Lit office towers on the Rotterdam waterfront beside the Erasmus Bridge at blue hour.
Transparency

Numbers you can verify.

How to verify the reserves backing USDest, the bond positions held by sUSDest, and compliance with the guardrails.

Status:
Launching on Base
Reserve:
USDC + T-bills
Epoch:
30 days
Governance token:
None

USDest is backed 1:1 by USDC and T-bill reserves. sUSDest is not a stablecoin and carries bond credit risk.

Rotterdam at blue hour — illustrative.

Proof of reserves

Two layers, shown separately.

The USDest reserve: USDC balance, tokenized T-bill fund holdings, and total reserve value vs USDest supply on Base. The sUSDest assets: vault USDest, bond positions at carrying value, accrued coupon, both share prices, reserve floor vs actual, and per-issuer cap vs actual.

Pre-launch

Contracts are not yet deployed. Numbers appear here at launch.

Status
Launching on Base
Reserve
USDC + T-bills
Epoch
30 days
Governance token
None
Reserve composition
Not yet deployed
Vault composition vs caps
Not yet deployed
Redemption queue
Not yet deployed
Share prices
Not yet deployed

Bond positions

Every bond position at carrying value.

Bonds in the docs
Bond positions held by sUSDest: issuer, structure, identifiers, values, coupon, maturity, loan-to-value, share of vault and status
BondStructureISIN / TokenFace value heldCarrying valueCouponMaturityLTV% of vaultStatus
Not yet deployed — positions will be listed here at launch.

Holding structure

Onchain holder
BondPositionManager (ONCHAINID identity)
Legal holder
USD.estate Holding Subsidiary (Cayman Islands)
Contracts & multisigs
Contract addresses
Governance

Parameter register

Values below are the launch values set by governance. They are concrete, not illustrative, and can be changed only through the public timelock.

Parameter register: launch values, who can change each one, and whether it is timelocked
ParameterCurrent valueChanged byTimelock
RESERVE_FLOOR_BPSReserve floor2000 (20%)TimelockYes
ISSUER_CAP_BPSPer-issuer cap2000 (20%)TimelockYes
BOND_CAP_BPSPer-bond cap1000 (10%)TimelockYes
MAX_LTV_BPSMaximum LTV7000 (70%)TimelockYes
MAX_VALUATION_AGEMaximum valuation age12 monthsTimelockYes
MAX_TENORMaximum tenor5 years (60 months)TimelockYes
ALLOWLIST_DELAYAllowlist delay7 daysTimelockYes
MAX_SUBSCRIPTION_EXPIRYSubscription expiry14 daysTimelockYes
EPOCH_LENGTHEpoch length30 daysTimelockYes
EPOCH_CUTOFFEpoch cutoff48 hours before epoch closeTimelockYes
MIN_REDEEM_SHARESMinimum redemption1e18 (1 sUSDest)TimelockYes
USDC_BUFFER_BPSUSDC buffer500 (5%)TimelockYes
MAX_SWAP_SLIPPAGE_BPSMaximum swap slippage50 (0.5%)TimelockYes
IMPAIRMENT_DELAYImpairment delay604,800 s (7 calendar days ≈ 5 business days)TimelockYes
IMPAIRMENT_HAIRCUT_BPSImpairment haircut8000 (80%)TimelockYes
BASE_YIELD_ADMIN_FEE_BPSBase yield admin fee1000 (10%)TimelockYes
PERFORMANCE_FEE_BPSPerformance fee1000 (10%)TimelockYes
MINT_FEE_BPSMint fee0TimelockYes
REDEEM_FEE_BPSRedeem fee0TimelockYes
Timelock delay48 hoursTimelock (self)Yes
Mint/redeem limitsSet per institution at onboardingFoundation (compliance)No
Institutional mint/redeem allowlistn/aFoundation (compliance)No
Pausen/aPause guardianNo

Three controls deliberately sit outside the timelock, marked “No”: the institutional mint/redeem allowlist and per-institution limits (compliance actions that must be immediate — a sanctions hit cannot wait 48 hours) and the emergency pause (which can only stop activity, never move value or change an economic term). Everything that affects the economics of USDest or sUSDest is timelocked.

Every fee rate is bounded in code at 3000 bps; setters enforce range bounds (bps ≤ 10 000) but no cross-parameter checks, so an emergency change can never be blocked by an unrelated value.

Allocation guardrails

The limits the strategy multisig cannot cross.

The contracts check them on every allocation, and a transaction that would breach one reverts. Every change to a guardrail goes through the timelock, so depositors see it before it applies.

20%
Reserve floor
RESERVE_FLOOR_BPS
20%
Per-issuer cap
ISSUER_CAP_BPS
10%
Per-bond cap
BOND_CAP_BPS
7 days
Bond allowlist timelock
ALLOWLIST_DELAY
14 days
Subscription expiry
MAX_SUBSCRIPTION_EXPIRY
Audits & assurance

Audits and offchain assurance.

Smart contract audit reports from independent security firms, plus the offchain assurance behind USDest reserves and sUSDest bond positions.

Smart contract audits

Smart contract audits by scope
AuditorScopeCommitDateReport
Pending engagementUSDest, BasePositionManagerPending engagementPending engagementPlanned
Pending engagementsUSDest vault, redemption queuePending engagementPending engagementPlanned
Pending engagementBondPositionManager, Subscription Timelock, BondAllowlist, RiskParametersPending engagementPending engagementPlanned

Each report will be attached to the docs as a PDF with its findings summary and remediation status.

ERC-3643 bond token contracts (token, identity registry, compliance modules) are deployed and operated by each issuer's token agent and are audited under the issuer's own arrangements; they are not USD.estate contracts. USDC and tokenized T-bill fund contracts are third-party contracts.

Offchain assurance

This is not a smart-contract audit. It is independent assurance over the offchain facts the protocol depends on — reserve and position existence, and the legal structure holding them — and it is a fourth engagement alongside the three contract audits.

Offchain assurance engagements
AssuranceProviderFrequency
Proof of Reserves & Bonds (agreed-upon procedures)Pending engagementPer epoch
Legal opinion: Holding Subsidiary structure and title to bond positionsPending engagementOne-off, refreshed on change
Legal opinion: token classification in key jurisdictionsPending engagementOne-off

Latest attestation report

No attestation engagement has been signed yet. Until one is, reserve balances and bond positions can be verified directly onchain.

Snapshot date
— (first attestation pending)
Independent accountant
— (engagement pending)
Engagement
Agreed-upon procedures

Live bug bounty: to launch alongside mainnet deployment.

Contract addresses

Contract addresses

USD.estate deploys to Base. Contracts are not yet deployed; addresses are published at deployment.

Anti-phishing. Only interact with addresses listed on the Contract Addresses page of the docs. USD.estate will never ask you to send funds to an address announced anywhere else.

Base

Protocol contracts on Base and their addresses
ContractAddress
USDestNot yet deployed
sUSDestNot yet deployed
BasePositionManagerNot yet deployed
BondPositionManagerNot yet deployed
BondPositionManager ONCHAINIDNot yet deployed
Subscription TimelockNot yet deployed
BondAllowlistNot yet deployed
RiskParametersNot yet deployed
Timelock ControllerNot yet deployed

Multisigs & roles

Multisigs, their Safe addresses and signing thresholds
RoleSafe addressThreshold
Strategy multisigSTRATEGY_ADMIN_ROLENot yet deployed3-of-5
Credit agentCREDIT_AGENT_ROLENot yet deployed2-of-3
ComplianceMINT_ALLOWLIST_ROLENot yet deployed2-of-3
Pause guardianPAUSE_ADMIN_ROLENot yet deployed2-of-4
Timelock proposer (Foundation)Not yet deployed3-of-5

Pause-guardian signers are disjoint from the strategy multisig signers. Signer addresses are published at deployment; the thresholds are the launch values and change only through the timelock.

Referenced third-party assets

Referenced third-party assets
AssetRoleAddress
USDCReserve and settlement currencyCanonical USDC on Base (published at launch)
Tokenized T-bill fund tokenUSDest reservePublished at launch

Ready when you are.