
Numbers you can verify.
How to verify the reserves backing USDest, the bond positions held by sUSDest, and compliance with the guardrails.
- Status:
- Launching on Base
- Reserve:
- USDC + T-bills
- Epoch:
- 30 days
- Governance token:
- None
USDest is backed 1:1 by USDC and T-bill reserves. sUSDest is not a stablecoin and carries bond credit risk.
Rotterdam at blue hour — illustrative.
Two layers, shown separately.
The USDest reserve: USDC balance, tokenized T-bill fund holdings, and total reserve value vs USDest supply on Base. The sUSDest assets: vault USDest, bond positions at carrying value, accrued coupon, both share prices, reserve floor vs actual, and per-issuer cap vs actual.
Contracts are not yet deployed. Numbers appear here at launch.
- Status
- Launching on Base
- Reserve
- USDC + T-bills
- Epoch
- 30 days
- Governance token
- None
- Reserve composition
- Not yet deployed
- Vault composition vs caps
- Not yet deployed
- Redemption queue
- Not yet deployed
- Share prices
- Not yet deployed
Bond positions
Every bond position at carrying value.
| Bond | Structure | ISIN / Token | Face value held | Carrying value | Coupon | Maturity | LTV | % of vault | Status |
|---|---|---|---|---|---|---|---|---|---|
| Not yet deployed — positions will be listed here at launch. | |||||||||
Holding structure
- Onchain holder
- BondPositionManager (ONCHAINID identity)
- Legal holder
- USD.estate Holding Subsidiary (Cayman Islands)
- Contracts & multisigs
- Contract addresses
Parameter register
Values below are the launch values set by governance. They are concrete, not illustrative, and can be changed only through the public timelock.
| Parameter | Current value | Changed by | Timelock |
|---|---|---|---|
RESERVE_FLOOR_BPSReserve floor | 2000 (20%) | Timelock | Yes |
ISSUER_CAP_BPSPer-issuer cap | 2000 (20%) | Timelock | Yes |
BOND_CAP_BPSPer-bond cap | 1000 (10%) | Timelock | Yes |
MAX_LTV_BPSMaximum LTV | 7000 (70%) | Timelock | Yes |
MAX_VALUATION_AGEMaximum valuation age | 12 months | Timelock | Yes |
MAX_TENORMaximum tenor | 5 years (60 months) | Timelock | Yes |
ALLOWLIST_DELAYAllowlist delay | 7 days | Timelock | Yes |
MAX_SUBSCRIPTION_EXPIRYSubscription expiry | 14 days | Timelock | Yes |
EPOCH_LENGTHEpoch length | 30 days | Timelock | Yes |
EPOCH_CUTOFFEpoch cutoff | 48 hours before epoch close | Timelock | Yes |
MIN_REDEEM_SHARESMinimum redemption | 1e18 (1 sUSDest) | Timelock | Yes |
USDC_BUFFER_BPSUSDC buffer | 500 (5%) | Timelock | Yes |
MAX_SWAP_SLIPPAGE_BPSMaximum swap slippage | 50 (0.5%) | Timelock | Yes |
IMPAIRMENT_DELAYImpairment delay | 604,800 s (7 calendar days ≈ 5 business days) | Timelock | Yes |
IMPAIRMENT_HAIRCUT_BPSImpairment haircut | 8000 (80%) | Timelock | Yes |
BASE_YIELD_ADMIN_FEE_BPSBase yield admin fee | 1000 (10%) | Timelock | Yes |
PERFORMANCE_FEE_BPSPerformance fee | 1000 (10%) | Timelock | Yes |
MINT_FEE_BPSMint fee | 0 | Timelock | Yes |
REDEEM_FEE_BPSRedeem fee | 0 | Timelock | Yes |
| Timelock delay | 48 hours | Timelock (self) | Yes |
| Mint/redeem limits | Set per institution at onboarding | Foundation (compliance) | No |
| Institutional mint/redeem allowlist | n/a | Foundation (compliance) | No |
| Pause | n/a | Pause guardian | No |
Three controls deliberately sit outside the timelock, marked “No”: the institutional mint/redeem allowlist and per-institution limits (compliance actions that must be immediate — a sanctions hit cannot wait 48 hours) and the emergency pause (which can only stop activity, never move value or change an economic term). Everything that affects the economics of USDest or sUSDest is timelocked.
Every fee rate is bounded in code at 3000 bps; setters enforce range bounds (bps ≤ 10 000) but no cross-parameter checks, so an emergency change can never be blocked by an unrelated value.
The limits the strategy multisig cannot cross.
The contracts check them on every allocation, and a transaction that would breach one reverts. Every change to a guardrail goes through the timelock, so depositors see it before it applies.
- 20%
- Reserve floor
- 20%
- Per-issuer cap
- 10%
- Per-bond cap
- 7 days
- Bond allowlist timelock
- 14 days
- Subscription expiry
RESERVE_FLOOR_BPSISSUER_CAP_BPSBOND_CAP_BPSALLOWLIST_DELAYMAX_SUBSCRIPTION_EXPIRYAudits and offchain assurance.
Smart contract audit reports from independent security firms, plus the offchain assurance behind USDest reserves and sUSDest bond positions.
Smart contract audits
| Auditor | Scope | Commit | Date | Report |
|---|---|---|---|---|
| Pending engagement | USDest, BasePositionManager | Pending engagement | Pending engagement | Planned |
| Pending engagement | sUSDest vault, redemption queue | Pending engagement | Pending engagement | Planned |
| Pending engagement | BondPositionManager, Subscription Timelock, BondAllowlist, RiskParameters | Pending engagement | Pending engagement | Planned |
Each report will be attached to the docs as a PDF with its findings summary and remediation status.
ERC-3643 bond token contracts (token, identity registry, compliance modules) are deployed and operated by each issuer's token agent and are audited under the issuer's own arrangements; they are not USD.estate contracts. USDC and tokenized T-bill fund contracts are third-party contracts.
Offchain assurance
This is not a smart-contract audit. It is independent assurance over the offchain facts the protocol depends on — reserve and position existence, and the legal structure holding them — and it is a fourth engagement alongside the three contract audits.
| Assurance | Provider | Frequency |
|---|---|---|
| Proof of Reserves & Bonds (agreed-upon procedures) | Pending engagement | Per epoch |
| Legal opinion: Holding Subsidiary structure and title to bond positions | Pending engagement | One-off, refreshed on change |
| Legal opinion: token classification in key jurisdictions | Pending engagement | One-off |
Latest attestation report
No attestation engagement has been signed yet. Until one is, reserve balances and bond positions can be verified directly onchain.
- Snapshot date
- — (first attestation pending)
- Independent accountant
- — (engagement pending)
- Engagement
- Agreed-upon procedures
Live bug bounty: to launch alongside mainnet deployment.
Contract addresses
USD.estate deploys to Base. Contracts are not yet deployed; addresses are published at deployment.
Anti-phishing. Only interact with addresses listed on the Contract Addresses page of the docs. USD.estate will never ask you to send funds to an address announced anywhere else.
Base
| Contract | Address |
|---|---|
| USDest | Not yet deployed |
| sUSDest | Not yet deployed |
| BasePositionManager | Not yet deployed |
| BondPositionManager | Not yet deployed |
| BondPositionManager ONCHAINID | Not yet deployed |
| Subscription Timelock | Not yet deployed |
| BondAllowlist | Not yet deployed |
| RiskParameters | Not yet deployed |
| Timelock Controller | Not yet deployed |
Multisigs & roles
| Role | Safe address | Threshold |
|---|---|---|
Strategy multisigSTRATEGY_ADMIN_ROLE | Not yet deployed | 3-of-5 |
Credit agentCREDIT_AGENT_ROLE | Not yet deployed | 2-of-3 |
ComplianceMINT_ALLOWLIST_ROLE | Not yet deployed | 2-of-3 |
Pause guardianPAUSE_ADMIN_ROLE | Not yet deployed | 2-of-4 |
| Timelock proposer (Foundation) | Not yet deployed | 3-of-5 |
Pause-guardian signers are disjoint from the strategy multisig signers. Signer addresses are published at deployment; the thresholds are the launch values and change only through the timelock.
Referenced third-party assets
| Asset | Role | Address |
|---|---|---|
| USDC | Reserve and settlement currency | Canonical USDC on Base (published at launch) |
| Tokenized T-bill fund token | USDest reserve | Published at launch |
Verify it at the source.
Each figure links to the contract or wallet on a block explorer, and to the latest attestation report once available.