Spiko

Orange · 66/100

Executive summary

Spiko is a Paris-based regulated fintech issuing tokenized UCITS money-market funds (USTBL, EUTBL) across Ethereum, Arbitrum, Polygon, Base, Starknet, Etherlink, and Stellar, scoring 76/100 (green band) with 92/100 data confidence.

  • Security: Four audits by Halborn, Trail of Bits, and Nethermind (2023–2025); Halborn's October 2025 Stellar audit found 1 critical issue (redemption burning from wrong account) marked solved, but deployed-bytecode match is not verifiable as of August 2026. Trail of Bits (October 2023) found 0 critical/high, 2 low (token lock risk, no minimum redemption), 2 informational; fix status and current-code match are not verifiable. Nethermind audits exist but detailed findings/remediation are not verifiable.
  • Governance & custody: Company-controlled; no DAO or public governance token verified. Spiko Finance SASU (France, ACPR-licensed CIB 19183) manages permissions via Safe multisig (threshold/signers not public) and internal Dfns-secured relayer. UUPS-upgradeable contracts with privileged mint/burn/pause/upgrade roles create material admin risk; whether admin can directly drain user funds is not verifiable as of September 2026. Underlying fund assets held by CACEIS Bank (depositary), segregated from Spiko's balance sheet.
  • Top risks: Permissioned architecture with centralized upgrade/mint/burn authority; admin compromise or malicious upgrade could freeze/confiscate tokens. NAV/liquidity risk from underlying T-bills and fund concentration. Oracle failure or stale NAV publication could impair transfers. Redemption processing is centralized (next-day NAV, business-day settlement). Chainlink CCIP cross-chain dependency adds bridge/message-delivery risk. No bug bounty program verified.
  • Incidents: No verified hacks, exploits, or fraud allegations as of September 2026.
  • Strengths: Regulated institutional product (French UCITS/MMF framework, AMF oversight, CACEIS custody); transparent on-chain fund-share register; 24/7 transferability; API/smart-contract integration for treasury workflows; positive reputation as low-to-moderate-risk RWA platform; public founders (Paul-Adrien Hyppolite, Antoine Michon) with credible backgrounds.
  • Unverified: TVL/AUM ($2.53B claimed, not independently verified); current deployed-code match to audited versions; multisig composition/independence; bug-bounty program; exact BTC/collateral exposure and stress-loss paths; native governance token (none found).
  • Recommended exposure: Conservative allocation as cash-equivalent/T-bill proxy for institutional treasuries seeking regulated, tokenized yield; limit to <10% of portfolio given centralized admin control, upgrade risk, and unverified bytecode-audit match. Suitable for users comfortable with KYC/allowlist restrictions and next-day redemption processing. Avoid if permissionless custody or immediate exit is required.
  • Open questions: Verify deployed contract bytecode matches latest audited commits across all seven chains; confirm Safe multisig threshold, signer identities, and independence; obtain independent on-chain TVL/AUM verification; clarify exact admin powers over user balances and upgrade timelock/notice period; review CACEIS custody agreement and fund prospectus for redemption gates/suspension terms; assess Chainlink CCIP bridge risk and cross-chain fund-share reconciliation.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 4 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 50 10.0 no full audit on record; latest report 2025-11-03
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 15 3.0 TVL $2,635,149,980 = 15% of reference ($17,538,184,136)
Data confidence 92 7/7 critical categories; 21/34 verified facts; 34/34 fresh (180d)

Identification

protocol identification

two sources

Spiko is not a typical DeFi yield protocol, but a Paris‑based fintech issuing tokenized UCITS money‑market funds (e.g. EUTBL, USTBL, SAFO) across multiple chains. It functions as a regulated RWA/cash‑management product, using blockchains as a shareholder register and transfer rail rather than as an on‑chain AMM or lending protocol. Protocol identification

  • Name: Spiko (issuer of tokenized money‑market funds such as EUTBL and USTBL).
  • Website: spiko.io (confirmed by MrDeFi and CoinStats).
  • Docs: docs.spiko.fr (French‑language documentation site).
  • Category: Tokenized regulated money‑market / RWA cash fund, not permissionless DeFi lending/AMM.
  • Launch date: Not explicitly stated in independent sources; Not verifiable as of 2026‑09‑03.
  • Supported chains: Arbitrum, Base, Ethereum, Etherlink, Polygon, Starknet, Stellar are consistently listed as deployment networks for Spiko funds.
  • Native token: There is no single “protocol token”; instead, Spiko issues multiple fund share tokens such as EUTBL (EU T‑Bills fund), USTBL (US T‑Bills fund) and SAFO (Spiko Amundi Overnight Swap Fund). Key fund token contract addresses (cross‑checked) For EUTBL (EU T‑Bills Money Market Fund):
  • Ethereum: 0xa0769f7a8fc65e47de93797b4e21c073c117fc80
  • Polygon PoS: 0xa0769f7a8fc65e47de93797b4e21c073c117fc80
  • Base: 0xa0769f7a8fc65e47de93797b4e21c073c117fc80
  • Etherlink: 0xa0769f7a8fc65e47de93797b4e21c073c117fc80
  • Arbitrum One: 0xcbeb19549054cc0a6257a77736fc78c367216ce7
  • Starknet: 0x04f5e0de717daa6aa8de63b1bf2e8d7823ec5b21a88461b1519d9dbc956fb7f2
  • Stellar asset ID: CBGV2QFQBBGEQRUKUMCPO3SZOHDDYO6SCP5CH6TW7EALKVHCXTMWDDOF These addresses are independently consistent across Holder.io and CoinStats, which rely on different data sources. Direct explorer verification status (e.g., contract name, verified flag) is Not verifiable as of 2026‑09‑03 without live explorer access. Fork lineage & code provenance
  • Public sources describe Spiko as an issuer of regulated UCITS funds tokenized on-chain, not as a fork of DeFi lending/AMM protocols (e.g., Aave, Compound).
  • No independent report identifies Spiko’s fund token contracts as forks of a specific upstream DeFi protocol; the design is closer to RWA share‑token implementations with off‑chain NAV/accounting.
  • Therefore, fork status, specific upstream codebase, and changes vs. upstream are Not verifiable as of 2026‑09‑03.
  • Likewise, audits of the on‑chain contracts and any history of malicious modifications in similar forks are Not verifiable as of 2026‑09‑03, given the absence of independent audit PDFs or incident reports in retrieved data.
Evidence (15)

maturity

one source

Spiko appears to be a real product site, not just a landing page: the main site and use-case pages describe live deposits, withdrawals, transfer timing, fees, and 2FA/four-eyes controls, which are consistent with an operating financial portal rather than a template-only brochure. Independent API-directory coverage also indicates developer-facing functionality, including a public API plus investor/distributor APIs for account management and deposit/withdrawal orders. That said, full UX health is not verifiable as of 2026-09-03: broken links, template reuse, fake metrics, and end-to-end portal behavior could not be checked here.

The docs presence is strong, with a dedicated documentation site and a quickstart showing authenticated calls and real balances/withdrawals, suggesting an open API exists. For maturity, this looks like a functioning fintech platform with public docs and transactional APIs, but some product claims are still unverified from independent sources and should be treated as vendor-supplied until cross-checked further.

Evidence (8)

Security

bug bounty

two sources

Not verifiable as of 2026-09-03. The web results did not surface any Spiko-specific bug bounty program; the only matching bounty results were for unrelated entities named Spike/Spiko-branded pages, which are not enough to confirm a program for this protocol. No start date, scope/parameters, payout structure, or published results could be verified from the available sources.

Evidence (3)

counterparty risks

two sources

As of September 5, 2026, no active dependency failure was identified in the reviewed sources; however, incident status is Not verifiable as of September 5, 2026 because Dune/on-chain monitoring was unavailable. Dependency map and risk findings

  • Core RWA issuer/SPV: Spiko’s principal products appear to be tokenized shares of French UCITS money-market funds (USTBL/EUTBL), investing in US and European Treasury bills. The fund—not a DeFi lending vault—creates the primary exposure to the asset manager, fund governance, sovereign issuers, administrator and depositary.
  • Custodian / banking counterparty: Spiko identifies CACEIS Bank, a Crédit Agricole subsidiary, as depositary/custodian; client cash is stated not to be held by Spiko. CACEIS concentration is therefore a material operational and insolvency dependency.
  • Oracle and privileged control risk: The contracts use an Oracle implementing Chainlink’s AggregatorV3Interface; token transfers are permissioned and controlled through a Spiko-managed PermissionManager. Oracle failure, stale NAV publication, administrator compromise or allowlist censorship could impair transfers/redemptions.
  • Bridge/interoperability: Spiko announced Chainlink CCIP for cross-chain distribution. This adds Chainlink/CCIP, message-delivery and destination-chain failure modes. Supported-chain balances are not independently verifiable here.
  • Stablecoin and payment exposure: Since June 30, 2026, subscriptions/redemptions can use USDC and EURC through Coinbase Payments, initially involving Base. This introduces USDC/EURC depeg, Circle/Coinbase service, sanctions, settlement and Base availability risk.
  • CEX/MM and derivatives exposure: Spiko’s newer Cash and Carry product references Marex execution, MSCI/Compass index calculation, and BNP Paribas bank-counterparty exposure. Whether this product is included in the reported Spiko TVL is Not verifiable as of September 5, 2026.
  • External DeFi, LST/restaking exposure: Specific Aave, Compound, Lido, Pendle, restaking or stablecoin-yield allocations are Not verifiable as of September 5, 2026. Morpho integration is documented for secondary liquidity, not proof of balance-sheet exposure. Contradiction / concentration callout: DeFiLlama reports approximately $2.503B TVL, with Stellar 62.7%, Arbitrum 17.6%, Ethereum 9.9%, Polygon 6.7%, Base 1.6%, Starknet 1.3% and Etherlink 0.2%. This differs materially from Spiko’s earlier $380M disclosure; the difference is unresolved and likely reflects changing dates or metric scope. Aggregator data is not on-chain verified. Failure scenarios include custodian/bank insolvency, Treasury or fund NAV disruption, oracle/CCIP outage, permission-manager compromise, stablecoin depeg, Coinbase payment suspension, or Marex/BNP counterparty default. No maximum aggregate external-counterparty exposure percentage can be established without current fund disclosures and on-chain verification.
Evidence (7)

crypto custody

unverified

Spiko’s custody is organized in two layers. At the fund layer, the underlying cash and Treasury-bill assets are held by CACEIS, which Spiko and CACEIS describe as the custodian/depositary; CACEIS also provides the secure wallets used for on-chain custody of investors’ fund units, rather than holding the assets in an omnibus pool with the custodian’s own assets. At the token layer, Spiko’s smart-contract system restricts token ownership to KYC-verified allowlisted addresses and separates duties across a multisig-controlled super-admin, an internal relayer for mint/burn/redemptions, an oracle operator for NAV publication, and an allowlister for onboarding.

Withdrawal paused
No
Segregated assets
Yes
Evidence (2)

key management

two sources

Spiko’s key management is organized around a managed-wallet setup rather than end-user self-custody for its operational infrastructure. Spiko states that transaction signing is secured with a managed wallet from Dfns, and Dfns says Spiko uses its platform to secure and automate wallet infrastructure. Operationally, the clearest published description is that Spiko separates duties across multiple wallet roles in its Stellar stack: a channel account supplies sequence numbers for parallel transactions, a main wallet signs Soroban authorization entries, and a sponsor wallet wraps the transaction in a fee-bump to pay fees.

Spiko also says it uses a dedicated multisig wallet for the super-admin permission group, which has full access to upgrade contracts and manage permissions. For smart-contract access control, Spiko centralizes privilege management in a dedicated Permission Manager using permission groups; this governs allowlisting, minting, burning, pausing, oracle publishing, and administrative upgrades. In other words, key management is split between operational signing wallets, a multisig-controlled admin role, and contract-level permissions rather than a single master key.

Not verifiable as of 2026-09-03: the public sources do not provide a complete, chain-by-chain inventory of all signing keys, custody arrangements, rotation policy, backup/recovery procedures, or whether the same operational model is used identically across Ethereum, Arbitrum, Polygon, Base, Starknet, and Etherlink.

Evidence (5)

smart-contract

two sources

Assessment — as of September 5, 2026. Spiko is materially permissioned and upgradeable, not a permissionless yield vault. Verified architecture (EVM): UUPS/ERC-1967 proxies for Token, Oracle, Redemption and PermissionManager, with OpenZeppelin-based implementations. The repository documents a shared PermissionManager and ERC-2771 forwarder. Arbitrum addresses recorded in the deployment artifacts include: PermissionManager 0xa925C217e4c1C82Ee721eBD496d3863D5C2d829A; Redemption 0x15EA0EC460a0E6847EC0AA8D50A84B3A51B95f74; EUTBL 0xCBeb19549054CC0a6257A77736FC78C367216cE7; USTBL 0x021289588cd81dC1AC87ea91e91607eEF68303F5; EUTBL oracle 0xe4880249745eAc5F1eD9d8F7DF844792D560e750. `` Admin / permission groups │ ▼ PermissionManager ──► Token proxy ──► Token implementation ├─────────► Oracle proxy ──► Oracle implementation └─────────► Redemption proxy ──► Redemption implementation `` Privileged functions: deployment configuration assigns roles for minting, burning, pausing/unpausing, transfers/whitelisting, NAV publication, redemption execution and mint approval/cancellation.

The admin controls role membership; the documented EVM design therefore permits censorship/freezing and arbitrary implementation upgrades. A compromised upgrade authority could replace logic to mint unlimited tokens, falsify NAV, block transfers/redemptions, or introduce asset-draining behavior. This is an architectural inference, not an on-chain execution result. Exit risk: users can request redemption, but execution and token burning require privileged operators; autonomous user exit is not established. Not verifiable as of September 5, 2026 whether every live deployment permits withdrawal while operators/admins are offline. Admin type, live owners, proxy-admin custody, renouncement status and timelock delay: Not verifiable as of September 5, 2026 because Dune/on-chain verification is unavailable.

No public evidence establishes a timelock or disclosed multisig threshold. Audit status: Trail of Bits audited the EVM code in October 2023; Halborn audited Stellar contracts in September 2025 and reported 1 Critical and 0 High findings, marked solved. The audit scope does not prove all current deployments or later features are audited. Finding: high admin/key, freeze, oracle and upgrade risk; rug risk is principally governance/implementation risk rather than an observed direct withdrawal function. Stellar’s reported Critical redemption bug was remediated.

Admin can drain
Yes
Upgradeable
Yes
Evidence (5)

audit

one source

Halborn — Stellar Contracts assurance assessment.

Auditor
Halborn
Report date
2025-10-03
Scope
Spiko Stellar Soroban smart-account contracts; assessed commit b66c29e, covering permission manager, token, redemption, and utilities.
Findings
Critical: 1; High: 0; Medium: 0; Low: 1; Informational: 3. Critical: redemption execution burns from the user account instead of the Redemption contract, potentially locking escrowed funds. Low: admin can renounce and leave the contract without an admin. Three informational findings concern idempotency/zero-amount operations, initialization placement, and documentation.
Fix status
All 5 findings marked Solved; Halborn reports 100% addressed. Deployed-code match: not independently verified as of September 6, 2026; the report identifies source commits, not deployed WASM hashes.
Report url
https://www.halborn.com/audits/spiko/stellar-contracts-879885
Report id
doc:6725855f351ab3e5
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

Nethermind — Spiko contracts repository audit report.

Auditor
Nethermind
Report date
2023-04-19
Scope
Spiko EVM contracts repository; exact in-scope contract set and deployed-chain coverage are not verifiable from the publicly retrievable report text.
Findings
Critical, High, Medium, Low, and Informational counts: Not verifiable as of September 6, 2026.
Fix status
Not verifiable as of September 6, 2026. Public report existence and historical date are confirmed, but remediation status and deployed-code/bytecode match are not established.
Report url
https://github.com/NethermindEth/PublicAuditReports/blob/main/NM0333-FINAL_SPIKO.pdf
Report id
doc:78cdc65115dce43e
Covers deployed code
No
Evidence (2)

audit

two sources

Nethermind Security — Spiko Token & RWA / MultiATM audit.

Auditor
Nethermind Security
Report date
2025-11-03
Scope
Solidity MultiATM contract supporting oracle-priced atomic token swaps, multi-hop swaps, and meta-transactions.
Findings
Critical: 0; High: 0; Medium: 0. Low and Informational findings: Not verifiable as of September 6, 2026 from the publicly retrievable report text.
Fix status
Not verifiable as of September 6, 2026. Public listing confirms the report and scope, but finding-by-finding remediation and deployed-code/bytecode match are not established.
Report url
https://github.com/NethermindEth/PublicAuditReports/blob/main/NM_0691_Spiko_Final%20.pdf
Report id
doc:8495e5b64b666dc4
Covers deployed code
No
Evidence (2)

audit

two sources

Trail of Bits — Spiko Smart Contracts security review.

Auditor
Trail of Bits
Report date
2023-10
Scope
Ethereum/EVM Solidity contracts covering token, redemption, oracle, and permission-management logic.
Findings
Critical: 0; High: 0; Medium: 0; Low: 2; Informational: 2. Low findings: tokens can be locked in the Redemption contract; no minimum redemption amount. Informational findings: event emissions are ignored in the test suite; publishPrice can modify an existing price or lock the oracle.
Fix status
Exact finding-by-finding remediation status: Not verifiable as of September 6, 2026. Trail of Bits marks a separate fix-review indicator in its archive, but no deployed-code/bytecode match was established; the review predates later deployments and feature changes.
Report url
https://github.com/trailofbits/publications/blob/master/reviews/2023-10-spiko-securityreview.pdf
Report id
doc:af4efe8a02df126c
Covers deployed code
No
Evidence (2)

Team & Reputation

founders

two sources

Spiko appears to be a real Paris-based fintech, not a pure web-front: its company profile says it was founded in 2023, has offices in Paris and London, and is licensed/supervised by French authorities (ACPR/AMF) as a MiFID investment firm. The founders are public, not anonymous: Paul-Adrien Hyppolite is listed as CEO and Antoine Michon as co-founder/COO (or general director), with both also shown on LinkedIn and in France FinTech. Founders & prior roles

  • Paul-Adrien Hyppolite: former French Treasury official responsible for regulation of financial instruments markets; also lists strong academic credentials.
  • Antoine Michon: former ministerial adviser on digital transformation and previously worked at Palantir; LinkedIn and company materials align on his role.
  • The broader team is also public, including a CTO (Samuel Briole) and legal/compliance leadership, which is a positive credibility signal for a regulated financial product. Reality check
  • There is a credible onshore footprint: Paris is the stated HQ, London is an additional office, and LinkedIn/company listings consistently point to France/Paris.
  • The company claims >€1 billion deployed and a $22 million Series A, but those are only verified here as company/press claims; independent on-chain verification is Not verifiable as of 2026-09-03.
  • I found no clear public evidence of hacks or security incidents in the material reviewed; absent a dedicated security review, that remains Not verifiable as of 2026-09-03. Bottom line: Spiko looks like a legitimate regulated fintech with named founders, a visible team, and a real physical presence. The main unresolved risk is not anonymity, but whether its public business metrics and TVL-style claims match independently verifiable data.
Evidence (8)

general reputation

two sources

Spiko currently has a generally positive, institution‑friendly reputation, framed more as a regulated fintech/tokenized fund platform than a typical permissionless DeFi protocol, with no public fraud, rug, insolvency or sanctions allegations identified. Not verifiable on-chain as of 2026‑09‑04. Positioning & institutional perception

  • Spiko is described as a Paris‑based regulated fintech tokenizing EU‑regulated money market funds (USTBL/EUTBL) on public chains, rather than a pure DeFi yield farm.
  • Independent commentary (DeFi Bullshit Detector) emphasizes that it is *not a traditional DeFi protocol* but a regulated product issuer using blockchain, rating core products “low‑to‑moderate risk” under a TradFi-style framework.
  • Multiple analytics/educational sources present Spiko as institutional‑grade, UCITS‑compliant money market fund tokenization, focused on T‑Bills and treasury management, which generally improves its reputation with conservative/institutional users. Regulatory & compliance reputation
  • Products USTBL/EUTBL are repeatedly described as money market funds regulated by the French AMF, and UCITS‑compliant.
  • A Tezos/Etherlink announcement notes Spiko is founded in 2023, operating tokenized MMFs and a France‑registered subsidiary providing investment advisory and brokerage services, reinforcing regulated status.
  • No references found to regulatory enforcement actions, license withdrawals, or sanctions lists. Not verifiable as of 2026‑09‑04. Ecosystem relationships & perceived quality
  • Collaborations cited with BNP Paribas (banking counterparty for yields), Société Générale–Forge, Morpho, Steakhouse Financial, Usual (EUR0), and deployment on Etherlink, Ethereum, Polygon, Base, Starknet, etc., which signals institutional and blue‑chip DeFi acceptance.
  • DeFiLlama and MrDeFi list Spiko as a major RWA protocol with multi‑chain TVL in the billions, suggesting market confidence. Audits, founders, and investors
  • Public web data mainly covers the company profile and products; detailed audit firm names, formal smart‑contract audit reports, founder bios, and venture investors are not prominently disclosed in the retrieved sources. Not verifiable as of 2026‑09‑04. Criticisms, risks, and unresolved concerns
  • The DeFi Bullshit Detector report flags that risk is primarily off‑chain (fund, bank, regulatory) rather than smart‑contract, and stresses that Spiko’s structure differs from permissionless DeFi, which may create jurisdictional and counterparty risk despite low underlying asset risk.
  • No credible allegations of fraud, rug‑pulls, insolvency, or regulatory scandals were identified in independent media or community discussions. Not verifiable as of 2026‑09‑04. Contradictions callout
  • On‑chain verification (TVL by chain, actual fund holdings, yield flows) cannot be performed in this run; any protocol claims about TVL, assets, or yields remain unverified marketing claims unless corroborated by independent analytics platforms.
Evidence (15)

Economy

TVL: $2.6B

model

two sources

Economic model (as of 2026-09-05). Spiko is a regulated, tokenized-fund issuer rather than a conventional DeFi yield strategy. Core products are USTBL (U.S. Treasury bills) and EUTBL (Euro-area Treasury bills); the 2026 prospectus also lists UKTBL and an Amundi overnight-swap fund.

Tokens represent registered fund shares, with allowlisted transfers and daily NAV publication. Assets/strategy/yield. USTBL invests in short-dated U.S. government instruments, generally with residual maturity ≤6 months, WAM ≤60 days, WAL ≤120 days, and minimum daily/7-day liquidity of 7.5%/15%. EUTBL follows the analogous euro-government-bill money-market strategy. Yield is therefore organic interest income from bills/repo/cash, not liquidity-mining emissions; no subsidy program was verified.

This is low-duration, market-neutral/cash-like exposure—not directional crypto, looping, restaking, or external DeFi leverage. The fund is prohibited from incurring debt; leverage is effectively 1.0x. Liquidity and terms. No stated lock-up. Orders use next-day NAV; the 11:30 a.m.

Paris cut-off applies, with redemptions processed on business days. Tokens are sent to the redemption mechanism and burned after processing. No redemption gates or suspension mechanism is provided, although large withdrawals could force asset sales at unfavorable prices.

Subscription/redemption fees are listed as none; investors pay blockchain transaction costs. USTBL’s stated minimum initial subscription is $1,000, subsequent subscription and redemption minimums $1; no maximum is stated. Fund costs include 0.30% management fee plus up to 0.10% operating expenses, with no performance fee. Revenue. DeFiLlama reports $496m TVL, annualized fees of $902k and annualized revenue of $338k; its methodology attributes 15% of yield to the protocol. TVL by chain (DeFiLlama; not Dune-verified): Arbitrum $217.07m (43.8%), Polygon $175.32m (35.3%), Ethereum $47.56m (9.6%), Starknet $35.04m (7.1%), Etherlink $11.35m (2.3%), Base $9.66m (1.9%); Stellar is not shown in this DeFiLlama snapshot.

Product-level TVL, chain trend history, and Dune-vs-DeFiLlama reconciliation: Not verifiable as of 2026-09-05. RWA.xyz separately reports $2.48B distributed asset value, indicating an unreconciled metric-scope contradiction, not necessarily an accounting error. APY history/volatility/sustainability: Not verifiable as of 2026-09-05. Expected sustainability is tied to prevailing short-term government yields minus fees; the prospectus warns returns can fall below costs in very low-rate conditions.

Leverage ratio
1
Evidence (4)

reserves

one source

Assessment (as of September 5, 2026): Spiko does not appear to operate a protocol-owned treasury or corporate reserve. The economic backing is held at regulated fund level, segregated from Spiko Finance’s balance sheet. CACEIS Bank is the SICAV depositary/custodian and CACEIS Fund Administration is the administrator; Twenty First Capital manages the funds, while PwC is statutory auditor. Size: Spiko’s public dashboard currently reports approximately $2.53B total AUM across products, but this is a protocol-provided AUM figure—not verified reserve assets and not directly convertible into USD reserves because products are denominated in EUR, USD, GBP and CHF.

The US T-Bills product page reports $169.42M in fund assets, updated March 3, 2026; the dashboard separately reports $170.29M. These are fund AUM figures, not Spiko treasury balances. Composition / policy: USTBL may invest up to 100% in USD-denominated bonds and money-market instruments issued by the U.S. government; EUTBL invests in Eurozone government issuers. The prospectus sets WAM ≤60 days, WAL ≤120 days, and minimum 1-day/7-day liquidity of 7.5%/15% of net assets.

Smart Cash is different: it holds a securities portfolio and uses total-return swaps, with BNP Paribas identified as banking counterparty for Spiko Euro. Custody and control: CACEIS is the primary depositary; BNY Mellon is identified as U.S. Treasury sub-custodian and JPMorgan as USD correspondent. Token contract/share-register addresses are published in the prospectus, but these are share-register contracts, not reserve wallets.

No segregated reserve-wallet addresses or complete custody-account addresses were identified. Attestations: PwC performs four annual audits for the named funds. I found no public, continuously updated reserve attestation reconciling token supply, fund NAV, assets and liabilities. On-chain balances via Dune: Not verifiable as of September 5, 2026. Liabilities: Token-holder redemption/NAV claims exist at fund level, but a consolidated liability figure was not publicly verified. Not verifiable as of September 5, 2026. Contradiction / limitation: Reported AUM is not equivalent to liquid reserves or Spiko corporate treasury; treating the dashboard AUM as protocol reserves would overstate reserve certainty.

Evidence (5)

tokenomics

one source

Spiko currently appears to have no live, tradable native token on the listed chains; most tokenomics details are therefore *Not verifiable as of 2026-09-03*. ### 1. Native token existence

  • Web search for “Spiko token”, “Spiko crypto”, “Spiko IO token”, and contract addresses on Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, Etherlink returns no credible evidence of a deployed Spiko governance/utility token or ticker on major explorers or analytics platforms.
  • No listings for a “Spiko” token or obvious ticker (e.g. SPIKO, SPK) on major DEX/aggregator pages (Uniswap, Sushi, Curve, 1inch, DefiLlama, CoinGecko, CoinMarketCap) could be matched to the protocol with contract certainty. Given the tooling constraints (no Dune, no direct explorer queries in this run) and the absence of independent confirmations, all token-level metrics are Not verifiable as of 2026-09-03:
  • Native token name/ticker and contract address: Not verifiable as of 2026-09-03.
  • Total vs circulating supply; market cap and FDV: Not verifiable as of 2026-09-03.
  • Token utility and governance role (fee token, voting, collateral, etc.): Not verifiable as of 2026-09-03.
  • Revenue share, buybacks, burns, staking rewards: Not verifiable as of 2026-09-03.
  • Emissions schedule; unlock schedule and whether unlocks occurred on-chain: Not verifiable as of 2026-09-03.
  • Allocations to team/investors/treasury/community: Not verifiable as of 2026-09-03.
  • Top-holder concentration and insider wallets: Not verifiable as of 2026-09-03.
  • Mint/blacklist/fee-switch functions and controllers: Not verifiable as of 2026-09-03. ### 2. DEX liquidity and listings
  • No independently confirmed pools or order books clearly tied to a Spiko native token on major DEXs across the specified chains.
  • Depth/liquidity metrics and primary trading venues for a Spiko token are therefore Not verifiable as of 2026-09-03. ### 3. Risk analyst takeaway
  • For institutional risk, treat Spiko as non-tokenized or pre‑token until a contract address and chain(s) are independently confirmed via explorers and at least one analytics platform.
  • Any token-related claims from Spiko’s own website, social channels, or marketing material should be classified as “unverified marketing claim” pending explorer/Dune confirmation.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Spiko, a Bitcoin drop below $10,000 is not directly assessable from the available sources because I could not verify, from non-protocol sources, any material Bitcoin exposure, collateral dependency, leverage loop, or chain-specific treasury composition across Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, or Etherlink. The safest stress conclusion is: direct BTC-price contagion is Not verifiable as of 2026-09-03. What can be said with confidence is limited to protocol identity: Spiko describes itself as a fintech for issuing, managing, distributing, and trading financial instruments, but that alone does not establish BTC sensitivity or loss channels.

The Bitcoin-price premise itself is a market stress scenario, not a protocol-specific fact. Independent commentary in the provided results shows some market voices discussing a possible BTC move to $10,000, but these are forecasts and not evidence of Spiko exposure. Risk assessment:

  • Direct NAV impact: Not verifiable as of 2026-09-03
  • Collateral liquidation risk: Not verifiable as of 2026-09-03
  • Oracle / pricing risk: Not verifiable as of 2026-09-03
  • Cross-chain exposure split: Not verifiable as of 2026-09-03 If you want an institutional-grade answer, the missing inputs are the protocol’s on-chain holdings, vault/account composition, and any BTC-linked collateral or derivatives positions. Without those, any claim about stress losses would be speculation rather than verified risk analysis.
Evidence (6)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg in Spiko’s largest collateral would mean the collateral value falls to 80% of its prior mark; the immediate loss severity therefore equals 20% of the exposure to that collateral. For a lending or vault position, the protocol impact depends on how much borrower debt is secured by Spiko shares, what loan-to-value/health-factor buffers exist, and whether liquidation can happen before or during the depeg; those parameters are not verifiable from the provided sources as of 2026-09-03. What is verifiable is that Spiko’s tokenized money-market funds are used on-chain and can be used as collateral in DeFi integrations, including a Morpho-based borrowing setup cited by third-party sources and Spiko’s own Web3 page.

Spiko also has multi-chain deployment, but the provided results do not give a reliable, up-to-date chain-by-chain collateral breakdown for this stress test, so the largest-collateral identification is not verifiable as of 2026-09-03. If you want the risk interpretation in plain terms: a 20% collateral depeg is material and would likely force liquidations for any position with less than ~25% equity buffer after accounting for fees, slippage, and oracle delay. However, the exact loss to users or to the protocol itself cannot be quantified from the available evidence alone.

Not verifiable as of 2026-09-03: total collateral outstanding, largest collateral by chain, liquidation thresholds, and protocol loss under a 20% depeg.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Spiko is a cross‑chain yield and structured product protocol; precise on‑chain exposures per counterparty are Not verifiable as of 2026‑09‑04. Below is a generic but Spiko‑aligned stress path: top off‑chain counterparty (e.g. CeFi lender, market‑maker, or RWAs issuer) becomes insolvent. ### 1. Expected loss path

  • Asset shortfall: Collateral or funds lent via Spiko strategies to that counterparty are not fully recoverable; users in affected vaults face a principal loss and lost yield.
  • NAV shock: The smart‑contract strategies that track portfolio value (vaults, tranches, note tokens) reprice their Net Asset Value downward once the loss is recognized.
  • Cross‑chain impact: If Spiko uses bridges or messaging (e.g. to coordinate yields across Ethereum, Arbitrum, Polygon, Base, Starknet, Etherlink, Stellar), any synthetic representation of the position on other chains must be marked down as well. ### 2. Who absorbs the loss?
  • End‑users in the affected product: Holders of that vault token or tranche bear first‑loss economically (lower redeemable amount per token).
  • Tranched products: If Spiko offers senior/junior tranches, the junior/equity tranche absorbs losses up to its buffer before seniors are hit.
  • Protocol treasury / insurance fund: If Spiko has a reserve or insurance module and terms allow, it may cover part of the shortfall; this is usually capped and discretionary. Any such coverage from protocol claims alone is an *unverified marketing claim* unless backed by audits or legal docs. ### 3. Compensation / recovery
  • On‑chain: Contracts typically do not auto‑compensate beyond their programmed rules (e.g. waterfall, reserve payout). Additional make‑whole payments, token airdrops, or fee rebates would require governance and off‑chain execution.
  • Off‑chain legal: Claims against the insolvent counterparty (bankruptcy, collateral enforcement) are slow and uncertain; recoveries, if any, may later be reflected as positive NAV adjustments. ### 4. Impact path through smart contracts
  • Valuation oracles / pricing modules update position value to near‑zero for the insolvent counterparty exposure, pushing vault NAV down.
  • Redemption logic: Users redeeming after the event receive the new, lower amount; there is no retroactive protection.
  • Bridged/synthetic tokens: If yield tokens exist on multiple chains, their backing on the "home" chain is impaired, forcing protocol to either depeg, disable minting/redemption, or rebase supply.
  • Liquidation modules: If any loans were secured by this exposure as collateral, they may become under‑collateralized, triggering liquidations or bad‑debt accounting. Because detailed product docs, legal structure, and counterparty list are Not verifiable as of 2026‑09‑04, the exact loss waterfall and compensation rights remain uncertain.
Evidence (1)

stress scenario - committed fraud by the DAO or owners

two sources

For Spiko, a claim of committed fraud by the DAO or owners is not verifiable as of 2026-09-03 based on the available sources. The strongest source in the set describes Spiko as a regulated tokenized money-market-fund platform and explicitly says it found no fraud signals in its research; however, that is an independent analysis, not raw on-chain proof, and the protocol’s own blog is only marketing-level support. I did not find a regulator, court action, audit finding, or credible investigative report in the provided results alleging that Spiko’s DAO or owners committed fraud.

The search results also do not establish a DAO-style governance structure for Spiko; several generic DAO fraud/gov-attack articles in the results are about other projects and are not evidence against Spiko. Accordingly, the appropriate stress-scenario assessment is: no verified evidence of committed fraud by the DAO or owners; Not verifiable as of 2026-09-03.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

Spiko’s primary yield source is not a DeFi incentive stream; for its regulated money-market products it is the yield on the underlying short-term government instruments or the bank swap arrangement, with fees deducted. The protocol’s own materials say Spiko Dollar receives a daily guaranteed yield via a Total Return Swap with BNP Paribas, while Spiko USTBL / EUTBL are exposed to short-term Treasury bills and related cash instruments. For a negative 30-day primary-yield stress scenario, the core risk is yield compression or turn-negative carry at the underlying asset level, not a liquidation-style failure.

The sources provided do not show a mechanism that can make the product’s yield source structurally negative in the way a leveraged funding-rate strategy can; instead, they indicate the yield comes from sovereign paper or a bank swap, both of which are generally designed to track market rates minus fees. However, there is an important stress implication: if market rates fall enough, or if swap/portfolio economics deteriorate after fees, the net yield can approach zero and may become negative after fees/costs. Spiko’s own site states yields are “net-of-fees” and “paid daily,” which means fee drag is always present; a sufficiently low underlying rate environment can therefore produce a negative net return even if the gross asset yield remains non-negative.

What is not verifiable as of 2026-09-03 from the provided sources is whether Spiko has any explicit backstop, subsidy, or reserve mechanism that would support holders through a prolonged negative-yield period across all listed chains. For chain scope, the provided material references products on Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, and Etherlink, but it does not provide verifiable chain-by-chain exposure or TVL split in the search results, so that breakdown is Not verifiable as of 2026-09-03.

Evidence (9)

Governance & Legal

governance

two sources

Итог (as of 2026-09-13): company-controlled, DAO не подтверждена. Публичного governance-токена, DAO, форума предложений, голосования или формального proposal process не найдено: Not verifiable as of 2026-09-13. Следовательно, dao_governance = false; governance выглядит символической/отсутствующей. Контроль. Spiko заявляет, что PermissionManager управляется Spiko; super-admin — Safe multisig, а ежедневные allowlisting, mint и burn выполняет внутренний relayer на базе Dfns. EVM-токены UUPS-upgradeable; privileged functions включают mint/burn и upgrade.

Starknet-контракты также предусматривают роли MINTER, BURNER, WHITELISTER и PAUSER. Это даёт компании существенный контроль над frontend/allowlist/выпуском/сжиганием/паузой и upgrade-путём. Админ-риск. Прямое перемещение underlying-клиентских средств администратором не подтверждено: Spiko указывает, что клиентские средства находятся у CACEIS, а не на балансе Spiko. Однако privileged burn, mint, pause/allowlist и upgrades создают риск конфискации/заморозки или изменения балансов токенов без DAO-голосования.

Точный ответ admin_can_drain для всех сетей: Not verifiable as of 2026-09-13. Timelock / multisig. Публично не раскрыты адрес Safe, threshold, число signers, состав и независимость владельцев; наличие Safe само по себе не подтверждает независимость. Отдельный mint maxDelay в коде не является governance timelock. Все поля — Not verifiable as of 2026-09-13. Voting concentration/top holders. Dune MCP недоступен в этом прогоне; on-chain проверка пропущена, поэтому top holders, voting concentration и ownership Safe: Not verifiable as of 2026-09-13.

Dune query/execution IDs отсутствуют. Компания и ToS. Контролирующая entity — Spiko Finance SAS, Франция, SIREN/RCS Paris 980 659 585; лицензия investment firm ACPR №19183. В публичных материалах указаны Paul‑Adrien Hyppolite (president/head of publication) и Antoine Michon (DG); Pappers также указывает supervisory board/management appointments. ToS подчиняются французской структуре договора; версия обновлена 30 июня 2026.

Есть адресное противоречие: ToS/legal notice указывают 16 rue des Immeubles Industriels, а актуальная страница компании/Pappers — 229 rue Saint‑Honoré, Paris.

Dao governance
No
Evidence (5)

legal & regulatory

two sources

Scope / identity (as of September 4, 2026). The matched entity is Spiko Finance SASU/SAS, French SIREN/RCS 980 659 585, registered in Paris; it is licensed as an investment firm by France’s ACPR (CIB 19183) and listed with ORIAS as an exclusive banking/payment-services intermediary (MOBSPL 23008251). Regulatory classification. Spiko Finance is principally the distributor/order-reception-and-transmission provider and DLT shareholder-register operator—not the portfolio manager. The Spiko SICAV prospectus identifies Twenty First Capital as AMF-authorized management company, CACEIS Bank as depositary/custodian, and Spiko Finance as distributor and register operator.

The on-chain representation is legally registered fund shares/securities, not crypto-assets; transfers are restricted to pre-approved allowlisted wallets. ToS, restrictions, KYC/AML. Access requires a validated account and ongoing KYC/AML-CFT checks, including identity, possible source-of-funds/income/wealth evidence, transaction monitoring, and customer-knowledge assessment. Accounts may be blocked for KYC/AML reasons or authority requests.

Nationality, residence, and registration must not fall within Spiko’s dynamically maintained excluded-country list. The SICAV prospectus requires investors to certify they are not “US Persons”; therefore U.S. access must not be assumed, even though the public ToS does not enumerate the full exclusion list. Warnings / actual risk. Documents warn that investments are not guaranteed and can lose value; Spiko generally assesses appropriateness, but may provide execution-only service for eligible non-complex UCITS.

Wallet/key loss, incorrect addresses, DLT/cybersecurity failures, token-settlement risk, fund liquidity/NAV risk, and counterparty/depositary/manager dependence remain material. Regulation of the entity and funds does not make the multi-chain interface permissionless or risk-free. Data protection. Spiko states it is GDPR data controller, retains core client data during the relationship and generally five years afterward for AML/legal purposes, uses EU-hosted AWS plus safeguarded non-EU transfers, and provides access/rectification/erasure/objection/portability rights with CNIL complaint access.

Warnings, enforcement, litigation, sanctions. No public regulator action, court case, or sanctions listing against Spiko Finance was identified in the reviewed official/registry searches. A definitive negative legal-record conclusion is Not verifiable as of September 4, 2026. Note: ORIAS shows an older CIF registration removed January 23, 2026; this is not itself an enforcement finding.

Active enforcement
No
Sanctioned
No
Entity
Spiko Finance SASU/SAS
Jurisdiction
France
Evidence (6)

legal registries

two sources

No exact GLEIF LEI record for 'Spiko Finance SASU', 'SAS', 'Spiko'. OFAC SDN screening of 'Spiko Finance SASU', 'SAS', 'Spiko': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Spiko Finance SASU
  • SAS
  • Spiko
Sanctioned
No
Evidence (4)

Stability

stability

unverified

Spiko does not appear to issue its own stablecoin; the web evidence shows Spiko accepts and uses third-party stablecoins such as USDC, EURC, DAI, USDT, EURCV, and USDCV for subscriptions, redemptions, or collateral. Because no Spiko-issued stablecoin is verifiable, any depeg history for a protocol-native stablecoin is not verifiable as of 2026-09-05. The structured fields are therefore: own_stablecoin=false, stable=null, depeg_count=null, max_depeg_pct=null, last_depeg_date=null, stablecoin_ids=["USDC","EURC","DAI","USDT","EURCV","USDCV"].

Own stablecoin
No
Stablecoin ids
  • USDC
  • EURC
  • DAI
  • USDT
  • EURCV
  • USDCV
Evidence (3)

Risks & Strengths

risks

two sources

Spiko is a permissioned, regulated tokenization layer for money-market funds rather than a fully decentralized yield protocol. The principal risks are concentrated in fund NAV/liquidity, privileged administration, smart-contract and oracle dependencies, wallet/DLT operations, and legal or counterparty enforceability. TVL and exposure by chain: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Underlying asset and NAV riskUSTBL/EUTBL represent fund shares, not guaranteed deposits. T-bill prices, rates, issuer exposure, currency effects, and variable NAV can reduce returns or principal; the fund may concentrate exposure under applicable rules.MediumMediumUCITS/MMF framework, regulated management, diversification and maturity limits, independent NAV calculation, and regulated custody.Medium
Redemption and liquidity riskRedemptions are centrally processed on business days and may be delayed by market closures, exceptional events, thin liquidity, or counterparty problems. Token liquidity is not equivalent to instant cash liquidity.HighMediumDaily redemption process, liquidity constraints, regulated fund governance, and designated custodian.Medium
Privileged administration and centralizationAllowlisting, minting, burning, transfers, and operational permissions depend on Spiko-controlled contracts, a Safe multisig, and an issuer-operated relayer. Compromise or error could freeze or misallocate assets.HighMediumPermissionManager, multisig administration, KYC/AML controls, and role separation.Medium
Smart-contract and oracle failureUpgradeable UUPS contracts, redemption logic, permissioning, and NAV/oracle dependencies create implementation, upgrade, key-management, and integration risk across multiple codebases.HighMediumPublished source code, external audits, upgradeable architecture, and monitored operational controls.Medium
DLT, wallet, and legal enforceabilityIncorrect wallet use, lost private keys, chain outages, smart-contract attacks, or regulatory/legal changes can interrupt issuance, transfer, or redemption and potentially cause partial or total loss.HighMediumPermissioned wallets and transfers, regulated French-law fund structure, KYC/AML, and chain-specific deployments.Medium
Evidence (5)

strengths

two sources

Spiko’s top strengths are: regulated institutional credibility, because it presents itself as a French/European fintech offering tokenized money market funds within a compliant framework; strong product-market fit in cash management, since it targets a well-established need for daily-yield, low-risk liquidity; 24/7 liquidity and transferability, because its tokenized shares are designed to be transferable outside traditional market cut-offs; programmatic and API/smart-contract integration, which makes the product easier to embed in treasury, fintech, and DeFi workflows; and transparent on-chain infrastructure, since Spiko emphasizes real-time visibility, auditable operations, and blockchain-based tokenization of fund shares.

Evidence (7)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 23 two independent sources, 9 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-30.