice-deviation guards, daily market data, and NAV reporting are described.Medium-High: centralized oracle operation and excluded components remain material.
Redemption and liquidity stressRedemptions are queued and typically processed on the next U.S. business day; forced T-Bill sales during volatility could occur below mark-to-market value.MediumMediumShort target maturity, diversified maturities, and off-chain USD liquidity reserves.Medium: liquidity is not guaranteed intraday or under a run.
Custody and legal-access riskHolders receive contractual claims on fund net assets, not direct custody of individual T-Bills; access depends on the issuer, custodians, administrators, KYC, and applicable law.HighLowBVI fund regulation, qualified custodians, fund administration, audits, and KYC/KYB controls.Medium: legal, counterparty, sanctions, or service-provider failure could delay recovery.
Smart-contract and network failureExploits, unforeseen bugs, or supported-chain outages could interrupt transfers, minting, or redemption despite audits.HighMediumEIP-4626-based design, Verichains/Hacken reviews, monitoring, and emergency pausing.Medium-High: audits are point-in-time and do not cover every deployment or dependency.
Evidence (4)

strengths

two sources

OpenEden TBILL’s main strengths are: direct U.S. Treasury Bill exposure rather than more complex structured products, instant on-chain minting/redemption that fits DeFi workflows, strong regulatory/compliance positioning with a BVI-regulated fund and KYC/AML onboarding, institutional-grade transparency via audits, custodian reports, monthly attestations, and planned Proof-of-Reserves, and multi-chain accessibility across Ethereum and supported expansion to Arbitrum, Solana, and XRPL. The product also emphasizes short duration and high liquidity from the underlying T-bill market, which supports cash-management use cases.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 17 two independent sources, 25 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-29.