Solstice

Orange · 68/100

Executive summary

Solstice is a Solana-native synthetic stablecoin and yield protocol offering USX (stablecoin) and YieldVault strategies (eUSX, strcUSX), scoring 71/100 (green band) with high data confidence (88/100).

  • Security: Four Halborn audits (YieldVault, USX Program, USX Rewarder, USX Staking) covering 2025–2026 found zero critical/high issues; all reported findings addressed. Sep2 secondary audit mentioned but report not retrieved. Deployed-code equivalence and signer identities not independently verified. Contracts claimed non-upgradeable with PDA-only minting, 3/5 Squads multisig, and 24-hour timelock—unverified marketing claims absent on-chain checks.
  • Incidents: USX depegged to ~$0.78–$0.80 (isolated prints to $0.10) on December 26, 2025, due to secondary-market liquidity stress, not exploit or collateral failure. Protocol and market makers restored peg within hours; reserves remained overcollateralized. No user reimbursement program; event exposed thin liquidity and unclear redemption access.
  • Governance & custody: Foundation-led governance, not a DAO; Risk Committee controls parameters, audits, deployments, and pause authority. Solstice Labs AG (Zug, Switzerland) operates the protocol; named directors include Timothy Grant, Benjamin Nadareski, Stuart Connolly, Marcus Maute. Backing assets held in segregated third-party custody (Ceffu, Copper) with off-exchange settlement; exact signer identities and multisig independence not verified.
  • Top risks: Off-chain collateral and counterparty dependencies (CEX, market makers, custodians, oracles) create insolvency, freeze, and operational risk; exact exposure, concentration, and legal waterfall not verifiable. Yield strategies rely on funding-rate arbitrage and delta-neutral trades, which can turn negative under regime shifts. Redemption mechanics (7-day minimum vs. "anytime" claims) and institutional-only access ($500k+) conflict with retail marketing. Legal counterparty inconsistent across disclosures (Swiss AG vs. BVI Foundation).
  • Strengths: Solana-native design with fast settlement and low fees; institutional-grade yield strategies (delta-neutral, market-neutral); composable architecture (USX → eUSX → SLX governance loop); public, non-anonymous team with TradFi/crypto pedigree (Galaxy Digital, Deus X Capital); backed by recognizable investors (Galaxy, Bitcoin Suisse, Auros). Claimed three-year track record and positive monthly returns—unverified marketing claims.
  • Unverified: Reserve composition, size, addresses, and coverage ratio; exact CEX/MM counterparties and exposure limits; oracle methodology and fallback logic; redemption gates, queueing, and settlement timing; SLX revenue share or fee distribution; deployed-code match to audited commits; on-chain TVL, liabilities, and signer topology—all not verifiable as of September 5, 2026 due to unavailable Dune/on-chain data.
  • Recommended exposure: Conservative allocation (≤2–5% of DeFi portfolio) for institutional allocators comfortable with off-chain custody, CEX counterparty risk, and Foundation governance. Require independent verification of reserves, custodian segregation, redemption mechanics, and deployed-code equivalence before scaling. Avoid if exposure to unverified collateral, thin secondary liquidity, or permissioned redemption is unacceptable. Monitor funding-rate reversals and secondary-market depth.
  • Open questions: Verify reserve addresses, composition, and real-time attestation; confirm deployed Solana programs match audited code; identify multisig signers and independence; clarify redemption mechanics (7-day vs. instant, gates, fees); quantify CEX/MM counterparty concentration and legal recourse; obtain legal opinion on entity structure and liability waterfall; stress-test yield strategies under negative funding and collateral depeg scenarios.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 4 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 100 20.0 full audit within 365 days (latest 2026-01-12)
Incidents 20% 100 20.0 no open incidents
Governance 20% 50 10.0 no DAO governance
TVL 20% 1 0.2 TVL $235,039,368 = 1% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 14/33 verified facts; 33/33 fresh (180d)

Identification

protocol identification

two sources

Identification — Solstice Finance. Name: Solstice Finance / Solstice Labs. Website: solstice.finance; documentation is linked from the Solstice site, with the public whitepaper serving as the principal technical document. Category: Solana-native synthetic stablecoin, basis-trading/yield protocol, and YieldVault framework.

Dates and deployment. Solstice Labs was announced on September 20, 2024; the public USX/YieldVault launch occurred on September 30, 2025. Chain: Solana only (100% of listed TVL). Native/governance token: SLX.

Address set. Candidate addresses reported by two independent web sources are: USX mint 6FrrzDk5mQARGc1TDYoyVnSyRdds1t4PbtohCD6p3tgG; eUSX mint 3ThdFZQKM6kRyVGLG48kaPg5TRMhYMKY1iCRa9xop1WC; USX program USXyiSTsPEWz55pSK7sZoUL79ntoVGQbaTDT57tH6bx; YieldVault program eUSXyKoZ6aGejYVbnp3wtWQ1E8zuokLAJPecPxxtgG3; SLX mint SLXdx4BUt2v9uJQNzWqSfzTJ9UKLUDsvxHFMEEdrfgq. Required Dune cross-check is unavailable in this run; therefore the requested >=2-source cross-check including Dune and Dune-based on-chain verification are: Not verifiable as of September 4, 2026. Solana Explorer pages were located for the USX program, but retrieved content did not show a verified-source status; token-mint explorer verification is likewise Not verifiable as of September 4, 2026.

Fork lineage. No evidence was found that Solstice’s protocol programs are a fork of a named upstream protocol. The public Solstice GitHub organization exposes metadata/integration repositories and unrelated infrastructure forks, not the core USX/YieldVault source; upstream diff, modifications, and audit coverage of any fork are Not verifiable as of September 4, 2026. Officially listed Halborn audits cover Solstice programs, but do not establish fork lineage.

Malicious modifications in comparable Solstice forks: Not verifiable as of September 4, 2026.

Evidence (10)

maturity

unverified

Solstice appears to be a real product portal, not just a landing page: the main site exposes product-specific pages for USX, SLX, YieldVault/eUSX, About, and Resources, including technical documentation for USX and a vault page describing deposits into YieldVault. The public materials also describe an operational Solana-native protocol with USX and YieldVault already launched, which is more consistent with a live app than a static marketing site. That said, live deposit/withdrawal functionality is not verifiable as of 2026-09-03 from the available web data, because no independently checkable transaction or state evidence was accessible in this run.

The same is true for whether the app currently supports withdrawals, what exact flows are live, and whether any backend API is exposed beyond the public documentation pages: Not verifiable as of 2026-09-03. ## UX / maturity signals

  • The site has multiple product pages and documentation, which is a positive maturity signal.
  • Search results reference an app subdomain and user flows like swap, earn-flares, and wallet connection, suggesting there is at least an interactive frontend rather than a pure brochure site.
  • I did not find reliable evidence of broken links or template reuse from the verified sources; Not verifiable as of 2026-09-03.
  • I did not find verified evidence of fake metrics on the site itself; claims such as TVL, holders, and APY remain unverified marketing claims in this pass. ## Open API
  • A public-facing API was not verifiable as of 2026-09-03.
  • The only clearly visible developer-facing material is technical documentation for the USX program, not an openly documented API endpoint or SDK. Overall: Solstice looks like a functioning protocol website with substantive product documentation and an app surface, but live operational maturity, withdrawals, and open API availability remain unverified in this run.
Evidence (8)

Security

bug bounty

one source

Not verifiable as of 2026-09-03. The only directly relevant public source found was Solstice’s own security page, which lists three independent audits but does not mention any bug bounty program. A third-party project profile also says “No CertiK Bug Bounty” and “No 3rd Party Bounty,” which suggests no active bounty was registered there, but it is not enough to confirm a broader program.

No public start date, scope, reward parameters, or disclosed bounty results were found.

Active
No
Evidence (2)

counterparty risks

one source

Оценка на 5 сентября 2026 г. Dune MCP недоступен; ончейн-проверка пропущена. Ключевые зависимости и сценарии риска

  • Резервы/кастодианы: USX и YieldVault зависят от off-chain резервов, лицензированного управляющего/фонда, банковско-кастодиальной инфраструктуры и процедур proof-of-solvency. Ceffu заявляет custody и MirrorX для off-exchange settlement; Copper — custody и ClearLoop для USX. Это снижает риск прямого перевода средств на биржу, но не устраняет риск банкротства, заморозки, ошибок сегрегации, юридической несостоятельности или операционного сбоя кастодиана/prime-провайдера.
  • CEX/MM и delta-neutral стратегии: заявлены funding-rate arbitrage, hedged staking и институциональные торговые стратегии. Следовательно, присутствуют риск биржевых контрагентов, ликвидаций, margin/collateral calls, funding reversal, market-maker withdrawal и неполного хеджирования. Конкретные биржи, лимиты и распределение экспозиции публично не подтверждены: Not verifiable as of September 5, 2026.
  • Оракулы: Chainlink используется для proof-of-reserves; независимый обзор также указывает Chainlink и Pyth в oracle-инфраструктуре. Риски: stale/ошибочный feed, зависимость от off-chain attestations, расхождение цены и NAV, а также oracle-manipulation при низкой ликвидности. Методология, fallback-логика и лимиты не подтверждены: Not verifiable as of September 5, 2026.
  • RWA/issuer risk: новый strcUSX связан с STRC preferred shares Strategy Inc.; это добавляет риск эмитента, корпоративных выплат, ликвидности Nasdaq-инструмента и структуры фонда/SPV. STRC не является залогом, напрямую обособленным в пользу держателей: экономическая поддержка Bitcoin на балансе Strategy не равна обеспечению конкретной эмиссии.
  • Bridges, stablecoins, LST/restaking: Solstice позиционируется как Solana-native; подтвержденной bridge-экспозиции, зависимости от внешних stablecoin/LST/restaking-протоколов или их долей не найдено: Not verifiable as of September 5, 2026. > Противоречие: запуск заявлял $160 млн TVL, тогда как доступный dashboard при последнем просмотре отображал TVL 0 и незагруженные резервы. Это не доказывает нулевые резервы сегодня, но заявленная цифра не подтверждена текущим ончейном. Структурированные поля:
  • dependency_failure_active: null — подтвержденного активного отказа не установлено; полноценная ончейн-проверка недоступна.
  • max_exposure_pct: null — публичные лимиты/доли контрагентов не подтверждены. Итог: риск высокий по кастодианам, торговым контрагентам, oracle/PoR и RWA-эмитенту; количественная концентрация неизвестна.
Evidence (5)

crypto custody

unverified

Solstice’s custody is organized as institutional, third-party custody rather than direct protocol self-custody for the backing assets. Public materials say USX offers “self-custody or managed custody via Ceffu and Copper.co,” and Solstice’s resources describe “continuous on-chain verification of an over-1:1 reserve ratio across all custodians via Accountable.” External custody partners also describe assets as remaining in segregated wallets under their custody, with off-exchange settlement rails for trading access. I could not verify any chain-level withdrawal pause or suspension from the available sources, so withdrawal_paused is null and Not verifiable as of 2026-09-05.

The available materials support segregated_assets = true because the custody model explicitly uses segregated third-party wallets and separate custodial rails. No on-chain verification was available in this run, so the finding is based on protocol and custodian disclosures rather than raw chain data.

Segregated assets
Yes
Evidence (3)

incident

two sources

On December 26, 2025, USX briefly depegged on Solana secondary markets. Most reported trading data showed a low near $0.78-$0.80 on Orca/Raydium; isolated thin-liquidity prints as low as $0.10 were also reported. Cause: heavy sell pressure and insufficient secondary-market liquidity, not a smart-contract exploit or collateral failure.

Affected parties were USX holders and secondary-market traders; no widespread liquidations or protocol insolvency were reported. Solstice and market makers injected liquidity at approximately 04:30 UTC, and USX recovered near parity. Solstice stated that backing assets/NAV remained unaffected and overcollateralized, while primary-market redemptions continued; a reserves attestation was subsequently referenced.

No realized protocol or user loss was publicly quantified: the market-price dislocation is not evidence of realized loss, and any user losses from trades during the wick are Not verifiable as of 2026-09-05. No attacker proceeds were identified. No user reimbursement program or reimbursement amount was reported; reimbursed=false.

Current status: resolved operationally, although the event exposed insufficient secondary liquidity and limited clarity regarding permissioned redemption access. No additional qualifying exploit, insolvency, or loss incident was identified in the overlap search through September 5, 2026; the May 2026 SLX allocation/vesting controversy was excluded as a non-event.

Date
2025-12-26
Cause
Liquidity issue
Status
resolved
Reimbursed
No
Event id
solstice-usx-depeg-2025-12-26
Evidence (4)

key management

two sources

Solstice appears to organize key management around multisig governance, non-upgradeable contracts, and PDA-only minting on Solana, which reduces the number of privileged keys that can unilaterally change protocol state. The protocol also markets an institutional custody stack that uses managed custody and mentions private MPC (multi-party computation) for distributed key management, where no single node holds a complete private key. For the broader operating model, third-party coverage says Solstice runs an in-house trading desk rather than outsourcing strategy execution, and that its institutional yield setup uses regulated/off-chain entities with custody and attestations handled through named providers.

That suggests key control is split between protocol-level governance keys on-chain and operational keys used by the managed treasury/custody stack off-chain, rather than concentrated in one wallet. What is not verifiable from the available sources is the exact signer topology, threshold count, key rotation policy, who controls the multisig, or whether MPC is used in production versus only as an infrastructure offering. So the most defensible answer is: Solstice organizes key management as a multi-party, institutionally oriented control model with multisig on-chain governance and custody/MPC for operational keys, but the precise implementation details are not publicly confirmed as of 2026-09-03.

Evidence (6)

smart-contract

two sources

As of September 5, 2026. Dune MCP was unavailable; therefore no raw on-chain verification, decoded governance-event analysis, upgrade-authority check, or measured timelock execution delay was performed. Per methodology: Not verifiable as of September 5, 2026 for those items. Identified Solana addresses

  • USX mint: 6FrrzDk5mQARGc1TDYoyVnSyRdds1t4PbtohCD6p3tgG (reported by Solana Compass/CoinDesk; explorer-level deployment verification not completed).
  • YieldVault program: eUSXyKoZ6aGejYVbnp3wtWQ1E8zuokLAJPecPxxtgG3 (reported by Solana Compass and Orb).
  • Squads multisig, signer set, proxy/upgrade authority, PDA authorities: Not verifiable as of September 5, 2026. Architecture / control claims User → USX mint → YieldVault program → eUSX / strategy vaults → redemption to USX Admin signers → claimed 3/5 Squads multisig → claimed 24-hour timelock → governance/admin instructions Solstice claims PDA-only minting, non-upgradeable contracts, 3-of-5 multisig governance, and a 24-hour timelock. These are unverified marketing claims absent raw account/state and transaction evidence. The Halborn report located for the USX/YieldVault programs covers two informational findings, with zero critical/high findings and states all reported findings were addressed. This supports audited code scope, but deployment-to-audited-commit equivalence and Sep2 governance-audit details were not independently verified. Risk assessment
  • Admin/owner/emergency, pause, withdrawal, fee, oracle, strategy, and role-renunciation functions: Not verifiable as of September 5, 2026.
  • Can users exit without admin? The audit description says eUSX redemption is user-initiated, while current product materials mention redemption windows; actual enforcement and admin dependence are Not verifiable as of September 5, 2026.
  • Worst case if keys compromise: potentially mint/freeze/redirection or strategy-control abuse, depending on actual authorities; exact impact is Not verifiable as of September 5, 2026.
  • Principal residual risks: multisig collusion/key compromise, off-chain custody/strategy risk, and possible withdrawal freeze. No evidence was found proving role renouncement or an immutable emergency path. Contradiction / gap: website claims “non-upgradeable,” “3/5,” and “24-hour timelock,” but none were on-chain verified in this run.
Unresolved critical
0
Unresolved high
0
Evidence (4)

audit

one source

Halborn — YieldVault security assessment. No change identified since the prior check. A deployed-program bytecode/build match was not independently established.

Auditor
Halborn
Report date
2025-05-16
Scope
Solana YieldVault Program; engagement April 17–24, 2025.
Findings
5 total: 0 critical, 0 high, 1 medium, 1 low, 3 informational.
Fix status
Report states 100% of findings addressed; independent remediation retest not identified.
Report url
https://storage.googleapis.com/dapp_prod/audit_reports/halborn_program_audit_250605.pdf
Report id
doc:840410292a5a3d81
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Halborn — USX Staking security assessment. No change identified since the prior check. The report is published in the bundled Halborn PDF; a deployed-program bytecode/build match was not independently established.

Auditor
Halborn
Report date
2026-03-31
Scope
Solana USX Staking programs; engagement December 1–3, 2025.
Findings
2 total: 0 critical, 0 high, 0 medium, 0 low, 2 informational. Findings: zero-asset transfers can cause full vesting delays; two-step authority transfer could be improved.
Fix status
Report states 100% of findings addressed by Solstice; independent remediation retest not identified.
Report url
https://storage.googleapis.com/dapp_prod_v2/audit_reports/halborn_program_audit_260327.pdf
Report id
doc:e21ae6450d8cdf5b
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Halborn — USX Program security assessment

Auditor
Halborn
Report date
2025-06-13
Scope
Solana USX Program; engagement April 22–May 6, 2025.
Findings
11 total: 0 critical, 0 high, 1 medium, 5 low, 5 informational. The report states all reported findings were addressed.
Fix status
Reported as 100% addressed by Solstice; independent retest details were not identified.
Evidence (2)

audit

one source

Halborn — USX Rewarder security assessment

Auditor
Halborn
Report date
2026-01-12
Scope
Solana USX Rewarder program; engagement December 8–15, 2025.
Findings
0 findings: 0 critical, 0 high, 0 medium, 0 low, 0 informational.
Fix status
No reported findings requiring remediation.
Evidence (1)

audit

unverified

Solstice states it has three independent smart contract audits by Halborn covering the USX Program, YieldVault Program, and governance contracts. The security page also says the contracts are non-upgradeable and the protocol uses a 3/5 multisig with a 24-hour timelock.

Auditor
Halborn
Report date
2026-08-30
Scope
USX Program; YieldVault Program; governance contracts
Evidence (3)

audit

unverified

Solstice says Richie May performed an independent financial audit of the Equinox Fund and protocol financials. This is a financial audit, not a smart-contract security audit, so it does not by itself establish coverage of deployed code.

Auditor
Richie May
Report date
2026-08-30
Scope
Equinox Fund and protocol financials
Evidence (1)

audit

unverified

Solstice says Sep2 provided a secondary audit for additional assurance on contract security, access controls, and economic attack vectors. No finding counts, remediation status, or exact report date were visible in the search results, and the underlying report was not retrieved here.

Auditor
Sep2
Report date
2026-08-30
Scope
Additional assurance on contract security, access controls, and economic attack vectors
Evidence (2)

Team & Reputation

founders

two sources

Solstice is a public, non-anonymous, institutionally-backed DeFi protocol on Solana, led by named executives with prior TradFi/crypto experience and incorporated in Switzerland via Solstice Labs AG and the Solstice Foundation. ### Founders & Key Team

  • Ben Nadareski – CEO & Co‑Founder
  • Previously Vice President of Global Trading at Galaxy Digital, a major crypto financial services firm.
  • Background in traditional finance and crypto trading.
  • Tim Grant – Co‑Founder & Chairman
  • CEO of Deus X Capital, a ~$1B AUM digital asset investment firm that backs Solstice.
  • Past roles at Galaxy Digital, SIX Digital Exchange, and R3, indicating long-standing institutional and infrastructure experience.
  • Chris Abbott – Chief Product Officer
  • 20+ years of experience in product strategy and UX; has founded and exited several Web3 ventures.
  • Broader team: 35+ people across ~10 countries, including veterans from Solana Labs, Coinbase, BlackRock, Galaxy Digital, Deloitte, etc. All of the above are *named individuals* with trackable prior careers, so the protocol is not anons-only and presents a standard corporate leadership structure rather than pseudonymous founders. ### Corporate Reality: Jurisdiction, Office, Onshore/Offshore
  • Solstice Finance is “developed by Solstice Labs AG, a Deus X Enterprise company, in partnership with the Solstice Foundation.”
  • Media coverage describes Solstice as a Zug, Switzerland-based firm, i.e., an onshore Swiss jurisdiction commonly used for crypto/fintech.
  • The set‑up references a licensed, approved manager and fund to provide institutional-grade access, implying some regulated entity involvement, but exact license details are Not verifiable as of 2026‑09‑03 from available sources.
  • No explicit physical office address is given in the reviewed materials; presence in Zug is reported, but full office verification is Not verifiable as of 2026‑09‑03. ### Prior Track Record, Credibility, and Incidents
  • Solstice claims a three‑year institutional track record and $375M+ in managed assets, backed by Deus X Capital; these figures appear only in Solstice’s own materials and therefore are unverified marketing claims.
  • Launch communications highlight backing by Galaxy Digital, MEV Capital, Bitcoin Suisse, Auros, and Deus X Capital, with $160M TVL at launch; these are reported in third‑party press releases and crypto media, which increases but does not fully confirm credibility.
  • As of the information reviewed, there are no publicly reported protocol hacks or major exploit incidents involving Solstice. Not verifiable as of 2026‑09‑03 beyond absence of media reports. ### Reality Check: Business vs. Web Front
  • The combination of:
  • identifiable founders with long-standing TradFi/crypto careers,
  • backing and ownership by Deus X Capital with $1B+ AUM,
  • incorporation and operations from Zug, Switzerland, and references to a licensed manager, suggests Solstice is operating as a real asset‑management business with an onchain protocol front, not just a purely web-native anonymous project. Contradiction Callout:
  • Solstice’s website states “$375M+ in managed assets” and “largest Solana-native settlement layer at launch”—these are unverified marketing claims, as we lack on-chain or independent analytics confirmation under current constraints.
  • Any TVL/asset figures not independently cross‑checked are Not verifiable as of 2026‑09‑03.
Evidence (5)

general reputation

two sources

Solstice currently has a pro-institutional, generally positive reputation, backed by well-known investors and media coverage, with no public fraud/rug/insolvency or sanctions allegations found as of 2026‑09‑03, but transparency on audits and legal structure remains a key open point. Founders, team, investors, backing

  • Operated by Solstice Labs AG, a Zug, Switzerland–based firm developing the protocol in partnership with the Solstice Foundation.
  • Publicly described as an *on‑chain asset manager* with a 35+ person team, “three-year institutional track record,” and **$375M+ in managed assets” — this is an *unverified marketing claim* from the project’s own site.
  • Backed by Deus X Capital (≈$1B AUM) and launch investors including Galaxy Digital, MEV Capital, Bitcoin Suisse, Auros, and Deus X Capital. These are recognizable institutional names, which is reputation‑positive. Audits, security, and risk signaling
  • No independent audit report from major firms (e.g., Trail of Bits, Quantstamp) is visible in the gathered data. Audit status is Not verifiable as of 2026‑09‑03.
  • Marketing emphasizes “institutional‑grade,” “delta‑neutral” strategies and use of licensed, approved managers and funds, but this is not backed by regulator filings in the retrieved data. Media and community sentiment
  • Coverage from The Defiant describes Solstice as a Solana DeFi protocol launching USX and YieldVault to provide permissionless access to delta‑neutral yield, in a neutral‑to‑positive tone.
  • Finance Yahoo and CoinDesk report on structured yield products (e.g., splitting preferred‑stock dividends into senior/junior tranches) and the launch of the SLX token at >$400M TVL, again in neutral‑to‑positive, institutional framing.
  • Exchange/academy content (Hotcoin, CoinEx, Bitget) portrays Solstice as a Solana‑native yield layer with institutional strategies and strong performance, but these largely echo project claims and should be treated as secondary/marketing‑aligned. Criticisms, incidents, legal/regulatory
  • No reports of rug pulls, insolvency, hacks, or major loss events were identified in the retrieved data as of 2026‑09‑03.
  • No visible regulatory actions, sanctions, or court cases against Solstice, Solstice Labs AG, or key products (USX, SLX, YieldVault) in the gathered material.
  • Key unresolved concerns:
  • Audit transparency and formal security assessments.
  • Clarity of regulatory licensing and investor‑protection frameworks beyond marketing language around “licensed managers”.
  • Independent verification of track record, TVL, and risk metrics (IRR, Sharpe) quoted in marketing and exchange reports.
Evidence (10)

Economy

TVL: $235.0M

model

one source

Assessment (as of September 5, 2026): Solstice is a Solana-only synthetic-stablecoin/yield protocol. Users deposit USDC/USDT to mint or acquire USX, then deposit USX into YieldVault strategies and receive yield-bearing tokens such as eUSX or structured-credit tokens. Solstice describes eUSX as market-neutral/delta-hedged, using funding-rate capture, basis trading, and hedged liquidity provision; strcUSX adds directional/external exposure to Strategy Inc.

STRC preferred income. These strategy descriptions are unverified marketing claims. Economic model: Yield is intended to be organic strategy income rather than token incentives; DeFiLlama reports zero incentives and states that fees are yield distributed to eUSX holders, with zero protocol revenue. External exposure exists through structured credit and, according to the roadmap, AI-infrastructure lending; direct verification of assets, counterparties, collateral composition, leverage, looping, or restaking is Not verifiable as of September 5, 2026. Withdrawals/constraints: YieldVault deposits have a minimum 7-day redemption window.

The site also says “withdraw anytime,” creating an unresolved mechanics ambiguity; exact gates, queueing, fees, limits, and settlement timing are Not verifiable as of September 5, 2026. Institutional direct minting reportedly requires $500,000+, while retail-access claims conflict with jurisdictional disclosures. APY sustainability: Reported figures include 21.5% for 2024, 13.96% three-year IRR, and 8.4% rolling 12-month APY; these are protocol-reported and not independently validated. APY history/volatility and organic-versus-subsidized attribution are Not verifiable as of September 5, 2026. TVL / contradiction: DeFiLlama reports $237.91m TVL, 100% on Solana, down 53% over 30 days.

The protocol site reports $371.70m, so the gap is a finding; on-chain Dune verification is unavailable. Product-level TVL and Dune-vs-Llama reconciliation are Not verifiable as of September 5, 2026. Risk conclusion: Economic exposure is primarily stablecoin reserve, basis-trading/counterparty, structured-credit, liquidity-window, and operational/custodial exposure—not demonstrably leveraged on-chain exposure. organic_yield_pct: null leverage_ratio: null

Evidence (4)

reserves

unverified

As of September 5, 2026, Dune MCP is unavailable for this run; therefore Solana balances, reserve addresses, liabilities, and chain-level reconciliation are Not verifiable as of September 5, 2026. Reported reserve framework: Solstice describes USX as overcollateralized and backed by audited cash, tokenized Treasuries, and delta-neutral hedged digital-asset positions. It states that off-chain assets are held with regulated custodians in segregated accounts and that Accountable provides continuous proof-of-solvency reporting. These are protocol/whitepaper claims and remain unverified marketing claims absent independent reconciliation. Size and composition: Exact reserve size, USD value, asset-by-asset composition, percentages, liquidity buckets, and encumbrances: Not verifiable as of September 5, 2026. Addresses and custody: Exact reserve wallets, custodian account identifiers, signer addresses, and legal ownership/control arrangements: Not verifiable as of September 5, 2026.

The security page claims 3/5 Squads multisig governance, a 24-hour timelock, PDA-only minting, and non-upgradeable contracts, but does not provide independently verified reserve-control evidence in the available material. Liabilities / attestations: Exact USX liabilities, coverage ratio, redemption obligations, and current attestation values: Not verifiable as of September 5, 2026. The indexed dashboard shows reserve and liability fields, but they were displayed as loading/blank; it lists CEFFU & Copper attestation reports last updated November 2025, which is stale under the seven-day freshness rule. Contradiction / finding: Solstice claims real-time proof of solvency, while the accessible dashboard snapshot does not expose current reserve, liability, or coverage figures. The figures therefore cannot be independently confirmed.

No Dune query ID or execution ID exists for this run. Assessment: Reserve-policy detail, custody segregation, control rights, and attestations are insufficiently verifiable from independent evidence. Treat reserve size and solvency as unconfirmed.

Evidence (5)

tokenomics

two sources

As of September 4, 2026: Token: Solstice (SLX), Solana SPL mint SLXdx4BUt2v9uJQNzWqSfzTJ9UKLUDsvxHFMEEdrfgq. This matches Solstice exchange documentation; a different Solscan “Solstice” mint (H7bQ...) appears to be a namesake and is excluded. Supply/valuation: Total and maximum supply are 1.0bn SLX; circulating supply is 242.854m.

DeFiLlama reports approximately $16.4m market cap, $67.6m FDV, and $53.4m outstanding FDV; these are aggregator figures, not on-chain verified. Utility/governance: SLX is used for access, staking and governance. Staking mints stSLX, which reportedly unlocks priority YieldVault access, redemption privileges, credit-market participation and higher Nexus tiers.

Governance is phased: the Foundation/Risk Committee currently retains substantial control, with signaling and later binding votes expected from stSLX holders. SLX does not confer dividends, profits or equity. Value accrual: No confirmed SLX revenue share or fee distribution.

DeFiLlama reports $0 protocol revenue and $0 incentives despite fees generated, with yield passed to eUSX holders. The application reports zero SLX burned and zero bought back; milestone-based burns are described in published materials but not evidenced here. Allocations/emissions: Published allocation data conflict: Solana Compass reports community 37.71%, foundation 24%, team/advisors 20%, airdrops 10%, strategic TVL partners 8%, public sale 0.29%; an earlier whitepaper describes a maximum 10% airdrop pool, while Season 2 advertises 3%.

Fixed supply/zero inflation is reported, but a complete emissions and vesting calendar is Not verifiable as of September 4, 2026. Whether announced unlocks occurred on-chain is Not verifiable as of September 4, 2026. Controls/concentration: Mint, freeze/blacklist, fee-switch authorities, controller identities, top-holder concentration and insider-wallet attribution are Not verifiable as of September 4, 2026 (Dune unavailable; no substitute on-chain inference used). Liquidity/listings: Solana Compass identifies Raydium and Orca liquidity; Bitget and other centralized venues report SLX listings.

DEX liquidity depth and slippage at institutional trade sizes are Not verifiable as of September 4, 2026.

Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Solstice on Solana, a Bitcoin move below $10,000 is Not verifiable as of 2026-09-03 from the available web results. None of the retrieved sources provide protocol-specific, on-chain, or audit-backed evidence showing Solstice’s loss mechanics, collateral composition, or liquidation thresholds under a BTC<$10k scenario. What *is* visible in the results is only a general market context: several third-party articles discuss BTC $10,000 as a broad macro stress or tail-risk level, and some note that Strategy-related structures would only face severe stress at that level.

One source also discusses a Solstice product built around Strategy’s STRC preferred stock and states a modeled senior impairment threshold of $47.66 for that structure, but that is not enough to map Solstice’s actual exposure to a BTC<$10k shock without verified protocol data. Because Dune/on-chain checks are unavailable in this run, I cannot verify Solstice’s TVL, asset mix, redemption gates, or whether the protocol has direct or indirect Bitcoin exposure. Any claim that Solstice would be safe, impaired, or insolvent under BTC<$10k would be speculation based on the current evidence set.

Evidence (8)

stress scenario - largest collateral depegs 20%,

one source

For a 20% depeg of the largest collateral, the protocol’s loss depends on whether that collateral is backing a given liability pool or just part of a diversified reserve. The web results only confirm that Solstice says USX is overcollateralized and backed by a diversified reserve of cash, tokenized Treasuries, and delta-neutral hedged positions; they do not provide enough data to quantify the realized loss from a 20% collateral price shock. Therefore, the stress impact is Not verifiable as of 2026-09-03.

What can be stated from the available sources is narrower: Solstice said the December 2025 USX dislocation was a secondary-market liquidity issue, not a collateral failure, and that primary-market redemptions stayed available while reserves remained above 100% collateralized. Those statements indicate the protocol claims resilience to market dislocations, but they do not establish the capital impact of a 20% move in the largest reserve asset. In other words, a 20% depeg could be immaterial, partially absorbed, or severe depending on reserve composition, concentration, haircuts, and whether the asset is used in hedged or unhedged positions; none of that is disclosed in the retrieved material.

The only defensible conclusion is that the requested scenario cannot be numerically assessed from the provided evidence, and any percentage-loss estimate would be speculation.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

For Solstice on Solana, the relevant counterparty-insolvency stress path is concentrated in the yield legs, not the base USX mint/redeem layer. Solstice says USX is overcollateralized and backed by audited cash, tokenized Treasuries, and delta-neutral hedged positions, while eUSX/YieldVault strategies explicitly carry counterparty risk on exchanges and funding-rate reversal risk. Expected loss path: if a top counterparty used by a strategy becomes insolvent, the first loss is borne by the affected strategy sleeve, where positions may be impaired, unwound at a discount, or become temporarily inaccessible. For USX, the loss path would be through reserve impairment only if the insolvent counterparty is part of the reserve stack or hedging stack; Solstice’s public materials say reserves are continuously verified and overcollateralized, but the exact legal waterfall for an offchain counterparty default is Not verifiable as of 2026-09-03. Who absorbs it: the immediate absorber is the specific strategy or reserve pool linked to that counterparty, then any junior tranche / token holders exposed to that pool; Solstice also describes a senior/junior-style structure for newer products, which implies losses can be allocated within product tranches before reaching the base layer.

If a loss exceeds the affected sleeve, the economic hit would pass to holders of the relevant yield token or vault shares, not automatically to unrelated USX holders, based on the separation between USX mint/redeem and YieldVault positions. Compensation: Solstice’s public materials do not specify a dedicated insurance fund or contractual loss-socialization mechanism for counterparty insolvency. It does say redemption for USX is available and YieldVault positions have a minimum 7-day redemption window, but whether redemptions remain at par after a counterparty default is Not verifiable as of 2026-09-03. Impact path through smart contracts: the affected Solana program would likely be the YieldVault or USX-related program that records the strategy position, with oracle-priced NAV updates, redemption processing, and any collateral-management logic changing token value or exit availability; Solstice states these contracts are audited by Halborn and Sep2 and use multi-oracle pricing, PDA-controlled minting, and onchain solvency verification. What is Not verifiable as of 2026-09-03 is the exact on-chain liquidation/default waterfall for a named counterparty failure.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

I could not verify any committed fraud by Solstice’s DAO or owners from the provided sources. The only Solstice-specific material here is the protocol’s own security/terms page, which states USX and SLX use non-upgradeable SPL programs and that deployed code cannot be changed, but that is an unverified marketing claim unless corroborated by independent evidence. On the available evidence, the stress-case assessment is Not verifiable as of 2026-09-03.

There are no independent reports in the supplied results showing a DAO treasury drain, malicious governance action, founder exit scam, or regulator/media allegation specific to Solstice on Solana. General DAO-fraud literature does show the kinds of fraud that can occur in governance systems—Sybil voting, malicious proposals, treasury diversion, and rug pulls—but those are category risks, not evidence that Solstice experienced them. The practical risk note for Solstice is narrower: if a protocol is truly non-upgradeable and Solana-native, that can reduce governance and bridge attack surface, but it does not itself prove the absence of fraud by owners or any off-chain misconduct.

Evidence (6)

stress scenario - primary yield source negative 30d,

unverified

Solstice’s *stated* primary yield sources are market-neutral strategies such as funding-rate capture, basis trading, and hedged liquidity provision, with eUSX described as a delta-neutral strategy. However, for a stress scenario where the primary yield source is negative over 30 days, the key risk is that these market-structure trades can stop earning or turn loss-making if funding, basis, borrowing, or hedge costs move against the book. What this means in practice:

  • Net yield could compress sharply or turn negative if the primary carry trades no longer offset hedge costs. The protocol’s own marketing emphasizes positive historical performance, but that does not eliminate drawdown risk in a regime shift.
  • Delta-neutral does not mean P&L-neutral. A strategy can be directionally hedged yet still lose money from spread widening, funding reversals, execution slippage, or liquidity stress.
  • If the negative 30-day period persists, the protocol would likely need to rely on *other* yield sleeves, fee subsidies, reserve income, or rebalanced allocations to stabilize user APY; those specific mitigants are Not verifiable as of 2026-09-03 from the provided results. Risk interpretation for an institutional review: the scenario is a strategy-level yield impairment rather than a solvency event by itself, unless losses exceed buffers or propagate into collateral/hedging structures. The current evidence set does not let me verify reserve size, loss buffers, or the exact waterfall. Not verifiable as of 2026-09-03.
Evidence (4)

Governance & Legal

governance

one source

As of September 13, 2026, governance is Foundation-led, not a fully decentralized DAO. The May 2026 whitepaper says the Solstice Foundation controls long-term direction; its Risk Committee sets initial parameters, reviews audits, approves deployments, handles incident response, and has extraordinary pause authority. SLX/stSLX currently provides signaling; binding token votes are a future phase.

DAO governance: false. Control map: Solstice Labs AG (Zug, Switzerland) provides development/advisory and appears to control the frontend/supporting infrastructure; its stated registration is CH-170.3.051.151-1 / CHE-239.924.206. Public registry-derived reporting lists Timothy Grant, Benjamin Nadareski, Stuart Connolly, and Marcus Maute as directors/signatories.

This is company-linked control, not token-holder control. Contracts/admin: the security page claims non-upgradeable USX/SLX programs, PDA-only USX minting, a Squads 3-of-5 multisig, and a 24-hour administrative timelock. The page does not disclose signer identities in the retrieved content, so signer independence is not independently verified.

Funds: Equinox Strategies Ltd, described as a BVI-licensed approved manager, operates Equinox Fund; separate issuance vehicles handle token minting/redemption. The Foundation directs governance and treasury deployment, while qualified custodians hold segregated fund assets. Proposal process: selected proposals receive community signaling; Risk Committee review remains operative.

The roadmap is Phase 2 staked-SLX signaling and Phase 3 binding votes on a widening parameter set. Voting concentration, top SLX holders, actual multisig signers, signer independence, and on-chain confirmation of timelock/admin powers: Not verifiable as of September 13, 2026. Dune was unavailable in this run, so no Dune query/execution IDs are available.

The Terms claim Solstice Labs does not control protocol operations after deployment, which conflicts with the whitepaper’s Foundation/Risk Committee control model; the on-chain/security claim wins only where verified, and it was not verified here.

Timelock
Yes
Timelock delay hours
24
Multisig threshold
3
Multisig owners
5
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Scope/identity: This is the Solana protocol using USX/eUSX/SLX at solstice.finance, not unrelated “Solstice” entities. Dune/on-chain verification was unavailable: Not verifiable as of September 4, 2026. Entity and jurisdiction: Public materials identify Solstice Labs AG, a Swiss company headquartered/registered in Zug, as the development/operator entity; the project whitepaper separately describes a Solstice Foundation for governance/token issuance and SLX Ltd as a BVI token issuer. SLX Ltd’s BVI incorporation is independently reflected in an LEI record.

However, the current Terms name only “Solstice Labs,” omit a legal registration number and specify governing law as the jurisdiction where Solstice Labs is incorporated. DefiLlama reports that user Terms are with Solstice Foundation under BVI law and references a Cayman registered seat—this conflicts with the Terms and Swiss-entity presentation. Finding: legal counterparty and liability perimeter are not consistently disclosed. Terms/restrictions: Terms describe a non-custodial Solana DeFi interface, broad disclaimers, user indemnity, a liability cap of the greater of fees paid or $100, and mandatory negotiation followed by arbitration. Users must be adults, comply with local law, and not be sanctioned or use the service for laundering, terrorist financing, or sanctions evasion.

Regional disclosures restrict products to professional/institutional users; Hong Kong products are not SFC-authorised for retail, Singapore products are not MAS-approved/licensed, and US/UK/China/comprehensively sanctioned jurisdictions are restricted for relevant products. KYC/AML/data protection: Singapore disclosure states KYC, source-of-funds and sanctions screening where required; no publicly verifiable universal KYC/AML policy or licensing perimeter was located. The privacy policy describes collection of contact details, wallet/on-chain data, IP/geolocation, cookies and analytics; it acknowledges immutable public-chain data cannot be deleted and provides access, rectification, erasure, objection and portability rights, but is expressly marked a draft requiring legal review. Classification/enforcement: The project characterizes USX/SLX as virtual assets and notes that certain products may be DPTs or capital-markets products. A reported MiCA Article 6 white-paper notification for SLX is not approval and does not cover USX.

Court cases, regulator warnings, and enforcement against this protocol/entity: Not verifiable as of September 4, 2026. Sanctions status of the protocol/entity: Not verifiable as of September 4, 2026. Legal form does not eliminate interface, issuer, fund-manager, marketing, AML, securities/derivatives, or consumer-protection exposure.

Entity
Solstice Labs AG; Solstice Foundation; SLX Ltd
Jurisdiction
Switzerland (Zug) for Solstice Labs AG; BVI for SLX Ltd; Solstice Foundation jurisdiction is inconsistent/not fully disclosed
Evidence (6)

legal registries

two sources

No exact GLEIF LEI record for 'Solstice Labs AG', 'Solstice Foundation', 'SLX Ltd'. OFAC SDN screening of 'Solstice Labs AG', 'Solstice Foundation', 'SLX Ltd': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Solstice Labs AG
  • Solstice Foundation
  • SLX Ltd
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Solstice does issue its own stablecoin, USX, on Solana. Available reporting supports one verifiable depeg event: on 2025-12-26 USX briefly fell as low as $0.10 on secondary markets before recovery toward $0.94-$0.99. On that basis, depeg_count is 1, the last depeg date is 2025-12-26, and max_depeg_pct is approximately 90%.

The stablecoin has since recovered toward peg, so the protocol is best classified as stable=true.

Own stablecoin
Yes
Stable
Yes
Depeg count
1
Max depeg pct
90%
Last depeg date
2025-12-26
Stablecoin ids
  • USX
Evidence (4)

Risks & Strengths

risks

two sources

Solstice’s principal risks arise from its smart-contract stack, off-chain yield and collateral dependencies, redemption liquidity, and governance/regulatory structure. The protocol advertises audits, non-upgradeable contracts, multisig governance, timelocks, and proof-of-solvency monitoring; these are protocol-reported mitigations and remain unverified on-chain because Dune was unavailable. On-chain balances, reserves, concentration, and latest block-level exposure: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract vulnerabilitiesUndiscovered logic, access-control, accounting, or integration bugs could freeze, misprice, or directly drain USX, vault, or reward positions. Audits reduce but do not eliminate exploit risk.HighMediumHalborn and Sep2 audits are reported; non-upgradeable contracts, PDA-only minting, monitoring, and administrative controls are advertised. Audit scope and deployed-code equivalence require ongoing verification.Material loss risk remains, particularly from unreviewed changes, composability, economic attacks, or Solana-runtime interactions.
Collateral and counterparty failureUSX yield and solvency depend on off-chain funds, custodians, prime brokers, trading venues, and Treasury/RWA exposure. A counterparty default, fraud, restriction, or delayed settlement could impair NAV or redemption.HighMediumThe protocol reports proof-of-solvency attestations, institutional counterparties, and financial audits. Independent reserve composition, legal claims, and counterparty limits are Not verifiable as of September 5, 2026.Users retain credit, custody, legal-enforceability, and concentration exposure outside Solana.
Redemption and liquidity mismatchStress withdrawals may exceed protocol buffers or immediately available fund liquidity, causing delays, discounts, queues, or temporary depeg of USX and vault shares.HighMediumSolstice describes reserve buffers, proof-of-solvency monitoring, and redemption mechanisms. Actual buffer size, withdrawal capacity, and stress-test results are Not verifiable as of September 5, 2026.A run can convert asset-quality risk into realized losses even if reserves are ultimately sufficient.
Strategy and market lossDelta-neutral or basis strategies can lose money through basis widening, liquidation, funding-rate reversal, execution slippage, volatile collateral, or model failure; advertised yield is variable and non-guaranteed.HighMediumRisk disclosures acknowledge volatility and variable yield; audits and institutional strategy management are cited. Position-level leverage, venues, hedges, and liquidation thresholds are Not verifiable as of September 5, 2026.Yield may fall sharply or become negative during stressed markets.
Governance and regulatory concentrationA small signer set or administrators may influence parameters, access, emergency actions, or product availability; regulatory, sanctions, KYC/AML, or securities-law changes could restrict users, assets, or redemptions.HighMediumThe protocol reports 3/5 multisig governance, a 24-hour timelock, disclosed signers, and jurisdictional restrictions. These controls and their current on-chain scope are Not verifiable as of September 5, 2026.Multisig capture, signer collusion, legal intervention, or jurisdictional loss of access remains possible.
Evidence (4)

strengths

two sources

Solstice’s top strengths are: 1) Solana-native design, which lets it benefit from Solana’s fast settlement, low fees, and composability; 2) a focused yield-layer model, positioning the protocol as infrastructure that routes stable capital into productive strategies rather than a single-product DeFi app; 3) institutional-style yield strategies, including delta-neutral and market-neutral approaches that aim to reduce directional risk; 4) composable product architecture, with USX, eUSX, YieldVault, and SLX forming a closed loop from settlement to yield to governance; and 5) a claimed multi-year operating track record, with the protocol stating a three-year live history and positive monthly returns across its strategy set. These points are supported primarily by Solstice’s own positioning and independent summaries that describe the same Solana-native, institutional-yield design, but the performance and track-record claims remain unverified by on-chain checks here and should be treated as protocol claims, not independently confirmed facts.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 14 two independent sources, 11 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-30.