
Ondo
Ondo USDY
Ondo USDY is a tokenized note on Ethereum representing claims on short-term US Treasuries and bank deposits, issued by a bankruptcy-remote Delaware SPV. Yield accrues from US Treasury interest, with daily verification by Ankura Trust and 103%+ overcollateralization.
AUM
$586.71m-0.33%
APY
3.55%
CCC+Rated Protocol
Updated Mar 13, 2026Risk Rating
CCC+
This rating is based solely on publicly available information. The range from CCC+ to BBB reflects the gap between the current assessment and the potential rating achievable if all identified improvement areas are addressed.
SCS: Smart Contract Security
KMP: Key Management Permissions
M: Market
L: Liquidity
C: Collateral
PM: Protocol Mechanics
ICE: Infra Counterparty Exposures
PCE: Protocol Counterparty Exposures
G: Governance
FR: Financial Resilience
TLC: Team Legal Compliance
DT: Documentation Transparency
Potential Score
Provider risk assessed across Business, Operations, Reliability, and Security.
View the detailed scoring breakdown
Challenge this ratingContract Addresses
VaultContract
0x96F6...985C
Oracle
0xa021...1de0
Blocklist
0xd8c8...B0a8
ProxyAdmin
0x3ed6...4c19
USDYManager
0x25A1...b97e
USDYImplementation
0xea0f...7528
Registry (Allowlist)
0x7cE9...dc70
GovernanceMultisig (Management)
0xaed4...8367
GovernanceMultisig (ProxyAdmin Owner)
0x1a69...3ad7
Key Strengths
- Extensive audit coverage from multiple top-tier firms including Spearbit/Cantina and Code4rena, with no unresolved critical findings across 8+ independent audits
- Bankruptcy-remote Delaware SPV with Ankura Trust as collateral agent holding first-priority security interest, providing structural investor protection
- 103%+ overcollateralization verified daily by Ankura Trust, backed by US Treasury bills and bank demand deposits
- 4-of-7 Gnosis Safe multisig for both proxy upgrades and management operations, verified on-chain
- Active Immunefi bug bounty program with $250K maximum payout
- SEC investigation closed without charges or enforcement action
Key Risks
- No on-chain timelock for proxy upgrades, allowing the multisig to upgrade the USDY implementation instantly without advance notice or user exit window
- Admin can burn tokens from any address and selectively block transfers via allowlist/blocklist enforcement, required for securities compliance but representing significant control over user funds
- 100% off-chain custody with Ondo as sole transfer agent for minting, redemption, and oracle price updates; recovery in insolvency depends on Ankura Trust legal process
- Multisig signer identities undisclosed with significant overlap between governance multisigs, making independence unverifiable
- Thin secondary market liquidity relative to TVL, with historical NAV deviation exceeding 6% during early thin-market conditions
- No disclosed real-time monitoring system or incident response playbook for smart contract operations
Market Overview
ChainEthereum
TreasuryNot reported
Stated Withdrawal Time5 business days
Get the full picture today
Request the full rating report and gain access to unparalleled rating data & information.
Request a full report