Pareto Credit

Green · 70/100

Executive summary

Pareto Credit is an institutional private credit marketplace on Ethereum that issues a synthetic dollar (USP) backed by loans to whitelisted borrowers, scoring 74/100 (green band) with high data confidence (86/100).

  • Security: Multiple Sherlock audits of USP (April 2025) and Credit Vaults (August 2025–June 2026) are documented; the USP audit identified at least one High finding (defaulted vaults valued at pre-default NAV) and three Medium findings (unclaimable withdrawals post-default, unlimited approvals, redemption DoS). Remediation status for most findings and bytecode match to deployed contracts are not verifiable as of September 2026. Omniscia audited governance (February 2026) with protocol-claimed resolution of all medium findings, but the underlying report is unverified. Active Immunefi bug bounty ($50k max) since March 2021.
  • Incidents: Zero realized loss. In March 2023, predecessor Idle Finance had ~$5.8M locked in the Euler exploit; 100% was recovered and redistributed by April 2023 after Euler's own recovery process.
  • Governance & custody: Multisig-led hybrid governance, not a full DAO. A 48-hour timelock controls the long-term fund; treasury/developer/pauser multisigs retain significant discretionary powers over team funds, vesting, operations reserve, and parameter changes. Assets are segregated by vault/tranche contract, not pooled custodially. Voting concentration and current multisig signers are not verifiable.
  • Top risks: (1) Borrower default and credit loss—funds lent directly to institutions (Fasanara, Bastion, Adaptive Frontier, FalconX); defaults impair USP backing and socialize losses via Stability Fund then sUSP holders. (2) Redemption liquidity—epoch-gated withdrawals; normal exit requires request + next-cycle claim; early exit may incur rate penalty. (3) Collateral depeg—audit notes protocol may mint USP at face value even if collateral depegs, risking undercollateralization. (4) Privileged admin—manager/owner can start/stop epochs, pause deposits/withdrawals, and configure vaults; no guaranteed immediate exit. (5) Oracle/valuation—third-party benchmark data for variable rates; provider, manipulation resistance, and fallback logic are not verifiable. Current Ethereum TVL, exposure concentration, borrower balances, and reserve adequacy are not verifiable as of September 2026 (Dune unavailable).
  • Strengths: Institutional-grade compliance (KYC/AML via Keyring, legal entity Idle DAO LLC Marshall Islands), doxxed founder team (Matteo Pandolfi CEO, Samuele Cester CPO, William Bergamo CTO) with multi-year Idle Finance track record, capital-efficient epoch-based vaults, documented Stability Fund (5% of fees) as first-loss buffer, and active API/manager console indicating operational maturity.
  • Unverified: Current reserves, treasury size, asset composition, and liabilities are not verifiable (historical disclosures conflict: ~$34k stables + $39k ETH/LRT in July 2024 vs. ~$13k stables + $37k BTC/ETH/LRT in January 2025). Circulating PAR supply, market cap, FDV, and deployed token address are not verifiable. Live collateral composition, largest collateral share, borrower concentration, and actual funded Stability Fund balance are not verifiable. Exact deployed-bytecode match for all audited contracts is not verifiable.
  • Recommended exposure: Conservative allocation only, treating this as early-stage institutional credit with unverified counterparty risk. Limit exposure to <5% of portfolio and require independent verification of: (1) current borrower identities, loan balances, and credit agreements; (2) Stability Fund adequacy vs. outstanding USP; (3) multisig signer identities and threshold; (4) deployed contract addresses and audit-report bytecode match; (5) redemption queue depth and actual withdrawal success rate over last 90 days. Favor senior/USP over junior/sUSP tranches if allocating. Monitor epoch cycles and avoid deposits near epoch boundaries. Exit if any borrower default is announced or if Stability Fund is disclosed as insufficient.
  • Open questions: (1) What is the current Stability Fund balance in USD and as % of total USP supply? (2) Who are the signers and threshold for treasury/developer/pauser multisigs? (3) What is the largest single-borrower exposure as % of total credit vault assets? (4) What are the deployed Ethereum addresses for ParetoDollar, Queue, Staking, and all live Credit Vaults, and do they match audited bytecode? (5) What is the average and P95 withdrawal time from request to claim over the last 90 days? (6) What oracle providers and fallback logic are used for variable-rate vault pricing? (7) What is the legal enforceability and recovery process for borrower defaults under Marshall Islands jurisdiction? (8) What is the current circulating supply and holder concentration of PAR governance token?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 11 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-06-17)
Incidents 20% 100 20.0 no open incidents
Governance 20% 50 10.0 no DAO governance
TVL 20% 0 0.0 TVL $159,981 = 0% of reference ($17,538,184,136)
Data confidence 86 7/7 critical categories; 13/41 verified facts; 41/41 fresh (180d)

Identification

protocol identification

two sources

Pareto Credit is an institutional private credit / RWA lending protocol on Ethereum that issues a synthetic USD (USP) and credit vault products; detailed on-chain verification is Not verifiable as of 2026-09-04. Identification

  • Name: Pareto Credit (often branded simply as Pareto)
  • Website: pareto.credit
  • Docs: docs.pareto.credit
  • Category: Institutional private credit marketplace / RWA lending with synthetic dollar (USP), credit vaults, and tranche lending
  • Launch date (protocol): Not precisely stated; the USP launch is reported May 15, 2025 in media coverage. Earlier social presence since 2019 relates to the team/brand, not necessarily mainnet deployment.
  • Chains: DefiLlama and third‑party analytics list Ethereum (TVL ~100% for pareto-credit slug) while MrDeFi mentions Optimism, Polygon, Arbitrum as broader Pareto Credit Vault deployments. For this assignment, focus chain is Ethereum.
  • Native / governance token: PAR; described as the governance / alignment token for the protocol’s participants, giving long-term stakers greater governance power and reward exposure. Cryptorank lists it as Pareto Credit (PAR). Key product contracts (conceptual; addresses not verifiable)
  • ParetoDollar (USP): ERC‑20 contract that mints USP when users deposit stablecoins (e.g., USDC, USDS). Deposits are routed into Credit Vaults; USP is a *synthetic dollar* backed by on-chain private credit rather than fiat reserves. Exact Ethereum contract address and explorer verification: Not verifiable as of 2026-09-04.
  • sUSP: Yield-bearing token received by staking USP; represents claim on yields from credit deployment. Address and verification: Not verifiable as of 2026-09-04.
  • Credit Vaults (IdleCDOEpochVariant / IdleCreditVault-based): Epoch-based lending vaults with AA/BB tranches, lending deposits to a single borrower per epoch, repaid with interest at epoch end. Specific vault, queue, and strategy contract addresses and their explorer verification: Not verifiable as of 2026-09-04. Fork lineage / upstream dependencies
  • Docs explicitly state Credit Vaults are built on top of IdleCDOEpochVariant and IdleCreditVault, indicating Pareto Credit builds on Idle Finance’s CDO / vault architecture rather than a pure ground-up implementation.
  • What changed vs. upstream Idle: Pareto adds institutional credit processes (whitelisted borrowers, private-credit underwriting), synthetic dollar USP, and RWA‑backed credit vaults; these are described as new protocol logic and integrations.
  • Audit status of changes: No independent audit reports for the Pareto-modified contracts were found in auditor repositories or GitHub in the available results; therefore Not verifiable as of 2026-09-04.
  • Malicious-modification history in similar forks: No records of malicious forks or exploit history specific to Pareto’s Idle-based vault lineage were surfaced in the searched results; Not verifiable as of 2026-09-04. Contradiction callout > Chain footprint and TVL: MrDeFi describes Pareto Credit as deployed across four chains (Optimism, Polygon, Ethereum, Arbitrum), while the DefiLlama entry for the pareto-credit slug shows Ethereum TVL and describes the protocol generally. Without on-chain queries or explorer address confirmation, multi-chain deployment and per-chain TVL breakdown are Not verifiable as of 2026-09-04.
Evidence (15)

maturity

two sources

Pareto Credit appears to have a real, functional product surface rather than a pure landing page. Its public docs describe an active v1 REST API with a base URL, API-key flow, and endpoints for vaults, tokens, transactions, and integrators, which is stronger than a marketing-only site. The docs also describe concrete user flows for deposits, withdrawals, and claims, including epoch gating and smart-contract interaction steps, and they name a separate manager app at manager.pareto.credit for real-time visibility into inflows and outflows.

That said, live execution quality cannot be fully verified here: Not verifiable as of 2026-09-04 for whether the web app currently processes deposits/withdrawals end-to-end without errors, or whether any links are broken in the live UI. The documentation itself suggests a mature product/UX stack, but the website content available here does not conclusively prove production uptime, actual user success rates, or absence of template artifacts. Open API: yes.

The docs explicitly state an active major version v1 API at https://api.pareto.credit/, provide a bearer-token authentication flow, and expose documented endpoints. Overall: Pareto Credit looks like an operating protocol with a documented front end, manager console, and public API, not just a static landing page; however, live app reliability and broken-link status remain Not verifiable as of 2026-09-04.

Evidence (5)

Security

bug bounty

one source

Pareto Credit has an active bug bounty program on Ethereum hosted by Immunefi. It has been live since 25 March 2021, with a maximum payout of $50,000 and rewards denominated in USD, paid in USDC for payouts under $10,000 and in USDC plus IDLE for larger payouts. The current scope includes specific smart contracts such as Senior Best Yield contracts, while Governance, Utilities, ERC-4626 wrappers, paused contracts, and deprecated/decommissioned contracts are out of scope.

Severity tiers include critical issues such as direct theft of user funds, permanent freezing of funds, protocol insolvency, and MEV leading to insolvency; high severity includes theft or permanent freezing of unclaimed yield; medium severity includes inability to operate due to lack of token funds or temporary freezing of funds. Publicly visible program materials do not show any disclosed paid-out results or completed bounty reports, so results are Not verifiable as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$50K
Since
2021-03-25
Evidence (3)

counterparty risks

unverified

As of September 6, 2026, public evidence indicates material external-counterparty exposure, but current balances and concentration are Not verifiable as of 2026-09-06 because Dune/on-chain verification was unavailable.

  • Institutional borrowers / RWA credit: USP collateral is lent directly to whitelisted institutional borrowers through Credit Vaults; documented Ethereum borrowers include Fasanara Digital, Adaptive Frontier, and Bastion Trading. FalconX exposure is documented on Optimism, while Bastion also lists Ethereum, Polygon, and Arbitrum. Defaults can create losses for USP; the stated loss waterfall is Stability Fund first, then reduction of sUSP value.
  • Stablecoin dependency: Minting/redemption uses USDC and USDS; AMM acquisition may involve USDT. This creates issuer, banking/custody, censorship, regulatory, and depeg risk.
  • Yield-source dependency: The USP queue can allocate to Pareto Credit Vaults and other whitelisted ERC-4626 strategies. Specific external ERC-4626 integrations, caps, and current allocations are Not verifiable as of 2026-09-06.
  • Oracle / manipulation risk: Public documentation references third-party benchmark data for variable-rate vaults, but does not establish the oracle providers, quorum, fallback logic, manipulation resistance, or current oracle configuration. Not verifiable as of 2026-09-06.
  • Bridges, custodians, CEX/MM exposure: No independently verifiable bridge, custodian, CEX, or market-maker exposure was identified. Not verifiable as of 2026-09-06.
  • Failure scenarios: borrower insolvency/default, stablecoin depeg or issuer freeze, delayed redemptions from weekly/monthly credit cycles, ERC-4626 integration failure, and oracle/benchmark error could impair liquidity or USP’s soft peg. Contradiction / data-quality callout: Public Pareto surfaces conflict: the app displayed $0 TVL and no active vault balances, while the marketing site displayed USP TVL of $3.6M and sUSP TVL of $2.8M; a separate roadmap claimed TVL above $180M. These figures are not reconciled and none is on-chain-verified in this run. Overall, dependency risk is high qualitatively because USP is a credit-backed synthetic dollar rather than a cash-reserve stablecoin; quantitative maximum exposure is unknown.
Evidence (6)

crypto custody

unverified

Pareto Credit’s custody is organized around on-chain smart-contract vaults and queues rather than a single off-chain custodian. Deposits go into Credit Vaults, withdrawals are processed in two steps through a withdraw queue across epochs, and vaults can be paused by the protocol’s security controls if needed. The docs also describe a separate non-custodial staking flow for USP, and borrower/collateral flows are routed through Credit Vaults, indicating assets are operationally segmented by vault/tranche and contract role rather than pooled under one omnibus wallet.

Segregated assets: true Withdrawal paused: not verifiable as of 2026-09-06 The available evidence supports segregation at the vault/tranche/contract level, but it does not verify whether all assets are legally segregated in a bankruptcy-remote sense for every product.

Segregated assets
Yes
Evidence (5)

incident

one source

Reverified and corrected Euler exposure event affecting Pareto’s predecessor, Idle Finance. On March 13, 2023, Euler suffered a donation/liquidation smart-contract exploit. Idle’s Euler-based Yield Tranches and related Senior/Junior Best Yield vault allocations were affected; approximately $5.8M of Idle-linked assets were locked or potentially impaired.

DAI Best Yield had already been fully rebalanced away from Euler and was unaffected. Idle paused affected products and recovered approximately $307K during the attack. After Euler’s recovery process, Idle received the corresponding recovered assets on April 12–13, 2023, swapped them back into the original asset mix, and restored 100% of affected deposits.

Contract implementations were updated to handle Euler’s broken eToken state, withdrawals were re-enabled, and products were rebalanced away from Euler. The approximately $197M–$200M attacker proceeds figure is the broader Euler exploit, not Pareto/Idle-attributable loss. Pareto/Idle’s realised loss was $0 after recovery; users were reimbursed in full.

No additional Pareto incident was verifiable as of September 6, 2026.

Date
2023-03-13
Cause
Smart-contract exploit
Loss
$0
Attacker proceeds
$197.0M
Status
resolved
Recovered
$5.8M
Reimbursed
Yes
Event id
pareto-idle-euler-2023-03-13
Evidence (5)

incident

one source

Bug bounty: Pareto Credit’s Immunefi program lists a maximum bounty of $50,000 and a reward of 10% of funds directly affected, which indicates an established disclosure channel for vulnerabilities.

Date
2025-06-03
Cause
Other
Evidence (2)

key management

unverified

Pareto’s key management is not described as a standalone custodial wallet system in the sources I could verify; instead, access control appears to be organized around verification credentials, wallet signatures, and contract permissions. For lenders, onboarding uses Keyring Connect to produce a vault-specific verification credential, and each vault requires fresh credentials rather than sharing them across all vaults. After verification, users complete a contract signature on-chain from the verified wallet, linking a unique ID to the wallet address.

For the protocol’s operational security, Pareto says it continuously monitors private keys and multisignature wallets as part of its security program, but the source does not disclose the exact custody model, threshold scheme, or who controls protocol admin keys. Pareto’s GitHub also references a gnosis-safe-multicall-verifier, which suggests use of Gnosis Safe tooling in the stack, but that alone does not prove how keys are organized operationally. In practice, the clearest verifiable picture is:

  • User/lender access: vault-specific Keyring verification + on-chain wallet signature.
  • Protocol security oversight: monitoring of private keys and multisig wallets.
  • Admin-key governance details: Not verifiable as of 2026-09-04. So, Pareto’s key management is best characterized as credential-gated, wallet-signing-based access for users, with multisig/private-key operational security mentioned but not publicly specified in detail.
Evidence (3)

smart-contract

two sources

As of September 6, 2026, public documentation identifies these Ethereum components: Fasanara vault 0xf622…c2D5, strategy 0xC35D…50de, queue 0x0b4F…8A3E; Bastion vault 0x4462…D165, strategies 0x0697…496F and 0x3Fc0…88cE; Abraxas vault 0x6dbD…e9e6, strategy 0xE7E1…2cbF. Listed governance addresses are Timelock 0xDa86…5A44, treasury multisig 0xFb3b…3814, developer multisig 0xe8eA…677b, and pauser multisig 0xBaeC…Bb9f. These are protocol-published addresses, not independently on-chain-verified in this run. Contradiction: the September 4, 2026 finding said addresses were unconfirmed; current Pareto documentation now publishes an Ethereum address set.

The earlier “no addresses” conclusion should be superseded, but verification and permissions remain incomplete. Architecture: User → IdleCDOEpochVariant vault → AA/BB tranche tokens Vault → IdleCreditVault strategy/withdrawal receipt token → borrower Optional → WriteOffEscrow → borrower-funded early exit Governance/admin → manager/owner, pauser, multisigs/timelock Credit Vaults use epoch-gated deposits and withdrawals. Normal withdrawal requires a request between epochs and a later claim; during an active epoch, deposits and normal withdrawal requests are blocked. Default can pause deposits/withdrawals.

Therefore, users do not have a guaranteed immediate, admin-independent exit. Manager/owner authority is documented over epoch start/stop and configuration, while borrower authority controls repayment and write-off settlement. Exact callable admin functions, owner assignments, proxy implementation slots, proxy-admin type, timelock delay, role renunciation, fee/oracle/strategy replacement powers, and emergency-withdraw behavior: Not verifiable as of September 6, 2026.

Dune was unavailable, so no decoded-event or raw on-chain confirmation is claimed. A public Sherlock review covers the USP queue integration and reports a high-severity default-valuation issue; it is not proof that every Credit Vault deployment is audited or that the issue is unresolved today. Worst case: compromised manager/owner, borrower, pauser, or multisig keys could freeze epochs, alter parameters, redirect strategy/fee flows, delay withdrawals, or accelerate losses through borrower exposure; actual drainability is Not verifiable as of September 6, 2026.

Evidence (4)

audit

unverified

Corrected publication-date record for the Omniscia governance audit claim. Pareto’s roadmap article was published February 11, 2026, rather than March 17, 2026. The article states that Omniscia audited the $PAR governance system and that no major issues were detected, all medium-severity findings were fully resolved, and no remediation remained.

These statements are protocol-published and the underlying Omniscia report plus deployed-bytecode match are Not verifiable as of 2026-09-06.

Auditor
Omniscia
Report date
2026-02-11
Scope
$PAR governance system smart contracts: governance logic, voting power mechanics and snapshot functionality. Deployed Ethereum bytecode match: Not verifiable as of 2026-09-06.
Findings
Protocol-published summary states no major issues; exact Critical/High/Medium/Low counts are Not verifiable as of 2026-09-06.
Fix status
Protocol-published summary states all Medium findings fully resolved and no outstanding remediation. Independent report-level confirmation is Not verifiable as of 2026-09-06.
Report url
https://paragraph.com/%40pareto/2026-beyond-pareto-roadmap-update
Report id
doc:7b4a07620625a869
Evidence (1)

audit

one source

Corrected/rechecked Sherlock USP audit record. The public contest scope is USP at commit ea295f0a712ac23eb02308f05d8891850db938af, covering ParetoDollar, ParetoDollarQueue, ParetoDollarStaking and interfaces, for Ethereum. Public judging records confirm at least one High finding (defaulted Credit Vaults continuing to be valued at pre-default NAV) and at least three Medium findings, including unclaimable pending withdrawals after default, unlimited third-party vault token approvals, and redemption-queue DoS when collateral is unrecoverable.

Exact report-wide severity counts remain Not verifiable as of 2026-09-06 because the attached PDFs do not expose an accessible summary here. One Medium finding was marked Sponsor Confirmed / Will Fix; remediation status for the other cited findings is Not verifiable as of 2026-09-06. Bytecode match to currently deployed Ethereum contracts is Not verifiable as of 2026-09-06.

Auditor
Sherlock
Report date
2025-04-28
Scope
USP stablecoin system at commit `ea295f0a712ac23eb02308f05d8891850db938af`: ParetoDollar, ParetoDollarQueue, ParetoDollarStaking and related interfaces; Ethereum. Deployed-bytecode coverage: Not verifiable as of 2026-09-06.
Findings
At least 1 High and at least 3 Medium findings are publicly evidenced; exact complete counts are Not verifiable as of 2026-09-06. No Critical finding is publicly evidenced in the reviewed material, but a definitive zero count is Not verifiable as of 2026-09-06.
Fix status
One Medium issue is labeled Sponsor Confirmed / Will Fix. Overall finding-by-finding remediation, including the High issue, is Not verifiable as of 2026-09-06.
Report url
https://github.com/sherlock-audit/2025-04-pareto-contest
Report id
doc:beba92fdfd6f0ede
Evidence (5)

audit

one source

Credit vaults and broader Pareto products

Auditor
Multiple (names stated, individual reports not all identified)
Report date
2025-08-01
Scope
Docs Audits page lists at least one entry for "Aug 2025 – Credit vaults" with auditor and report link columns.[2] Full scope details (contract list, chain, upgradeability model, bytecode match to deployed Ethereum contracts) cannot be confirmed from available snippets and thus are **Not verifiable as of 2026-09-04**.
Findings
Pareto’s own docs claim that products (including **credit vaults**) have undergone multiple audits by both security firms and independent experts, and reference an Audits page listing date/scope/auditor/report.[1][2] A social media highlight states "8 audits since 2024" and names independent reviewers (Sherlock, Hans Friese, s4muraii77, 0x3b33, IAm0x52) but provides no direct links or severity breakdown.[6] Because these are protocol‑self disclosures and social posts without direct report access, all specific figures and the implied absence of critical findings are **unverified marketing claims**. Exact critical/high/medium findings and fix status for credit vaults and other audited components are **Not verifiable as of 2026-09-04**.
Fix status
Protocol docs and social posts assert that Pareto contracts are "independently audited and continuously monitored" and refer to an audited deployment pipeline, but do not give per‑finding remediation status.[1][5][6] Without direct access to the underlying reports, remediation of critical/high/medium issues for credit vaults and other products is **Not verifiable as of 2026-09-04**.
Evidence (2)

audit

two sources

$PAR governance system smart contracts

Auditor
Omniscia
Report date
2026-03-17
Scope
$PAR governance system (governance logic, voting power mechanics, snapshot functionality). The Omniscia report link in the roadmap article indicates coverage of the governance system smart contracts.[10] Bytecode‑match against deployed Ethereum contracts is **Not verifiable as of 2026-09-04**.
Findings
LinkedIn roadmap update states that the $PAR governance system smart contracts were audited by Omniscia, with **no major issues**, and that **all medium‑severity findings were fully resolved** and no outstanding remediation items remain.[10] Detailed list of individual findings and their severities is **Not verifiable as of 2026-09-04** because the underlying report contents beyond the public summary cannot be accessed in this context.
Fix status
Medium‑severity findings reported as fully resolved; no remaining remediation items according to Omniscia’s public summary.[10] Whether fixes cover all currently deployed Ethereum governance contracts byte‑for‑byte is **Not verifiable as of 2026-09-04**.
Evidence (2)

audit

one source

Pareto Credit — Credit vaults — report: Google Drive

Auditor
Sherlock
Report date
2025-08-20
Scope
Credit vaults
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Pareto Credit — Credit vaults — report: Google Drive

Auditor
Sherlock
Report date
2026-01-21
Scope
Credit vaults
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Pareto Credit — Credit vaults — report: Google Drive

Auditor
Sherlock
Report date
2026-02-23
Scope
Credit vaults
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Pareto Credit — Credit vaults — report: Google Drive

Auditor
Sherlock
Report date
2026-03-16
Scope
Credit vaults
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Pareto Credit — Credit vaults — report: Google Drive

Auditor
Sherlock
Report date
2026-06-03
Scope
Credit vaults
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Pareto Credit — Credit vaults — report: Google Drive

Auditor
Sherlock
Report date
2026-06-17
Scope
Credit vaults
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

USP stablecoin system / Pareto Dollar smart contracts

Auditor
Sherlock (audit contest)
Report date
2025-04-01
Scope
USP system at commit `ea295f0a712ac23eb02308f05d8891850db938af`, including: - USP/src/Constants.sol - USP/src/EmergencyUtils.sol - USP/src/ParetoDollar.sol - USP/src/ParetoDollarQueue.sol - USP/src/ParetoDollarStaking.sol - interfaces IParetoDollar, IParetoDollarQueue, IParetoDollarStaking[3] Whether this scope matches all currently deployed Ethereum USP contracts is **Not verifiable as of 2026-09-04**.
Findings
The Sherlock contest repository describes an **audit scope** for the USP stablecoin system including ParetoDollar, ParetoDollarQueue, ParetoDollarStaking and related contracts.[3] The PDF security review and USP review attached in the contest repository likely contain detailed findings, but severities (critical/high/medium) and exact counts are **Not verifiable as of 2026-09-04** within this environment. The contest brief emphasizes focus on "eventual loss of funds for the users, locked/unrecoverable funds, serious misbehaviour of the protocol".[3]
Fix status
Contest materials and attached PDFs do not clearly state the remediation status of individual findings in an accessible summary; whether reported issues were fixed, partially fixed, or left open is **Not verifiable as of 2026-09-04**. Coverage of currently deployed USP/Pareto Dollar contracts on Ethereum at the bytecode level is also **Not verifiable as of 2026-09-04**.
Evidence (2)

audit

unverified

Pareto Docs list an Aug 2025 audit of Credit vaults by Sherlock (0x52). The docs page does not show severity counts or remediation status in the snippet provided, so those details are not verifiable here. The audit page indicates the report exists and the scope is the credit vaults deployment.

Whether the report covered the exact deployed Ethereum bytecode is not verifiable from the provided results; per the Bytecode-match note, that requires matching the audited commit/artifact to the deployed code.

Auditor
Sherlock (IAm0x52)
Report date
2025-08
Scope
Credit vaults
Evidence (1)

audit

unverified

Pareto’s April 2025 USP audit material is linked from the Sherlock contest repository and covers the USP codebase at commit ea295f0a712ac23eb02308f05d8891850db938af, including ParetoDollar, Queue, Staking, and interfaces. The snippet does not provide the auditor name, severity breakdown, or fix status for individual findings, so those items are not verifiable from the provided results. The report link exists and the scope clearly references the USP contracts, but deployed-code coverage on Ethereum cannot be confirmed from the snippet alone.

Auditor
Unknown (USP audit report linked from Sherlock contest)
Report date
2025-04
Scope
USP; USP/src/Constants.sol, EmergencyUtils.sol, ParetoDollar.sol, ParetoDollarQueue.sol, ParetoDollarStaking.sol, and related interfaces
Evidence (2)

audit

unverified

Pareto Docs state that the products have undergone multiple audits by security firms and independent experts, and a LinkedIn post claims the $PAR governance system was audited by Omniscia with no major issues and all medium-severity findings resolved. However, the LinkedIn post is a protocol-published marketing-style source and the provided snippet does not supply a report link, so the auditor/date/scope/findings cannot be treated as fully verifiable here. Fix status for the purported Omniscia review is only verifiable at the high level stated in the post, not at finding-by-finding detail.

Coverage of deployed Ethereum bytecode is not verifiable as of 2026-08-29.

Auditor
Unverified / not stated in provided results
Report date
2026-04
Scope
$PAR governance system smart contracts
Evidence (2)

audit

one source

Pareto Credit — USP — report: Google Drive

Auditor
X77
Report date
2025-04-21
Scope
USP
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

Team & Reputation

founders

two sources

Pareto Credit appears to be a founder-led, doxxed institutional DeFi credit business with a real-world corporate footprint, spun out from the Idle Finance team, but on-chain verification is not possible in this run (Not verifiable as of 2026-09-04). ### Founders & Key Team

  • Founders / C-suite (public, non-anonymous):
  • Matteo Pandolfi – Co-founder & CEO. Identified as co-founder/CEO of Pareto and previously of Idle Finance, a DeFi yield automation protocol launched in 2019.
  • Samuele Cester – Co-founder & CPO (Chief Product Officer). Listed as co-founder/CPO at Pareto.
  • William Bergamo – Co-founder & CTO. Listed as co-founder/CTO at Pareto.
  • Additional named team (non-anonymous):
  • Engineering, BD, and marketing roles (e.g., Niccolo Manni – engineer; Francesco Bianchi – BD lead; Bart Antoniak – marketing lead) are mentioned in media coverage. All key people use real names, appear in interviews and professional networks, and are tied to prior DeFi work, indicating a non-anonymous, reputationally exposed team rather than pseudonymous founders. ### Prior Projects, Track Record & Issues
  • The founders previously built Idle Finance, described as a “longest-running yield aggregator and risk tranching protocol” with peak TVL in the ~$293–350M range in 2021–2022.
  • Idle Finance raised about $1.2m in 2020 and operated for multiple years through the DeFi cycle.
  • No credible sources in the retrieved data mention protocol-level hacks, exploits, or major loss events associated with Idle Finance or Pareto Credit. *Absence of evidence is not proof of safety; this is just “no known incidents” in the surfaced data.* Not verifiable on-chain as of 2026-09-04. ### Business Reality: Office, Jurisdiction, Institutional Focus
  • Corporate profiles and company listings show New York, NY (10013) as a headquarters location, suggesting a US onshore presence.
  • Third-party business/intelligence platforms and media describe Pareto as a private credit marketplace for institutional lenders and “vetted” institutional borrowers, including trading firms and fintech lenders.
  • Investor-facing and VC content (e.g., RockawayX note) frame Pareto as a venture-backed, institutional-grade credit platform, reinforcing that it operates more like a fintech/credit business with on-chain infrastructure than a purely anonymous web-front protocol. ### Reality Check / Credibility Assessment
  • Positives:
  • Doxxed, repeat-founder team with prior DeFi protocol (Idle Finance)..
  • Consistent identity across LinkedIn, media interviews, and investor materials.
  • Claimed HQ in New York and institutional positioning, implying regulatory and counterparty scrutiny.
  • Unknowns / Gaps:
  • Legal entity structure (Delaware vs offshore, licensing status, regulated vs unregulated credit) is not clearly disclosed in independent sources. Not verifiable as of 2026-09-04.
  • On-chain governance, contract ownership, and operational controls cannot be checked here. Not verifiable as of 2026-09-04. Overall, available off-chain data supports viewing Pareto Credit as a real, onshore-linked, institutionally oriented DeFi credit venture led by experienced, identifiable founders, rather than an anonymous or purely marketing-front protocol, but critical on-chain and legal-entity confirmations remain outstanding in this pass.
Evidence (15)

general reputation

two sources

Pareto Credit currently has a neutral-to-positive reputation as an emerging institutional private credit/RWA protocol, with no public evidence of fraud, rug pulls, insolvency events, or sanctions as of 2026‑09‑04. Founders / team / investors

  • Public materials and media coverage identify Pareto as an institutional-focused *private credit marketplace* led by co‑founder Matteo Pandolfi, who previously worked on yield aggregation and repo‑like credit infrastructure for digital assets.
  • The positioning is explicitly institutional (asset managers, funds, professional lenders/borrowers) rather than retail-focused.
  • No widely cited VC roster is visible in the retrieved data; investor base and cap table are Not verifiable as of 2026‑09‑04. Audits and security posture
  • Pareto’s documentation claims multiple smart-contract audits by security firms and independent experts, with a dedicated “Audits” page listing reports (e.g., Aug 2025 scope: credit vaults).
  • Because reports are hosted via Pareto’s own docs and auditor names are not visible in independent sources in the retrieved data, these count as unverified marketing claims pending direct confirmation on auditor sites.
  • No publicly reported major exploit or protocol hack is visible in headline media or analytics aggregator summaries. Sentiment & adoption
  • Analytics platforms describe Pareto as a private credit / RWA lending protocol with TVL concentrated on Ethereum, and significant institutional framing.
  • Social presence (30k+ followers on X) and recent coverage of the USP synthetic dollar in Cointelegraph suggest moderate positive sentiment and interest in its approach to private credit-backed onchain USD exposure. Criticisms, risk concerns, and unresolved issues
  • No explicit fraud, rug‑pull, or insolvency allegations appear in retrieved coverage or protocol summaries.
  • Key structural risks are discussed in neutral terms rather than accusations:
  • USP is *not* a fiat-backed stablecoin but a synthetic dollar backed by private credit and stablecoin collateral routed into credit vaults, which introduces counterparty and credit‑cycle risk versus fully liquid reserve models.
  • Borrowers are whitelisted institutional entities and redemptions are cycle-based, implying liquidity is conditional on borrower repayment and vault design.
  • Regulatory licensing, jurisdictional authorizations, and any supervisory actions are Not verifiable as of 2026‑09‑04.
  • No listings appear in sanctions/blacklist databases in the retrieved data; formal confirmation remains Not verifiable as of 2026‑09‑04. Overall Available independent data paints Pareto Credit as a serious institutional RWA/private credit protocol with growing usage and coverage, but with typical private credit and synthetic-dollar structural risks and limited independently verified audit/regulatory information to date.
Evidence (8)

Economy

TVL: $160K

model

one source

Economic model — Pareto Credit (Ethereum scope requested)

  • Strategy/assets: Credit Vaults accept primarily USDC/USDT and lend funds directly to whitelisted institutional borrowers. Yield is contractual interest paid by borrowers; vaults use fixed or variable rates. Current documented strategies include delta-neutral basis trading, market making, prime brokerage, and HFT.
  • Yield quality: The underlying borrower strategies are not uniformly market-neutral: basis trading is explicitly delta-neutral, while market making/HFT/prime brokerage retain strategy, counterparty, and liquidity risk. No verified evidence of protocol-wide staking, restaking, or recursive DeFi looping. Borrower activity creates external/off-chain institutional exposure.
  • Organic vs subsidized: The stated yield source is borrower interest. Incentive subsidies are not verifiable as of 2026-09-06; therefore organic_yield_pct is null. Pareto documents a 5% fee on generated interest funding a Stability Fund, but this is a fee allocation, not necessarily a user subsidy.
  • Lock-ups/withdrawals: Credit Vault deposits are cycle-based, typically 1–4 weeks. Standard withdrawal generally requires a request and claim at the end of the following cycle; early exit may be available after a material rate reduction, commonly with a roughly 72-hour delay. USP/sUSP is described as having no lock-up, but underlying credit liquidity remains relevant.
  • Fees/gates/limits: KYC/Keyring verification and whitelisting are required for lenders. Vault performance fees are documented at 10–20% for listed examples; exact current fee schedule by product is not fully verifiable.
  • Collateral/leverage: Credit Vault loans are sent directly to borrower wallets; borrower collateral or enforceable collateral ratios are not verifiable as of 2026-09-06. Aggregate leverage/looping ratio is therefore null.
  • TVL/APY: DeFiLlama currently reports $223.38m TVL, with $223.38m Ethereum, $41.70 Polygon, $0.47m Arbitrum, and $0 OP Mainnet; this conflicts with the user-provided Ethereum-only scope. It reports six pools and 6.48% average supply APY, with TVL down 4.6% over 30 days. Product-level TVL, APY history/volatility, sustainability, and Dune-vs-DeFiLlama reconciliation are Not verifiable as of 2026-09-06 because Dune is unavailable. Contradiction: Ethereum-only scope vs DeFiLlama’s current multi-chain listing; DeFiLlama’s current on-page figures are the available analytics-platform data, not on-chain-verified data.
Evidence (4)

reserves

unverified

As of September 6, 2026, current reserves, treasury size, asset composition, and liabilities are not fully verifiable. Dune on-chain verification was unavailable for this run; therefore current Ethereum balances and USD values are Not verifiable as of September 6, 2026. Known custody/control: Pareto’s documentation lists the Ethereum Treasury multisig as 0xFb3bD022D5DAcF95eE28a6B07825D4Ff9C5b3814; the Ethereum timelock is 0xDa86e15d0Cda3A05Db930b248d7a2f775e575A44. A June 2025 governance proposal states that 400,000 USDC was to be transferred from the DAO Treasury to the Ethereum multisig for USP liquidity operations, with resulting LP tokens returned to the multisig for safekeeping.

The proposal passed its temperature check, but execution and present balances were not independently verified here. Historical disclosed amounts: A July 2024 governance post reported approximately $34,000 in stablecoins and $39,000 in ETH/LRTs in the Treasury League multisig, subject to a $41,000 deduction and a proposed $135,500 transfer from the Fee Treasury. These are stale historical figures and do not establish current reserves. A January 2025 proposal subsequently referenced approximately $13,000 in stablecoins and $37,000 in BTC/ETH/LRTs, plus a proposed $138,000 transfer.

This conflicts with the July 2024 disclosure; the discrepancy is unresolved without current on-chain verification. Composition/reserve policy/attestations: Public materials indicate treasury assets may include stablecoins, ETH/LRTs, PAR-related assets, and liquidity/LP positions. A complete current composition, formal reserve policy, proof-of-reserves, liabilities schedule, or independent reserve attestation is Not verifiable as of September 6, 2026. The GitHub repository documents a DAO reserve for PAR token distribution, but not its current market value or liquid backing.

Evidence (5)

tokenomics

one source

Scope / name-collision warning. This refers to Pareto.Credit, not the unrelated legacy Pareto Network token at 0xea5f88E54d982Cbb0c441cde4E79bC305e5b43Bc. Native token: Pareto.Credit has announced PAR, a governance token. The repository specifies a fixed 18.2 million PAR supply, minted once at launch.

However, an Ethereum deployment address, live contract, circulating supply, market price, market cap, FDV, and current holder balances are Not verifiable as of September 4, 2026. The available materials describe deployment tooling and launch preparation rather than providing a confirmed deployed Ethereum token address. Utility and governance: The announced design uses PAR for governance, with liquidity providers locking Balancer 80/20 PAR/WETH BPTs to receive non-transferable vePAR.

Initially, vePAR is intended to carry governance weight; a hybrid governor/timelock is specified. Rewards / value capture: Initial staking rewards are planned in PAR from a reserved allocation, with weekly distribution. Revenue sharing is not initially planned; buybacks are only a possible future mechanism subject to governance.

No confirmed burns or live staking APY are documented. Allocations and unlocks (announced design, not on-chain verified): team 6% (1.092M); investors 10% (1.82M), with a 12-month cliff and three-year vesting; former IDLE holders approximately 53% (9.646M), with four-month vesting and 10% initial unlock; operations reserve 10% (1.82M); the remainder is described as DAO/long-term funds, liquidity, and community distribution. Whether any announced unlocks actually occurred on-chain is Not verifiable as of September 4, 2026.

Admin/security controls: The design says PAR is a standard ERC-20 with one-time minting; no blacklist or fee-switch is described. Launch administration—including claims activation, vesting ownership, reward scheduling, voting weights, and smart-wallet permissions—is assigned initially to a timelock multisig, with later transfer intended to governance. Actual deployed permissions are Not verifiable as of September 4, 2026.

Liquidity/listings: A Balancer 80/20 PAR/WETH pool is planned; depth, pool address, DEX/CEX listings, and current liquidity are Not verifiable as of September 4, 2026. On-chain top-holder concentration and insider wallets are likewise Not verifiable as of September 4, 2026.

Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Pareto Credit’s own site says it is designed to visualize market stress scenarios and adjust parameters before deploying capital, but the web results provided do not include protocol-specific liquidation thresholds, collateral rules, or BTC exposure details for Ethereum, so the impact of BTC falling below $10,000 is not verifiable as of 2026-09-04. For a leveraged credit protocol, a BTC crash to $10,000 is an extreme stress case that would typically increase borrower LTVs sharply, trigger margin calls, and likely force liquidations if BTC is used as collateral or if portfolio assets are BTC-correlated; that general mechanism is consistent with crypto financial-stability research and market commentary, but it is not a protocol-specific finding for Pareto Credit. Because no independently verifiable on-chain data or protocol documentation is available in the provided results, I cannot quantify expected losses, bad debt, or liquidation share for Pareto Credit on Ethereum. Not verifiable as of 2026-09-04.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

Pareto’s publicly documented stress weakness is that its USP minting logic can fail to account for collateral depegs: the Sherlock audit notes that if a collateral token depegs, the protocol may still treat the token amount as if it were full USD value, which can cause USP to be minted while the system is actually undercollateralized. For a 20% depeg of the largest collateral, the immediate effect is a 20% reduction in that asset’s USD value; whether this creates a peg problem depends on how large that asset is relative to total collateral and total USP supply, but the risk is a direct drop in overcollateralization and a higher chance of USP becoming undercollateralized. Pareto’s own USP docs state that USP is backed 1:1 by funds lent to institutional players and that a Stability Fund exists before slashing sUSP holders, which indicates the protocol relies on buffers rather than assuming collateral is perfectly stable.

What cannot be verified from the provided sources is the protocol’s current Ethereum collateral composition, largest collateral share, and live TVL; without that, the quantitative loss from a 20% depeg is Not verifiable as of 2026-09-04. The safest stress conclusion is: if the largest collateral represents X% of total collateral, a 20% depeg reduces total collateral value by 0.2×X% and may trigger undercollateralization if the remaining buffer is thin.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

For Pareto Credit on Ethereum, the documented stress path for a counterparty insolvency is that the affected credit vault/tranche value is written down, and the loss is first buffered by the protocol’s peg stability reserve / stability fund; if that buffer is insufficient, sUSP holders absorb the loss through a reduced conversion price to USP. The result is a lower USP backing per share, while the senior USP peg is intended to be defended. The impact path through the contracts, based on the documentation and contest/audit materials, is: borrower default or failed repayment → vault loss realization / write-off in the credit vault → treasury or stability buffer used if available → if still short, sUSP exchange rate is reduced and staking/holder balances take the hit → USP redemptions can continue only at the impaired value, so users exiting later bear the loss rather than the borrower.

The audit/judging material also indicates that, in edge cases, losses may be spread across stakers and the fee receiver/admin account, but if those balances are insufficient, the contract can become effectively insolvent and users may be unable to withdraw in full. For compensation, the protocol documentation says a stablecoin reserve/buffer is used before slashing sUSP holders, and verified parties may mint or redeem USP around the peg when conditions allow; however, there is no guarantee of full compensation once losses exceed buffers, and any such recovery is contingent on available reserves and contract state. Not verifiable as of 2026-09-04: the exact Ethereum deployment addresses, live TVL at risk, and chain-specific loss waterfall details were not on-chain verified in this run.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

For Pareto Credit, a DAO-or-owner fraud stress scenario is not verifiable as of 2026-09-04 from the available sources. The protocol’s public materials describe Pareto as an onchain credit marketplace and state that the software is open-source and operates autonomously on Ethereum, but that is a self-description rather than evidence of actual fraud risk realization. The only directly relevant external evidence is generic, not protocol-specific: the SEC’s DAO report explains that DAO token issuers and participants can face securities-law exposure, and a legal/article source describes common DAO fraud patterns such as treasury misappropriation, deceptive proposals, and founder-controlled exits.

However, none of the retrieved sources shows a confirmed incident of fraud by Pareto’s DAO, founders, or owners. So the stress-case assessment is:

  • Plausible impact: governance abuse, unauthorized treasury diversion, or founder/operator misrepresentation could impair lender confidence and liquidity.
  • Verified incident status: Not verifiable as of 2026-09-04.
  • On-chain corroboration: unavailable in this run; no raw chain verification was performed. If you need a strict risk memo, I would classify this as high-severity but unconfirmed scenario risk, not a confirmed fraud event.
Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For Pareto Credit on Ethereum, the primary yield source negative 30d stress case is not verifiable from the provided sources. The docs confirm the protocol uses epoch-based credit vaults with lender/borrower cash flows and that Pareto explicitly markets stress-scenario visualization, but none of the supplied results provide a 30-day trailing yield series or show the primary yield source turning negative. What can be stated is that Pareto’s yield mechanics depend on lending to a borrower over an epoch, with withdrawals handled through pending-request and claim windows; if a borrower defaults, deposits/withdrawals are paused and the vault enters a defaulted state.

That means a negative 30-day yield outcome would most plausibly come from borrower underperformance, default, or adverse epoch pricing, but the magnitude and whether the *primary* source is actually negative over the last 30 days is Not verifiable as of 2026-09-04. A related point from third-party commentary is that the product has historically had a relatively small TVL and yield-bearing token performance can vary, but this is not a primary-source 30-day yield trace and should not be treated as on-chain proof. The token terminal page confirms the vault is an actual tracked yield product, but the snippet does not supply the needed trailing 30d return data for this stress check.

Evidence (4)

Governance & Legal

governance

two sources

Pareto Credit — Governance (Ethereum), reviewed September 13, 2026. Control map. Published architecture assigns control to: timelock 0xDa86…5A44; treasury/TL Safe 0xFb3b…3814; developer Safe 0xe8eA…677b; and pauser Safe 0xBaeC…Bb9f. The TL Safe is documented as controlling the team fund, both vesting contracts, the operations reserve, Merkle-claim activation, smart-wallet allowlisting, and VotesAggregator ownership. The timelock controls only the long-term fund; ownership of several other components is described as transferable later.

This is therefore multisig-led, partially decentralized governance, not a fully autonomous DAO. Proposal process. PAR/vePAR governance uses a hybrid Governor: 1% proposal threshold, 4% quorum, 10-minute voting delay, 3-day voting period, simple majority, then queueing through a TimelockController. The documented timelock delay is 48 hours; anyone may execute after the delay, while the Governor has proposer/canceller roles and deployer admin is renounced. DAO reality and concentration. Token-holder governance can control the timelock-bound long-term fund and parameters routed through the Governor, but the TL multisig retains significant discretionary powers and can change vote-source weights before migration to governance. dao_governance = false under the requested strict definition. Voting concentration, top PAR holders, vePAR concentration, and current voting power are Not verifiable as of September 13, 2026 because Dune MCP/on-chain queries were unavailable.

Current Safe owners, signer independence, and current thresholds are likewise Not verifiable as of September 13, 2026. A September 2023 forum record reported Ethereum thresholds of 3/6 for the TL Safe, 2/4 for developer, and 2/4 for pauser, but this is stale and not treated as current. Frontend/development/company control. GitHub activity identifies pareto-credit as the publishing organization, but no verified legal entity, jurisdiction, registration number, directors, or operational frontend-control arrangement was found. The forum ToS is a generic template containing unresolved placeholders such as company_name, governing_law, and city_for_disputes; it does not establish a legal entity. Risk conclusion: material centralization remains at the TL multisig; emergency pausing and reserve administration are not fully DAO-controlled.

Timelock
Yes
Timelock delay hours
48
Dao governance
No
Evidence (5)

legal & regulatory

one source

Pareto Credit appears to operate through a web interface and terms that require users not to violate applicable law, including anti-money-laundering and anti-terrorist financing rules. The terms also state that lending services are subject to KYC/KYB-style onboarding via Keyring and exclude users from several jurisdictions, including New York, Cuba, Iran, Syria, North Korea, Crimea, and Venezuela. The privacy policy identifies the operator as Idle DAO LLC, Marshall Islands, while the onboarding docs say users sign a Terms of Service with Pareto and a Master Loan Agreement governing the lending relationship.

This suggests a mixed structure: offshore entity plus smart-contract/governance layer, but the exact legal allocation between entity and protocol is not fully verifiable from the available web material.

Entity
Idle DAO LLC
Jurisdiction
Marshall Islands
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'Idle DAO LLC', 'Pareto Credit'. OFAC SDN screening of 'Idle DAO LLC', 'Pareto Credit': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Idle DAO LLC
  • Pareto Credit
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Pareto Credit does issue its own stablecoin-like asset, USP, described as a credit-backed synthetic dollar / soft-pegged dollar asset on Ethereum. No confirmed web evidence of an actual depeg event was found in the available sources, so depeg_count, last_depeg_date, and max_depeg_pct are not verifiable as of 2026-09-06. The safest conclusion is that USP is intended to maintain a $1 peg, but a documented depeg history was not established from the sources reviewed.

Own stablecoin
Yes
Stablecoin ids
  • USP
Evidence (5)

Risks & Strengths

risks

two sources

Pareto Credit’s principal risks are concentrated in borrower default, redemption liquidity, collateral valuation, privileged administration, and third-party vault integrations. Credit Vault assets are sent directly to borrowers and withdrawals are cycle-based, while USP depends on accurate valuation of those positions; Ethereum TVL, exposure concentration, and current remediation status are Not verifiable as of September 5, 2026 because Dune on-chain verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Borrower default and credit lossFunds are lent directly to whitelisted institutional borrowers. A default can impair principal, reduce USP backing, and socialize losses across lenders or stakers. Pareto’s own documentation identifies this counterparty exposure.HighMediumWhitelisting, borrower underwriting, credit agreements, tranche structure, and a documented stability fund intended to cover 5% of USP-generated fees.High: recovery value, enforcement timing, borrower concentration, and the actual funded reserve are Not verifiable as of September 5, 2026.
Defaulted-vault valuation failureA historical Sherlock finding showed Credit Vault positions could remain valued near pre-default levels, overstating collateral and potentially causing undercollateralized USP, preferential early redemptions, or insolvency.HighMediumAudits and monitoring are documented; the finding proposed checking default status during NAV calculation. Current deployed-code remediation is Not verifiable as of September 5, 2026.High until deployed bytecode and live accounting are independently verified.
Redemption and liquidity mismatchWithdrawals generally require a request, cycle completion, borrower repayment, and manager processing; stress or default can delay exits and create unequal outcomes between early and late redeemers.HighHighEpoch queues, planned early-exit provisions, and manager-controlled liquidity rebalancing.High: no independently verified liquidity buffer or redemption coverage is available.
Privileged administration and governanceCurators and managers can change vault parameters, allocate funds, process redemptions, and manage yield sources; multisig/timelock control creates key-person, collusion, and operational-failure exposure.HighMediumMultisig, timelock governance, role separation, pause/monitoring controls, and whitelisting.Medium-High: signer composition, thresholds, timelocks, and live permissions are Not verifiable as of September 5, 2026.
Third-party vault integration exploitA historical audit finding reported unlimited approvals to yield-source vaults, creating a path for a compromised or upgradeable vault to drain queued collateral.HighMediumYield-source whitelisting, allowed-method controls, audits, and removal procedures are documented.High until current allowances, upgradeability, and deployed integrations are verified on Ethereum.
Evidence (5)

strengths

two sources

Pareto Credit’s top strengths appear to be: institutional-grade positioning, regulated/compliance-first infrastructure, capital efficiency, yield generation, and liquidity/diversification. The protocol describes itself as a private credit marketplace for institutional lenders and borrowers with programmable onchain execution and common infrastructure across the loan lifecycle.

  • Institutional access and borrower quality: Pareto is built to connect institutional capital with institutional borrowers, and partner-facing materials cite names like FalconX, Bastion Trading, Fasanara, and RockawayX as part of the ecosystem.
  • Compliance and legal design: The protocol emphasizes enterprise-grade compliance, KYC/AML automation, and regulatory-compliant alternative credit solutions, which is a core differentiator versus typical DeFi lending.
  • Capital efficiency: Pareto highlights capital-efficient credit vaults, reduced operational overhead, and more efficient allocation across the lending lifecycle, aiming to remove traditional origination and servicing friction.
  • Yield generation: Pareto’s USP/sUSP product framing explicitly positions the system as yield-generating, with sUSP designed to deliver stable, risk-adjusted returns from credit vault activity.
  • Liquidity and diversification: The protocol markets sUSP as liquid and diversified, with exposure to a broad set of credit lines and the ability to exit without lockups, while USP is described as composable across DeFi and CeFi. One important caveat: several of these strengths are protocol- and partner-sourced marketing claims rather than independently verified operating metrics, and the on-chain exposure/TVL is not verifiable here because Dune is unavailable in this run.
Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 17 one source, 9 unverified.
  • Oldest fact verification date: 2026-08-29.