Usual USD0

Green · 75/100

Executive summary

Usual USD0 is an over-collateralized stablecoin backed by short-duration U.S. Treasury bills and tokenized RWA, scoring 56/100 (orange band) with a -10 penalty for unresolved incident remediation.

  • Security: Multiple audits by Cantina, Paladin, Sherlock, and Halborn covering core contracts; most recent (0xSimao Nov 2025) found 3 low/info issues unfixed; Cantina Jan 2025 left 1 high unresolved (acknowledged); Paladin Oct 2024 confirmed deployed-code match on Arbitrum; $16M bug bounty active on Sherlock since April 2025.
  • Incidents: May 2025 arbitrage exploit caused ~$43k loss with remediation in progress (penalty applied); January 2025 USD0++ redemption-floor change (from $0.995 to $0.87) triggered depeg to $0.89 and market stress, resolved but user reimbursement not verified; USD0 itself has no verified depeg events.
  • Governance & custody: Hybrid governance with DAO voting (80% USUALx / 20% bUSD0) but legal control unclear; Usual Labs (Up Only Co, French SAS) operates frontend; collateral custodied at BNY Mellon (USYC) and CACEIS (USTBL); protocol claims ring-fenced, non-rehypothecated assets but independence from legal entity not verified.
  • Top risks: High admin/key risk—upgradeable proxies with DEFAULT_ADMIN controlling roles, pausing, minting, blacklisting, and emergency withdrawals; RWA counterparty concentration (Hashnote USYC 42.73% per stale June 2025 data); cross-chain bridge dependencies (Chainlink CCIP, LayerZero); oracle staleness or NAV mispricing could cause mis-minting; custodian/tokenizer failure could delay redemptions despite solvent Treasuries.
  • Strengths: 1:1 backing by short-duration Treasuries (max 0.33yr duration) reduces fractional-reserve risk; real-time on-chain reserve transparency; permissionless minting and broad DeFi composability; insurance fund (0.33–5.33% target) for collateral shocks; public, non-anonymous team (Pierre Person, ex-French MP) increases reputational accountability.
  • Unverified: Current reserve composition, chain-by-chain balances, and exact collateral addresses not verifiable (Dune unavailable); fix status for most Cantina/Halborn/Sherlock audits not disclosed; whether deployed code matches all audited commits unclear; exact proxy-admin setup (Safe vs EOA) and upgrade history not confirmed; May 2025 incident remediation completion not documented.
  • Recommended exposure: Conservative allocation only (≤2% portfolio) given unresolved high finding, incomplete incident remediation, and high admin privileges; require independent verification of current reserves, proxy-admin multisig, and May 2025 fix deployment before increasing; suitable for short-duration RWA exposure with active monitoring of collateral composition and DAO governance votes; avoid if counterparty/custody transparency is mandatory.
  • Open questions: Verify current collateral breakdown and Insurance Fund balance on-chain; confirm proxy-admin is a multisig (not EOA) and review upgrade history; obtain post-fix audit or incident postmortem for May 2025 exploit; clarify legal enforceability of DAO decisions vs Usual Labs control; check whether all critical/high findings from Cantina Phase 2 and Jan 2025 audits are now resolved; validate BNY Mellon custody attestation and redemption SLA in practice.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 7 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-25)
Incidents 20% 100 20.0 1 open incident(s), $43,000 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 1 0.2 TVL $89,241,030 = 1% of reference ($17,538,184,136)
Data confidence 85 7/7 critical categories; 13/51 verified facts; 51/51 fresh (180d)

Identification

protocol identification

one source

Usual USD0 is a stablecoin / CDP-style DeFi protocol that issues the USD0 stablecoin against collateral, operating mainly on Ethereum and Arbitrum. 1. Basic Identification

  • Name: Usual USD0 (often just Usual; USD0 is the native stablecoin).
  • Website: Usual labs / protocol site (exact URL not provided here to comply with instructions).
  • Docs: Hosted in a standard docs portal (e.g. docs subdomain) describing USD0, collateral vaults, and governance; this is protocol self-description and thus an *unverified marketing claim* unless cross-checked.
  • Category: Over‑collateralized stablecoin / lending/CDP protocol (similar design space to Maker‑style systems).
  • Launch date: Public launch is mentioned in blog and social posts in 2024; precise date is Not verifiable as of 2026‑09‑03 from independent sources.
  • Chains:
  • Ethereum mainnet – core contracts (USD0 token, vaults, governance).
  • Arbitrum – bridged / native USD0 and auxiliary contracts.
  • Native token(s):
  • USD0 – protocol stablecoin.
  • A separate governance / value-accrual token is referenced in materials, but name, ticker, and contract are Not verifiable as of 2026‑09‑03 from independent sources. 2. Main Contract Addresses & Verification Due to missing Dune MCP and limited independent explorer cross‑checks in search results:
  • Specific Ethereum USD0 token contract address, vault contracts, and Arbitrum contracts are Not verifiable as of 2026‑09‑03.
  • Explorer “verified” status (source-code verification on Etherscan/Arbiscan) for these contracts is likewise Not verifiable as of 2026‑09‑03. Because contract addresses cannot be independently confirmed and cross‑checked from ≥2 sources, no addresses are listed to avoid mis‑identification. 3. Fork Lineage & Code Provenance
  • Search results do not provide a clear statement that Usual USD0 is a fork of a specific upstream protocol (e.g., MakerDAO, Liquity, etc.). This is therefore Not verifiable as of 2026‑09‑03.
  • No independent source details what changed vs any upstream codebase, whether changes were audited, or any malicious‑modification history in related forks. All of these are Not verifiable as of 2026‑09‑03. 4. Evidence Gaps (Key for Risk Analysis)
  • No on‑chain verification (Dune disabled, no reliable contract discovery from independent sources).
  • Audit status (auditor name, scope, dates) and bug bounty presence are Not verifiable as of 2026‑09‑03.
  • Any specific TVL, supply, or protocol usage figures from Usual’s own materials are unverified marketing claims unless and until backed by independent analytics.
Evidence (2)

maturity

unverified

Usual USD0 appears to have a real product surface, not just a marketing landing page: its docs describe live smart-contract functionality, including permissionless minting/redemption via the dApp for bUSD0 and deposit/withdraw flows in the USD0 technical docs. The protocol also documents tracking USD0, USD0++, and USUAL on Arbitrum from the dApp, and its cross-chain support materials describe bridging USD0/USD0++ between Ethereum and Arbitrum. That said, several important maturity checks are not fully verifiable from the available web evidence: broken links, fake metrics, and template-site signs are Not verifiable as of 2026-09-03.

The same applies to whether the UI is consistently operational end-to-end for all deposit/withdraw paths right now, because the retrieved sources are documentation and announcements rather than a live runtime audit of the portal. Open API: Not verifiable as of 2026-09-03. The available materials show smart-contract interfaces and technical contract docs, but they do not clearly expose a public REST/GraphQL API for external use.

Overall: the project looks like a functioning protocol with a real dApp and documented user flows, but external proof of current UX quality and open API availability is incomplete from the available sources.

Evidence (5)

Security

bug bounty

one source

Usual appears to have an active bug bounty program on Sherlock covering the Core Stablecoin Protocol on Ethereum mainnet only, with severity tiers for Critical, High, and Medium findings. The program was announced on 2025-04-02 and documented on Usual’s tech docs on 2025-04-09. Critical issues are described as theft or irreversible loss of 5%–100% of TVL for core contracts only; High covers 1%–5% of TVL across the entire protocol; Medium covers individual-user loss or lockup.

The announced top payout is $16 million for critical vulnerabilities, with reports submitted via Sherlock. Usual’s later Fira UZR bounty is separate and out of scope for this question. No independently verified public disclosure of concrete bounty payouts, submissions, or resolved cases was found in the gathered sources.

Active
Yes
Platform
Sherlock
Max payout
$16.0M
Since
2025-04-02
Evidence (2)

counterparty risks

unverified

Assessment — as of September 5, 2026 > Contradiction / correction: The previously recorded description of USD0 as backed by ETH/LST yield and GMX hedges is not supported by the current documentation reviewed. Current materials describe USD0 as backed by short-duration U.S. Treasury exposure and repo/cash-management assets, primarily through Hashnote USYC, with additional collateral sources including M^0 and Spiko.

The earlier Lido, Ether.fi, and GMX dependency finding should be treated as superseded, not reused. Primary counterparties and dependencies:

  • RWA issuers/tokenizers: Hashnote/USYC is identified as the primary collateral source; M^0 and Spiko are additional sources. This creates issuer, fund-structure, NAV, redemption, legal-ring-fencing, and operational dependencies.
  • Custody/settlement: Reported custodians include BNY Mellon for USYC and CACEIS for USTBL; indirect minting also depends on USDC/Circle and collateral providers. A custodian, tokenizer, bank, or collateral-provider failure could delay or impair redemption even if Treasury assets remain solvent.
  • Oracles: USD0 uses a ClassicalOracle for collateral pricing and Chainlink infrastructure for pricing/proof-of-reserve integrations. Oracle staleness, incorrect NAV, governance/key compromise, or liquidity-disconnected pricing could cause mis-minting, mis-redemption, or peg stress.
  • Bridges: Ethereum is primary; Arbitrum transfers use Chainlink CCIP and LayerZero. Cross-chain message forgery, endpoint/configuration failure, replay, or pause risk can isolate or impair Arbitrum liquidity.
  • Market structure: Secondary liquidity relies on venues including Curve and Uniswap, while USDC/USDT are exit assets. A pool imbalance, stablecoin depeg, or collateral-provider withdrawal could produce temporary market discounts. Failure scenarios: Treasury/tokenizer insolvency or legal impairment; delayed redemptions; oracle failure; bridge exploit; USDC depeg; DEX liquidity shock; or governance/upgrade compromise. Protocol materials cite a 0.33%–5.33% insurance-fund target, but current funded amount and coverage are not independently verified. On-chain exposure: Not verifiable as of September 5, 2026. Dune MCP was unavailable; no exposure percentage is inferred. Fields: dependency_failure_active: null; max_exposure_pct: null.
Evidence (5)

crypto custody

one source

Usual USD0 appears to use institutional third-party custody for the collateral: Usual’s docs say USD0’s strategy uses reverse repos and U.S. government securities, with custody at BNY Mellon. The docs also say collateral is held in audited smart contracts, is not rehypothecated, and is isolated/ring-fenced from Usual’s balance sheet at the tokenizer level. However, the exact protocol-level custody flow on Arbitrum and Ethereum is not fully verifiable from the available sources, so the precise custody organization remains Not verifiable as of 2026-09-05.

Withdrawal status is also Not verifiable as of 2026-09-05; one third-party report from early 2025 said Usual introduced conditional and unconditional exit paths, but no current source here confirms whether withdrawals are paused now.

Segregated assets
Yes
Evidence (4)

incident

two sources

Usual also experienced a USD0 peg-stress episode in which USD0 briefly traded around $0.99 before recovering. The reporting attributed this to a single whale trader and said the protocol itself remained safe and did not suffer broader stress or deleveraging. No loss figure was reported, and from the available sources the affected users or reimbursement/fix details are Not verifiable as of 2026-08-25.

Date
2025-01-02
Cause
Liquidity issue
Evidence (2)

incident

one source

Ethereum incident on January 9–10, 2025: Usual changed USD0++ redemption terms, replacing the prior near-1:1 floor with a $0.87 unconditional floor that rises over four years, while retaining a conditional 1:1 exit with reward forfeiture. USD0++ fell to approximately $0.89; USD0 itself was not reported as depegged. Affected parties were USD0++ holders, Curve/Pendle liquidity providers, and leveraged integrations exposed to the former 1:1 assumption.

No realised protocol/user loss was quantified; no attacker was involved. Response included early activation of the Revenue Switch, 1:1 early unstaking with forfeited rewards, liquidity measures, and later product/liquidity redesigns. Reimbursement of mark-to-market losses: Not verifiable as of 2026-09-05.

The redemption redesign and subsequent liquidity transition are complete; status: resolved, although affected users were not documented as being made whole.

Date
2025-01-09
Cause
Liquidity issue
Status
resolved
Event id
usual-usd0-usd0pp-redemption-depeg-2025-01
Evidence (3)

incident

two sources

Usual USD0: Input Validation via Missing Input Validation on Ethereum; loss $43,000 (DeFiLlama hacks registry). Remediation status: remediation_in_progress (retained evidence).

Date
2025-05-27
Cause
Smart-contract exploit
Loss
$43K
Attacker proceeds
$43K
Status
remediation in progress
Recovered
$0
Reimbursed
No
Classification
Input Validation
Technique
Missing Input Validation
Event id
usual-usd0-usd0pp-sky-vault-arbitrage-2025-05-27
Evidence (3)

incident

two sources

Usual USD0 has had two notable incident categories since launch: a May 28, 2025 arbitrage/exploit on a USD0++ investment vault and a January 2025 USD0++ depegging/redemption-parameter change that affected market pricing and user expectations rather than the base USD0 peg. The May 2025 event was described by secondary reports as a series of unvetted transactions/arbitrage that prompted a pause of affected contracts, while Usual said no user funds were affected and the core protocol remained operational; reported loss was about $42,973–$43,000. The January 2025 event centered on USD0++ dropping to about $0.89 and then a surprise adjustment of the redemption floor from $0.995 to $0.87, which sparked backlash and downstream market/liquidation stress; no USD0 loss figure was reported.

Because the provided sources are mostly media writeups, the exact affected contracts, reimbursement status, and technical root cause beyond “arbitrage / redemption-mechanism change” are Not verifiable as of 2026-08-25.

Date
2025-05-28
Cause
Smart-contract exploit
Loss
$43K
Evidence (3)

key management

one source

Key management for Usual USD0 appears to be organized as a mix of on-chain role-based access control and community governance, rather than a single custodian key. The docs say collateral onboarding and risk parameters are governed by USUAL token governance, including adding/removing collateral types, setting exposure limits, and adjusting risk parameters. Usual’s risk policy also says portfolio actions are enforced through smart contracts and governed by the DAO, with on-chain monitoring, dynamic rebalancing via the Multi Collateral Controller, and an insurance fund for losses.

Evidence (2)

smart-contract

two sources

Assessment (as of September 5, 2026): High admin/key risk; not trust-minimized. Addresses / architecture: Ethereum USD0 0x73A15FeD60Bf67631dC6cd7Bc5B6e8da8190aCF5; Arbitrum USD0 0x35f1C5cB7Fb977E669fD244C567Da99d8a3a6850; Ethereum DaoCollateral 0xde6e1F680C4816446C8D515989E2358636A38b04; SwapperEngine 0xB969B0d14F7682bAF37ba7c364b351B830a812B2; RegistryAccess 0x0D374775E962c3608B8F0A4b8B10567DF739bb56; RegistryContract 0x0594cb5ca47eFE1Ff25C7B8B43E221683B4Db34c; ClassicalOracle 0xb97e163cE6A8296F36112b042891CFe1E23C35BF. Users → DaoCollateral / SwapperEngine → USD0 ↔ RWA collateral; RegistryAccess → roles → token, collateral, oracle, bridge contracts; multisig/admin → proxy upgrades + emergency controls. Usual documents a transparent-proxy, upgradeable architecture. Paladin explicitly identified Arbitrum L2Usd0 and L2Usd0PP proxies and their implementations.

The current Ethereum USD0 deployment is documented as upgradeable/pausable and role-controlled. Exact proxy-admin contract, whether it is a Safe/multisig or EOA, and decoded admin-change history: Not verifiable as of September 5, 2026 (Dune unavailable). Privileged powers: DEFAULT_ADMIN manages roles, registry/contract references, oracle initialization, CBR parameters, redeem fees, DAO redemption and emergency withdrawal for USD0pp. Pausing roles can halt token transfers, mint/swap/redeem pathways; USD0_MINT/BURN can mint or burn; BLACKLIST_ROLE can blacklist users.

The architecture therefore permits freezing, censorship, parameter/oracle abuse, and—through upgrades—arbitrary logic replacement. A compromised admin set could drain assets indirectly or make balances economically worthless; direct arbitrary USD0 treasury withdrawal is not established from the cited documentation. Users have documented permissionless mint/redeem routes, but admin-controlled pauses and fees mean there is no guaranteed admin-independent exit.

Usual claims a three-day delay for granting DEFAULT_ADMIN; an on-chain measured timelock delay is Not verifiable as of September 5, 2026. Role renunciation status is likewise not independently verified; docs state DEFAULT_ADMIN is not intended to be renounced. Paladin reports zero high-severity findings and two acknowledged governance findings; its audit covered Arbitrum 2024 deployments, not necessarily every current Ethereum implementation.

Admin can drain
Yes
Audited deployment
Yes
Upgradeable
Yes
Unresolved critical
0
Unresolved high
0
Evidence (6)

audit

two sources

Usual bUSD0 upgrade audit. Scope covered usual-dao/core-protocol with files including src/token/RTUsd0.sol, src/token/Usd0PP.sol, src/token/Usd0.sol, oracle and registry/access-control contracts.

Auditor
0xSimao
Report date
2025-11-11
Scope
Repository: usual-dao/core-protocol; audited commit 944105857d4af203c16137bca58f130472fd195e; final commit b72162e963cd0a5bb86c0c93d1f2a7bfb63ad6dd; files include RTUsd0, Usd0PP, Usd0, oracle, registry, token mapping, access control
Findings
3 total low/info findings; 0 critical, 0 high, 0 medium, 3 low/info.
Fix status
Issues not fixed and not acknowledged, per the report snippet.
Evidence (2)

audit

unverified

Newly verified published report: Blackthorn WrappedM review.

Auditor
Blackthorn
Report date
2024-12
Scope
WrappedM contracts.
Findings
0 critical; 0 high; 1 medium; 0 low; 3 informational.
Fix status
Not verifiable as of September 5, 2026; the published summary does not disclose remediation status.
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Cantina — May 2024 — Pegasus permissioned launch; scope: permissioned launch contracts / mint-to-swap migration; findings: Not verifiable as of September 4, 2026; fix status: Not verifiable as of September 4, 2026; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Cantina
Report date
2024-05
Scope
Permissioned launch contracts; mint-engine replacement
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Cantina — June 2024 — Pegasus public competition; scope: same launch-contract scope; findings/fix status: Not verifiable as of September 4, 2026; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Cantina
Report date
2024-06
Scope
Public competition on launch contracts
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Cantina — November 24, 2024 — Pegasus Phase 2; scope: V1 distribution/staking additions; findings: 0 critical, 1 high, 5 medium; fix status: report records fixes for cited issues, with some partial fixes; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Cantina
Report date
2024-11-24
Scope
V1 distribution, staking and related upgrades
Findings
0 critical; 1 high; 5 medium.
Fix status
Several findings marked fixed; at least one medium issue noted as only partially fixed.
Evidence (1)

audit

one source

Cantina — November 2024 — Pegasus Phase 1; scope: V1 upgrades including DAO Collateral, SwapperEngine and bUSD0; findings/fix status: Not verifiable as of September 4, 2026; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Cantina
Report date
2024-11
Scope
V1 upgrades; DAO Collateral; SwapperEngine; bUSD0
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

unverified

Newly verified published report: Cantina USD0++ Adjustments.

Auditor
Cantina
Report date
2024-12
Scope
USD0++ adjustment contracts.
Findings
0 critical; 0 high; 1 medium; 7 low; 7 informational.
Fix status
Medium, low and informational findings were unresolved according to the published summary.
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

unverified

Newly verified published report: Cantina Redirect & Fee Sweep.

Auditor
Cantina
Report date
2025-01
Scope
Redirect and fee-sweep logic.
Findings
0 critical; 1 high; 1 medium; 11 low; 4 informational.
Fix status
High acknowledged; medium fixed; 8 low fixed and 3 acknowledged; 3 informational fixed and 1 acknowledged.
Unresolved critical
0
Unresolved high
1
Evidence (1)

audit

one source

Corrected prior record: Paladin Usual USD0 audit. The report explicitly identifies Arbitrum proxy and implementation addresses and marks the live code as MATCH for assessed contracts.

Auditor
Paladin
Report date
2024-10-11
Scope
Usual USD0 contracts on Arbitrum: L2Usd0, L2Usd0PP, L1 OFT Adapter and OFT MintAndBurnAdapter.
Findings
2 governance; 1 low; 5 informational findings. No critical or high findings. The report summary records 8 findings total, with 6 resolved and 2 acknowledged.
Fix status
Six findings resolved; two acknowledged with no change made. Exact per-contract resolution is stated in the report.
Report url
https://paladinsec.co/assets/audits/20241011_Paladin_UsualUSD0_Final_Report.pdf
Report id
doc:8f75866c92331598
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Halborn — November 2024 — Usual V1 Audit; scope: V1 contracts including DAO Collateral, SwapperEngine and bUSD0; findings/fix status: Not verifiable as of September 4, 2026; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Halborn
Report date
2024-11
Scope
Usual V1 contracts
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Paladin — October 2024 — L2 Tokens Audit; scope: L2 token contracts and OFT adapters; findings/fix status: Not verifiable as of September 4, 2026; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Paladin
Report date
2024-10
Scope
L2 tokens; OFT MintAndBurnAdapter; L1 OFT Adapter
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

A Bytecode-match note is not verifiable from the provided sources. The available report explicitly covers Usual’s USD0 contracts on Arbitrum, but the extent to which the deployed bytecode matched the audited repository is not stated in the search results.

Auditor
Paladin
Report date
2026-08-25
Scope
Deployed USD0 code on Arbitrum versus audited code
Evidence (1)

audit

one source

Sherlock — November 2024 — Usual V1 public audit competition; scope: V1 protocol; findings/fix status: Not verifiable as of September 4, 2026; deployed-code coverage: Not verifiable as of September 4, 2026.

Auditor
Sherlock
Report date
2024-11
Scope
Usual V1 public competition
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

unverified

Newly verified published report: Sherlock Euler Oracle / Stability-Loan Hook.

Auditor
Sherlock
Report date
2025-02
Scope
Euler Oracle and Stability-Loan hook.
Findings
0 critical; 0 high; 1 medium; 0 low; 5 informational.
Fix status
All listed findings fixed according to the published summary.
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Usual also lists a private Sherlock collaborative review completed on 2025-06-03 covering the core protocol repository, including the token suite, mint and redeem flows, distribution machinery, and the roles that gate treasury and parameter changes. The public write-up says the detailed findings were not published individually.

Auditor
Sherlock / 0xSimao
Report date
2025-06-03
Scope
usual-dao/core-protocol repository: token suite, mint/redeem flows, distribution machinery, treasury/parameter roles
Evidence (2)

audit

one source

Usual also lists a private Sherlock upgrade audit completed on 2025-11-11 for the bUSD0 upgrade. The public summary says there were 2 low findings and lists them as issues in Usd0PP.sol::_deconstruct() and Usd0PP::mintWithPermit().

Auditor
Sherlock / 0xSimao
Report date
2025-11-11
Scope
bUSD0 upgrade: Usd0, Usd0PP, RTUsd0, oracle stack, token mapping and registry contracts
Evidence (2)

audit

one source

Publicly indexed Usual Pegasus Phase 1 report. The snippet says the team identified 10 issues and gives severity counts, but the exact contract list and bytecode-match confirmation are not fully available from the snippet alone.

Auditor
Spearbit / Cantina
Report date
2025-10-22
Scope
Usual Pegasus Phase 1; reviewed commit hash 747f595f (as referenced in the snippet).
Findings
0 critical, 0 high, 1 medium, 4 low, 2 gas optimizations, 3 informational.
Fix status
Not fully verifiable as of 2026-09-03 from the available snippet.
Evidence (1)

Team & Reputation

founders

two sources

Usual USD0 is run by a fully public, non-anonymous team, with a French core and visible prior careers in politics and traditional finance/tech; however, on‑chain and corporate registry checks are Not verifiable as of 2026-09-03. Founders & key team

  • Multiple independent sources name Pierre Person as founder/CEO of Usual.
  • A Binance research-style post notes he is a former French Member of Parliament for La République En Marche (Macron’s party), born in 1989.
  • Hugo Sallé is cited as COO and cofounder. A LinkedIn post referencing “Cofounder & COO @Usual | exCofounder @Pumpkin (acquired by CMA)” suggests prior entrepreneurial experience with an exit in traditional finance or fintech.
  • Manfred Tourron is listed as CTO. Public vs anonymous; reputation
  • Names, roles and biographical details are openly disclosed in third‑party articles and social media, indicating a non-anonymous founding team.
  • Prior role of Person as a national legislator suggests a high public-profile, reputationally exposed founder, which is atypical for anonymous DeFi teams and increases the cost of malfeasance from a reputational perspective.
  • Sallé’s prior cofounder role at Pumpkin (reported as acquired by CMA) indicates at least one previous startup outcome rather than a first-time founder profile. Jurisdiction, office, and business reality
  • Several sources state the team mainly comes from France, implying a European (likely French) operational base and suggesting an onshore team rather than an obviously offshore-only structure.
  • No independent confirmation of a registered legal entity, physical office address, or regulatory licenses was found in the retrieved data. Not verifiable as of 2026-09-03.
  • Protocol docs describe “Usual DAO” as issuer of bUSD0 and present Usual as a multi-chain DeFi/RWA platform, supporting the view that there is a real operating product suite (USD0, bUSD0, etc.), not just a static website. Hacks / prior controversies
  • Within the available data there is no mention of prior hacks or major failures tied to Person, Sallé, Tourron, or the Usual protocol. Not verifiable as of 2026-09-03. Reality check (risk analyst view)
  • Positives: named founders, prior public-office experience, previous startup exit, multi-chain deployed products.
  • Gaps: no on-chain verification here, no direct view of cap table, legal entity, regulatory status, or detailed team size and background beyond the three leads. Not verifiable as of 2026-09-03. Contradiction box
  • No direct contradictions between sources on team identity or roles were observed in the retrieved data as of 2026-09-03.
Evidence (7)

general reputation

two sources

Usual USD0 currently has a neutral-to-positive reputation, with growing institutional RWA positioning and no public fraud/rug/insolvency or sanctions allegations identified as of 2026‑09‑03. Founders, investors, team Public web data in the retrieved set focuses on the product and not the founding team or cap table; names of founders, key executives, and VC investors are not verifiable as of 2026‑09‑03. Protocol positioning & sentiment

  • USD0 is framed as a fully collateralized, RWA‑backed stablecoin (short‑term US Treasuries, repos, tokenized T‑bill products) and part of a “decentralized banking system” narrative. This is a classic *institutional RWA* positioning rather than retail meme/anon stablecoin.
  • It is deployed on Ethereum (primary) and Arbitrum, with multi‑chain expansion (Base, BNB) and integrations with Curve, Uniswap, Camelot, Stargate, Chainlink CCIP, and LayerZero, which generally signals ecosystem acceptance.
  • Third‑party descriptions (QRI report, price trackers, educational sites) treat USD0 as a standard RWA stablecoin and do not flag controversies. Audits and security reputation
  • The available docs emphasize architecture, mint/redeem flows, and institutional RWA providers (Hashnote, M0, Superstate).
  • However, independent smart‑contract/security audit reports and bug bounty program details are not surfaced in the retrieved set and are therefore not verifiable as of 2026‑09‑03. Criticisms and risk‑related commentary
  • Public materials and neutral explainers highlight the usual RWA trade‑offs (dependence on off‑chain issuers/custodians and regulatory exposure) but do not report specific scandals or losses tied to Usual USD0.
  • No credible reports of peg‑loss events, mass redemptions, or insolvency have been identified in the surfaced data; peg metrics around ~0.998–1.00 are shown in analytics. Legal, regulatory, sanctions
  • There are no visible references to enforcement actions, sanctions listings, or formal fraud accusations against the protocol or USD0 in the retrieved sources as of 2026‑09‑03.
  • As with all RWA stablecoins, the structure is implicitly exposed to US securities/commodities and payments regulation, but specific regulatory proceedings for Usual are not verifiable as of 2026‑09‑03. Unresolved concerns for an institutional risk view
  • Lack of easily verifiable information on audits, governance, and beneficial ownership is a material gap.
  • Heavy dependence on off‑chain Treasury/RWA providers introduces issuer, custodian, and regulatory risk, standard for this design but still non‑trivial.
  • Multi‑chain deployment (Ethereum, Arbitrum and others) means bridge and interoperability risk via CCIP/LayerZero/Stargate. Overall, reputation is cautiously positive but with typical RWA/bridging structural risks and incomplete public disclosure on audits and ownership.
Evidence (9)

Economy

TVL: $89.2M

model

one source

Strategy/assets in: USD0 is a fully collateralized, liquid-deposit stablecoin backed by Treasury bills and equivalent sovereign instruments, with a stated maximum redemption horizon of five business days. The documented design prohibits leverage at the collateral layer. Yield source / sustainability: Primary organic yield is T-bill/repo collateral yield; secondary revenue comes from mint/redeem fees, early-unstake penalties, and Fira lending fees (10 bps). However, historical revenue was materially penalty- and incentive-driven: DefiLlama attributes Q2 2025 gross revenue of $24.82m, including $17.4m from early-unstake penalties versus $4.06m RWA yield.

This makes historical APY/revenue less sustainable than the “real yield” framing suggests. Risk posture: Core USD0 collateral is carry-based and broadly market-neutral to crypto beta; no leverage, looping, restaking, or crypto-directional exposure is documented for USD0 itself. Treasury governance can create external exposure: documentation reports treasury allocations including ETH and yield strategies, but this is treasury risk rather than USD0 collateral risk. Lock-ups/withdrawals: USD0 is designed for redemption, subject to fees and liquidity timing. bUSD0/USD0++-type positions have early-unstake penalties and a primary-market floor; locked USUALx positions require fixed-duration commitments, with only locked positions receiving weekly USD0 revenue distributions. Fees/revenue: DefiLlama reports current 30-day fees of $400k and protocol revenue of $390k; stated revenue allocation is 30% to locked USUALx holders and 70% to the DAO treasury. Current tracked average supply APY is 10.27%, but APY history/volatility by product is not fully disclosed in the retrieved data. TVL: DefiLlama currently reports $90.38m, down 4.5% over 30 days, with 100% attributed to Ethereum.

Although USD0 contracts are documented on Arbitrum, chain-level Arbitrum TVL, product breakdown, and Dune-vs-DefiLlama reconciliation are Not verifiable as of September 5, 2026 because Dune MCP is unavailable. Contradiction: Protocol documentation presents multi-chain deployment and sustainable Treasury yield; current DefiLlama shows Ethereum-only TVL and historical revenue heavily dependent on early-unstake penalties. The latter is the stronger current analytics evidence. organic_yield_pct: null (not separable from emissions, pool incentives, and penalties). leverage_ratio: 1.0x (documented unlevered collateral design).

Leverage ratio
1
Evidence (4)

reserves

two sources

Assessment date: September 5, 2026. Dune/on-chain verification was unavailable; therefore current reserve balances, liabilities, wallet balances, and chain-by-chain backing are Not verifiable as of September 5, 2026. Composition and size. Usual’s latest fact sheet describes USD0 as backed 1:1 by short-duration U.S. Treasury bills and equivalent sovereign instruments, using multiple tokenizers: primarily Hashnote USYC, plus M^0/M and Spiko USTBL. The protocol claims a maximum portfolio-average duration of 0.33 years and an insurance fund target of 0.33%–5.33% of circulating USD0.

These are protocol disclosures, not independently verified reserve figures. A June 2025 protocol risk-policy snapshot listed USYC ($264.83m; 42.73%), eUSD0/Euler USL ($287.97m; 46.46%), and USUALM/wrapped M ($67.04m; 10.81%). This is stale data under the seven-day freshness rule and should not be treated as current composition. Addresses / custody. Official documentation identifies the Ethereum USD0 token as 0x73A15FeD60Bf67631dC6cd7Bc5B6e8da8190aCF5 and Arbitrum USD0 as 0x35f1C5cB7Fb977E669fD244C567Da99d8a3a6850.

The published Ethereum collateral treasury is 0xdd82875f0840AAD58a455A70B88eEd9F59ceC7c7; however, its current balances and whether it captures all USD0 collateral are Not verifiable as of September 5, 2026. Usual states that USYC assets are custodied by BNY Mellon, with Marex involved in repo operations and NAV Consulting/Cohen & Company providing administration/audit functions. LlamaRisk’s review reported that reserve attestations were not publicly available at that time; no current public attestation was located in this check. Not verifiable as of September 5, 2026. Control and policy. DAO governance is described as controlling collateral types, exposure limits, risk parameters, and treasury decisions.

Technical documentation assigns critical roles—including minting, pausing, blacklisting, collateral activation, and emergency functions—to a “Usual Multisig”; the exact signers, threshold, timelock status, and reserve-wallet controls were not independently verified here. Contradiction / finding: protocol materials claim real-time, fully collateralized reserve transparency, but current reserve amounts, attestations, and custody-wallet balances could not be independently verified. The claim remains an unverified marketing claim. Current analytics show approximately $548.62m on Ethereum, $65,484 on Arbitrum, and $1.78m labeled “Usual Treasury,” but these are aggregator figures—not reserve attestations or Dune-verified backing.

Evidence (5)

tokenomics

one source

Usual USD0 currently appears to have no live, tradable native token on Ethereum or Arbitrum; most tokenomics elements requested are therefore Not verifiable as of 2026‑09‑03. ### 1. Native token, contracts, supply, market cap

  • Searches for “Usual USD0 token”, “usual-usd0”, and contract addresses on Ethereum/Arbitrum return no confirmed ERC‑20 token associated with the protocol, only references to USD0 as a *stable asset* notionally used in Usual’s design.
  • No listings on major aggregators (CoinGecko, CoinMarketCap, DeFiLlama) for “Usual USD0” or “USD0” tied to this protocol are found.
  • Therefore: name/ticker, contract address, total/circulating supply, market cap, FDV → Not verifiable as of 2026‑09‑03. ### 2. Token utility, governance, revenue share
  • Public materials describing Usual refer to a stablecoin‑like USD0 concept within a broader “Usual” ecosystem, but do not present concrete tokenomics, governance token, or revenue‑sharing mechanics tied to a deployed smart contract.
  • No governance forums, Snapshot spaces, or on‑chain voting contracts specific to a “Usual” token are found.
  • Governance role, revenue share, buybacks, burns, staking rewards → Not verifiable as of 2026‑09‑03. ### 3. Emissions, unlocks, allocations
  • No vesting schedules, TGE announcements, or investor/team allocation tables from independent sources (audits, investor decks, regulator filings) are available.
  • Without confirmed token contracts, emissions schedule, unlock schedule, and whether unlocks occurred on‑chain; allocations to team/investors/treasury/community → Not verifiable as of 2026‑09‑03. ### 4. Holder concentration, control functions
  • Explorers do not show a verified ERC‑20 “Usual” or “USD0” token contract tied to this protocol, so:
  • Top-holder concentration and insider wallets → Not verifiable as of 2026‑09‑03.
  • Mint/blacklist/fee‑switch functions and controllers → Not verifiable as of 2026‑09‑03. ### 5. DEX liquidity and listings
  • No significant pools for “USD0” or “Usual” tied to this protocol are visible on major DEXs/aggregators on Ethereum or Arbitrum.
  • DEX liquidity depth and main listings → Not verifiable as of 2026‑09‑03. From a risk perspective, treat Usual USD0 as pre‑token or undisclosed‑tokenomics: any future token launch would require fresh analysis of contract powers (mint/burn/blacklist), governance, unlocks, and holder concentration before institutional exposure.
Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 is a *tail-risk* macro shock, not a base case, and the main implication for Usual USD0 would be indirect: stress would likely come through collateral markets, risk-off deleveraging, and any BTC-linked reserves or hedges rather than through a direct BTC-native mechanism. The web results provided do not contain protocol-specific evidence for Usual USD0’s Arbitrum/Ethereum exposures, reserve composition, liquidation thresholds, or stress-loss behavior, so those protocol-level impacts are Not verifiable as of 2026-09-03. What can be said from the sources is that multiple market commentators frame $10,000 BTC as requiring an extreme confluence of shocks such as global recession, liquidity contraction, ETF outflows, forced deleveraging, and broader risk-asset selloffs.

In that kind of environment, a protocol like USD0 would be exposed to secondary effects: lower collateral valuations, potential de-risking from counterparties, and tighter market liquidity. However, the exact effect on USD0’s peg stability, backing, or user positions cannot be determined from the supplied sources, so the correct answer is Not verifiable as of 2026-09-03. If you want, I can next produce a protocol-specific stress memo once you provide reserve docs, audit materials, or on-chain data access for Usual USD0.

Evidence (4)

stress scenario - largest collateral depegs 20%,

one source

Not verifiable as of 2026-09-03. The provided search results do not identify Usual USD0’s live collateral composition or chain-specific exposure on Arbitrum and Ethereum, so a 20% depeg stress on the largest collateral cannot be quantified reliably from the available sources. The only directly relevant material in the results is a third-party simulation discussing a 20% depeg scenario for wstETH in Compound V3’s Ethereum WETH market, which is a different protocol and market, so it cannot be used to estimate Usual USD0’s losses or liquidation impact.

A protocol-specific stress answer would require verified on-chain collateral balances, user positions, and LTV/liquidation thresholds for each chain; those are not available here.

Evidence (1)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Usual USD0 is an over‑collateralised stablecoin backed by tokenised US Treasuries (Usual Yield tokens); the key counterparty is the off‑chain issuer/custodian of these tokenised T‑bill positions. Below is a stylised stress scenario where this top counterparty (custodian/issuer of underlying T‑bills) becomes insolvent. On‑chain data is Not verifiable as of 2026‑09‑04. ### 1.

Loss path

  • Primary loss: off‑chain assets (USTs) backing Usual Yield tokens are frozen or enter bankruptcy; tokenised positions may become illiquid or worthless if claims on the underlying are not honoured.
  • On‑chain effect: Usual USD0 collateral baskets holding Usual Yield tokens experience a sharp drop in market value or complete write‑off; price oracles reflect this via de‑pegging of the collateral tokens.
  • Stablecoin backing impact: USD0 becomes under‑collateralised relative to its target (usually 1 USD), as NAV of backing assets falls below outstanding supply. ### 2. Who absorbs the loss
  • Immediate economic loss: borne by USD0 holders — they now hold a token redeemable against an impaired pool of tokenised T‑bills; redemptions (if still possible) return reduced value.
  • Equity / protocol stakeholders: if there is a junior/first‑loss tranche (protocol treasury, insurance fund, or governance token stakers), they absorb losses up to their cushion before USD0 holders are hit. This structure is Not verifiable as of 2026‑09‑04.
  • Custodian’s estate: in theory, bankruptcy courts may later distribute residual value to token holders, but timing and recovery are uncertain and off‑chain. ### 3. Smart‑contract impact path
  • Oracle update → collateral revaluation: price feeds mark down Usual Yield collateral; USD0 collateralisation ratio falls.
  • Automatic safeguards (if implemented):
  • Minting of new USD0 is paused when collateral ratio/oracle conditions breach thresholds.
  • Redemptions may be throttled or switched to pro‑rata claims on the impaired collateral basket.
  • Liquidation mechanisms (if any) try to sell remaining healthy collateral for stable assets; efficacy depends on liquidity on Arbitrum/Ethereum.
  • DeFi integrations: protocols holding USD0 (lending markets, LP pools) mark‑to‑market; positions using USD0 as collateral are liquidated, spreading losses to levered users and LPs. ### 4. Compensation
  • Insurance / reserve funds: if protocol holds dedicated reserves or has third‑party insurance, these would pay out first; presence and size Not verifiable as of 2026‑09‑04.
  • Legal claims: ultimate recovery depends on off‑chain legal process against the insolvent custodian; not enforced by smart contracts. Net: in a top‑counterparty insolvency, USD0 holders and integrated DeFi users are primary shock absorbers; smart contracts mainly enforce pause/withdrawal/liquidation rules, but do not themselves provide full compensation.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For the stress scenario “committed fraud by the DAO or owners”, Usual USD0 has at least one *credible historical governance-risk precedent* in the broader Arbitrum ecosystem: the Arbitrum Foundation’s 2023 transfer of about 750 million ARB from the DAO treasury without a token-holder vote was widely reported as a governance bypass, although the funds were later returned and no funds were permanently lost. That makes a DAO/owner fraud-style scenario *plausible as a governance-risk category*, but it does not by itself prove that Usual USD0’s DAO or owners have committed fraud. What is verifiable from the available sources is that Arbitrum governance has already faced serious integrity concerns, including vote-buying and emergency interventions that show governance power can be contested or concentrated.

However, I found no source in the provided results that directly alleges or proves Usual USD0 DAO/owner fraud on Ethereum or Arbitrum. So the correct risk assessment is:

  • Risk type: governance/owner misappropriation, unauthorized treasury movement, or deceptive allocation of protocol-controlled assets.
  • Evidence level for Usual USD0 specifically: Not verifiable as of 2026-09-03.
  • Ecosystem signal: Arbitrum has demonstrated governance weaknesses that could amplify this risk. If you want, I can next assess the related stress cases for Usual USD0: *admin key compromise, hidden mint/burn authority, or treasury seizure*.
Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For Usual USD0, the primary yield source is cash-and-cash-equivalent yield from short-term T-bills / RWA collateral, not a DeFi farming leg. In the published risk policy, Usual says duration is tightly limited (maximum portfolio weighted-average duration ≤ 0.33 years) and that rate shocks mainly affect collateral mark-to-market rather than creating a large income drawdown. Under a negative 30-day stress on the primary yield source, the relevant implication is a lower collateral yield contribution over that month, which can compress the reserve’s income buffer.

Usual’s own docs do not provide a quantified 30-day negative-yield scenario or a direct estimate of the effect on USD0’s yield stream, so the exact impact is Not verifiable as of 2026-09-03. What can be said from the docs is that Usual’s stated defense is to absorb short-term collateral-value shocks with the Insurance Fund and, if needed, use corrective actions such as burning Insurance Fund reserves, pausing minting, or routing new issuance through secondary markets. The docs also indicate the protocol is designed around rate-risk scenarios, but those examples are framed as positive rate shocks to collateral value; they do not establish how a negative 30-day yield shock would flow through to holder APY.

There is also a broader caveat: because USD0’s yield depends on the performance of its RWA/T-bill collateral stack, a negative yield month would likely reduce distributable returns first, while peg integrity would depend on whether the collateral value and Insurance Fund remain sufficient. The precise outcome for holders on Arbitrum vs. Ethereum is Not verifiable as of 2026-09-03 from the provided sources alone.

Evidence (4)

Governance & Legal

governance

two sources

As of September 13, 2026. Governance appears hybrid and is not proven fully autonomous. Usual’s documentation claims the DAO governs parameters, collateral onboarding, treasury/revenue policy, and upgrades through transparent proxies; it describes an 80% USUALx / 20% bUSD0 voting split and a UIP lifecycle of submission, discussion, voting, and execution. These are protocol claims, not on-chain-verified control evidence. Control and powers. The frontend is operated through usual.money/app.usual.money.

Legal terms identify Usual Labs as Up Only Co, a French SAS at 1 rue de Stockholm, Paris, SIREN 919 540 427; terms state token voting does not confer ownership or formal rights in Up Only Co/ADDU. Public company data lists Pierre Person as president and HSC Ventures as director general. The French association ADDU is described as holding or organizing protocol-related IP/assets and acting on DAO mandate, while not formally controlling the protocol. DAO reality. The DAO is operationally meaningful through Snapshot proposals, but independence is unresolved: legal execution, frontend development, and contract-role authority are not independently verified.

The documentation also says the DAO has emergency authority, including a Counter Bank Run Mechanism. Contradiction / risk finding. Marketing and governance documents say the DAO is the single authority and can upgrade contracts, while the Terms disclaim token-holder ownership/formal control over the legal entities. The gap is material: DAO control is asserted but not demonstrated at the contract-admin and execution layer. On-chain checks. Voting concentration, top holders, proxy admins, timelock, multisig signers/threshold, signer independence, and whether any admin can move user funds: Not verifiable as of September 13, 2026. Dune MCP was unavailable; no on-chain substitute was used.

Therefore the DAO is classified false under the requested strict test: actual token-holder control over parameters and upgrades is not verified.

Dao governance
No
Evidence (5)

legal & regulatory

one source

Usual USD0 is an over‑collateralized stablecoin of the Usual protocol, live on Ethereum and Arbitrum; it is not a centralized issuer like USDC, and most legal aspects relate to the Usual Labs entity rather than the token itself. Entity & jurisdiction Web disclosures and project materials identify Usual Labs (often styled just “Usual”) as the core developer/issuer of the protocol; however, there is no clearly verifiable corporate registry record or formal legal-entity description tied to USD0 in independent sources. Given the lack of confirmed filings or regulator references: entity and jurisdiction are Not verifiable as of 2026‑09‑03. Terms of Service / user restrictions The protocol site and app include typical DeFi disclaimers (no guarantees, use at own risk) and geographic restrictions referencing the U.S. and other high‑risk jurisdictions, but these statements are only visible in Usual’s own materials and therefore count as unverified marketing claims. No independently archived ToS or enforceable user agreement has been located: Not verifiable as of 2026‑09‑03. KYC / AML Usual USD0 operates as a non‑custodial, smart‑contract stablecoin; publicly accessible documentation and app interfaces indicate no wallet‑level KYC for basic mint/redeem and DeFi use, consistent with typical Ethereum/Arbitrum DeFi.

There is no independent evidence of integrated AML transaction monitoring or screening beyond any default RPC / front‑end provider measures: Not verifiable as of 2026‑09‑03. Regulatory classification Independent analysis sites and media describe USD0 as a crypto‑asset/stablecoin within DeFi rather than a regulated bank deposit or e‑money. No formal classification (e.g., by SEC, CFTC, ESMA, MAS) has been found: Not verifiable as of 2026‑09‑03. Warnings, enforcement, court cases, sanctions Searches of regulator communications, enforcement databases, and sanctions lists show no specific warnings, enforcement actions, or sanctions naming Usual, Usual Labs, or USD0. Accordingly:

  • active_enforcement: false (as of 2026‑09‑03) — no identified action directly against the protocol or its core entity.
  • sanctioned: false (as of 2026‑09‑03) — the protocol/entity itself is not listed; note this does *not* address whether it blocks sanctioned wallets. Data protection / privacy There is no independently verifiable privacy policy or data‑processing description beyond standard web analytics and wallet‑connection behavior on the app front‑end: Not verifiable as of 2026‑09‑03. Legal structure vs actual risk Given the absence of clear, independently verified corporate structure, regulator filings, or formal risk disclosures, users face typical DeFi legal risk: reliance on code, governance processes, and market liquidity rather than enforceable claims on an identifiable legal issuer.
Sanctioned
No
Evidence (2)

Stability

stability

one source

USD0 is Usual’s own stablecoin, and the retrieved web evidence supports that it is intended to stay at par via redemption into underlying Treasury collateral. The available sources do not verify any depeg event for USD0 itself; the depeg reporting in the retrieved material concerns USD0++/bUSD0, not USD0. Therefore the number of verified USD0 depeg events, the last depeg date, and the maximum depeg percentage are not verifiable as of 2026-09-05.

Own stablecoin
Yes
Stablecoin ids
  • USD0
Evidence (4)

Risks & Strengths

risks

two sources

USD0’s principal risks are concentrated in the RWA collateral stack, redemption mechanics, privileged administration, cross-chain infrastructure, and legal enforceability. Protocol-documented controls reduce—but do not eliminate—these risks; current Ethereum/Arbitrum balances, collateral composition, and exposure shares are Not verifiable as of September 5, 2026 because Dune on-chain verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Collateral issuer and custodyFailure, freeze, misvaluation, or legal impairment at a tokenizer, custodian, or underlying fund could reduce recoverable collateral and weaken USD0’s backing. Concentration in a primary provider can amplify contagion.HighMediumProtocol documents multiple tokenizers, regulated custodians, short-duration sovereign assets, independent audits, collateral eligibility rules, and an Insurance Fund. These are protocol-reported controls, not independently verified here.Material third-party, custody, settlement, and disclosure risk remains.
Redemption liquidity and depegPrimary redemption may depend on RWA settlement windows of up to five business days; during stress, DEX liquidity or arbitrage may be insufficient, causing USD0 to trade below par.HighMediumDirect redemption, secondary-market venues, collateral-provider matching, redemption fees, and an Insurance Fund are documented.Run risk, market-depth risk, and redemption gating/friction remain.
Privileged governance controlAdmin or role compromise could enable minting, burning, pausing, or blacklisting, directly impairing balances and transferability. Paladin specifically acknowledged governance-privilege findings.HighMediumRole separation, pausing, blacklist controls, and a stated multisig-admin design are documented; Paladin’s governance findings remained acknowledged rather than resolved.Key-management, insider, governance, and emergency-action risk remains high-impact.
Cross-chain and contract failureLayerZero adapters, upgradeable token contracts, message routing, or chain-specific deployments can fail or desynchronize supply, potentially trapping or duplicating value.HighMediumSeparate L1/L2 adapters, rate limits, pause controls, audits, and audited Arbitrum bridge-related contracts are documented.Bridge, upgrade, implementation-drift, and unsupported-chain risk remains.
Regulatory and legal enforceabilityTokenized Treasury claims may not provide holders with direct, bankruptcy-remote rights to securities; regulatory, sanctions, AML, or jurisdictional changes could restrict access or redemption.HighMediumThe protocol cites regulated tokenizers, custodians, compliance processes, and permissioned collateral providers.Legal-title, insolvency, jurisdiction, and policy risk is not eliminated.
Evidence (3)

strengths

two sources

Usual USD0’s top strengths are: (1) full collateralization by short-duration real-world assets—USD0 is designed to be backed 1:1 by tokenized U.S. Treasury bills and overnight repos, which reduces fractional-reserve and bank-counterparty risk; (2) real-time reserve transparency—the docs emphasize that backing can be audited on-chain rather than relying only on periodic attestations; (3) permissionless minting and broad DeFi composability—USD0 is presented as easy to mint and integrate for trading, lending, and collateral use across DeFi; (4) community-aligned value capture—Usual says protocol value is redistributed to the community through the USUAL token rather than retained entirely by the issuer; and (5) institutional-grade RWA access with reduced banking exposure—the protocol frames USD0 as a way to access treasury-backed yield without traditional bank-deposit risk or fractional reserve exposure.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 17 two independent sources, 26 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-25.