Spiko

Orange · 67/100 Data confidence 75/100

Missing critical evidence: incident, legal. The score is capped until coverage improves.

Executive summary

Spiko is a Paris-based tokenized money-market fund platform issuing regulated T-bill fund shares (USTBL/EUTBL) on seven blockchains, scoring 33/100 (red band) due to governance opacity, unverified smart-contract controls, and limited on-chain transparency.

  • Structure & regulation: Fully doxxed founders (Paul-Adrien Hyppolite, ex-French Treasury; Antoine Michon, ex-Palantir) operate a MiFID-licensed firm supervised by French ACPR/AMF; funds managed by Twenty First Capital with CACEIS (Crédit Agricole) as custodian and PwC as auditor, positioning Spiko as a regulated RWA issuer rather than permissionless DeFi.
  • Governance & custody: No DAO governance; control rests with company and undisclosed admin multisig that can upgrade all EVM contracts via UUPS proxy; signer set, threshold, and timelock are not verifiable as of 2026-08-29. Fund assets custodied by CACEIS; on-chain tokens can be self-custodied by users.
  • Security: Halborn audit (2025) found a Critical Stellar redemption bug (since fixed); Trail of Bits audit (Oct 2023) reported 4 findings (2 low, 2 informational). No bug bounty program verifiable; exact reserve addresses and on-chain balances across all seven chains not verifiable as of 2026-08-29.
  • Top risks: Sovereign default risk on underlying T-bills; smart-contract/tokenization layer risk; custody and operational concentration with off-chain providers; regulatory framework dependency; undisclosed multisig control enabling unilateral upgrades without public timelock.
  • Economic model: Organic yield from short-duration government securities (U.S./EU T-bills), net of management fees; no leverage, subsidies, or crypto emissions. Daily liquidity and daily accrual claimed but live transaction throughput not verifiable as of 2026-08-29.
  • Strengths: Regulated structure with AMF oversight; institutional-grade custody; Arbitrum DAO endorsed Spiko for treasury diversification (35% proposed allocation); daily yield and fee-free subscriptions/redemptions in USDC/EURC per marketing materials.
  • Unverified: TVL, exact reserve composition, multisig signers/threshold, on-chain deployment dates, live withdrawal completion, stress-test exposures, and all yield/counterparty claims rely on protocol marketing without independent on-chain confirmation as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 90 22.5 3 audit(s); fresh audit bonus; no qualifying bug bounty
incidents 25% 50 12.5 0 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 85 12.8 0 onchain, 18 two-source, 5 one-source of 24 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL unavailable; neutral context, not a safety signal
governance 10% 70 7.0 verified governance +20; timelock in governance +15; no legal signals

Identification

protocol identification

two sources

Spiko is a tokenized money‑market / RWA protocol, not a traditional permissionless DeFi yield farm, issuing regulated fund tokens and integrating them into DeFi rails. ### Basic identification

  • Name: Spiko
  • Website: spiko.io
  • Docs / tech content: Public product docs and technical blog via the main site and tech.spiko.io (no separate DeFi-style docs repo visible).
  • Category: Real‑World Assets (RWA) / tokenized money market funds (USTBL / EUTBL), plus UCITS cash‑management products (Spiko Dollar / SAFO).
  • Legal / business launch: Founded June 2023 as a MiFID investment firm licensed by French regulators (ACPR, AMF).
  • On‑chain launch date: Not verifiable as of 2026‑08‑29. ### Chains and deployment footprint Independent data platforms classify Spiko as an RWA protocol “deployed across 7 chains, led by Etherlink, Ethereum, Base.” The user‑provided list (Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, Etherlink) matches this description, but:
  • Exact contracts per chain and deployment timestamps are Not verifiable as of 2026‑08‑29. ### Tokens / instruments
  • Main on‑chain products (native instruments, not governance tokens):
  • EUTBL / USTBL – tokenized EU‑regulated money market funds investing in Eurozone and US T‑Bills.
  • Spiko Dollar / Spiko Amundi Overnight Swap Fund (SAFO) – UCITS fund using total‑return swaps with BNP Paribas to deliver daily USD yield (SOFR + 0.47%); Amundi as manager, CACEIS as custodian.
  • Any distinct ERC‑20 contract symbols or addresses for these instruments are Not verifiable as of 2026‑08‑29.
  • No evidence of a separate governance / utility token (e.g., “SPIKO”) is visible; Spiko operates as a regulated issuer rather than a token‑governed DAO. ### Contract addresses & verification status
  • Specific main contract addresses on Ethereum, Arbitrum, Polygon, Base, Starknet, Etherlink, Stellar and their explorer verification status are Not verifiable as of 2026‑08‑29.
  • Cross‑checks against on‑chain analytics or explorer pages cannot be performed in this turn; any address list from third‑party sites would be treated as unverified marketing claim. ### Fork lineage and code provenance
  • An independent risk review explicitly states Spiko is “not a traditional DeFi protocol” but a Paris‑based fintech tokenizing regulated money market funds on public blockchains, implying a purpose‑built infrastructure rather than a clear fork of major DeFi money‑market protocols (e.g., Aave, Compound).
  • No public evidence that Spiko’s core issuance / transfer infrastructure is a direct fork of another protocol, nor of a separate open‑source repo showing such a fork. Not verifiable as of 2026‑08‑29.
  • Spiko’s funds do integrate with Morpho markets (e.g., SAFO used as collateral on Morpho) but that concerns Morpho’s contracts, not Spiko’s own protocol being a fork of Morpho.
  • No records found of malicious modifications in Spiko forks or compromised clones. Not verifiable as of 2026‑08‑29 for any such history. Given the absence of verifiable contract data in this turn, any more detailed contract‑level or audit‑mapping analysis must be flagged as Not verifiable as of 2026‑08‑29 rather than inferred.
Evidence (9)

maturity

two sources

Spiko looks like a live product, not just a landing page: independent API listings show a self-service dashboard, account access, and APIs for balances, transactions, deposits, withdrawals, webhooks, and documents, which indicates real portal functionality rather than a static marketing site. The documentation snippets also describe authenticated read/write flows and include deposit/withdrawal order endpoints, supporting that live money movement is part of the product surface. I could not verify actual deposit/withdrawal completion on-chain or from independent runtime evidence here, so live transaction execution remains Not verifiable as of 2026-08-29. Similarly, broken links, fake metrics, and template-sign detection are Not verifiable as of 2026-08-29 from the material gathered. Open API: yes. Multiple sources describe an open Public API plus investor/distributor APIs, with explicit API documentation and published endpoint collections. Overall maturity verdict: productized and operational on the web/API layer, with a functional portal and documented money-movement APIs, but on this evidence set the live-usage depth and real-world transaction throughput are Not verifiable as of 2026-08-29.

Evidence (6)

Security

audit

two sources

Spiko’s Stellar smart contracts (Soroban‑based "Smart Account" / redemption logic) were audited by Halborn with an engagement dated 16–17 September 2025, published 3 October 2025. Scope: protocol‑level security review of the Stellar contracts implementing account management and fund redemption; Halborn describes manual and automated testing of Rust code, cross‑contract interactions, and fail‑closed behavior. The audit reports 1 critical, 0 high, 0 medium, 1 low, and several informational issues. The Critical finding was "Redemption execution burns from user account instead of redemption contract," which could lock funds or mis‑burn tokens; Halborn records it as Solved – 2025‑09‑21. A Low issue (admin renounce leaving contract without admin) and multiple Informational issues (idempotency key consumption without work, constructor/initialize placement, documentation) are also marked Solved – 2025‑09‑21. Halborn and the Stellar Security Portal both list this audit, but whether the currently deployed Stellar bytecode matches the audited version is Not verifiable as of 2026‑08‑30. Link (non-clickable): Halborn "Stellar Contracts – Spiko" audit report.

Auditor
Halborn
Report Date
2025-10-03
Scope
Stellar Soroban smart contracts (Smart Account system and redemption logic on Stellar)
Evidence (4)

audit

one source

There is a Nethermind audit report file "NM0333-FINAL_SPIKO.pdf" in Nethermind’s public audit‑reports GitHub repository. This confirms Nethermind has produced at least one security report involving Spiko, but the contents (scope, chains, severity breakdown, and fix status) are Not verifiable as of 2026‑08‑30 because the PDF was not inspected here. Accordingly, its coverage of Spiko’s deployments on Ethereum, Arbitrum, Polygon, Base, Starknet, Etherlink, or Stellar cannot be relied upon without direct review — this entry serves only as a pointer that an additional audit likely exists. Bytecode‑match status to current deployments is also Not verifiable as of 2026‑08‑30.

Auditor
Nethermind
Report Date
2023-04-19
Scope
Unclear; Nethermind audit report exists but its detailed scope and findings were not reviewed in this run.
Evidence (1)

audit

two sources

Spiko’s EVM smart contracts (Ethereum stack, covering the fund/tokenization logic) underwent a security review by Trail of Bits in October 2023. Scope (per Trail of Bits’ summary): protocol-level smart‑contract review of the core Spiko contracts governing the funds on EVM chains; the public summary lists 4 findings: 0 critical, 0 high, 2 low, 2 informational. Identified issues included locked tokens in the Redemption contract and lack of minimum redemption amount (both Low) plus oracle and event‑emission concerns (Informational). The Trail of Bits library entry and Spiko technical blog state that these contracts were audited, but do not publicly enumerate fix status for each issue nor provide explicit bytecode‑match verification for currently deployed contracts on Ethereum, Arbitrum, Polygon, Base, Starknet, Etherlink—this is Not verifiable as of 2026‑08‑30. One independent review notes that this EVM audit is now stale relative to later additions (CCIP cross‑chain, Morpho integration, multi‑chain expansion). Link (non-clickable): Trail of Bits “Spiko Smart Contracts” audit report in their public library.

Auditor
Trail of Bits
Report Date
2023-10
Scope
EVM smart contracts (core fund/tokenization logic; Ethereum‑stack, multi‑chain deployment; exact chain coverage per deployed contracts is not fully documented publicly)
Evidence (5)

bug bounty

two sources

Not verifiable as of 2026-08-29. No Spiko bug bounty program was found in the web results, and the only relevant security evidence located was an audit report plus a third-party directory page that appears to be for Spike, not Spiko, so it cannot be used to confirm an active program, its start date, parameters, or results. The Trail of Bits review shows Spiko had a security audit in October 2023 with 4 findings (2 low, 2 informational), but that is an audit, not a bug bounty program. The Halborn audit for Spiko Stellar contracts shows a separate 2025 engagement with several fixed findings, again not a bounty program.

Evidence (3)

counterparty risks

one source

Spiko appears to be an early‑stage / low‑profile protocol; there is very limited independent information and no accessible docs beyond the main site. As a result, most dependency details are Not verifiable as of 2026‑08‑30. ### 1. Identity, scope, and basic integration landscape Public sources confirm Spiko as a DeFi project with a site at spiko.io but provide almost no detail on architecture, contracts, or supported chains beyond marketing references. Given this opacity, every specific dependency (bridges, oracles, custodians, CEX links, RWA issuers) is not independently documented. ### 2. External protocol & token exposure

  • Stablecoins, LSTs, restaking tokens: There is no reliable listing of what assets Spiko supports or how they’re used (collateral vs. LP vs. rewards). Not verifiable as of 2026‑08‑30.
  • Other DeFi protocols: No confirmed integrations (e.g., lending markets, DEX routers, yield aggregators) can be tied to contract addresses for Spiko on any chain. Not verifiable as of 2026‑08‑30. Risk implication: Without on-chain or documentation evidence, you must assume *unknown but potentially material protocol counterparty risk* across each chain where Spiko claims to operate. ### 3. Oracles & price manipulation risk No credible information on:
  • Which oracle(s) (Chainlink, Pyth, TWAP, custom) Spiko uses.
  • Whether prices are pull/push, on-chain only, or off-chain fed. Therefore, oracle choice, update frequency, and manipulation risk (low-liquidity pairs, thin books) are Not verifiable as of 2026‑08‑30. ### 4. Bridges and cross‑chain infrastructure Spiko marketing mentions multiple chains (Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, Etherlink), but there is no independent mapping of:
  • Cross‑chain messaging providers (LayerZero, Wormhole, Axelar, native bridges).
  • Whether positions or accounting are synchronized across chains. All bridge dependencies and associated failure modes (message spoofing, relayer failure, wrapped-asset depegs) are Not verifiable as of 2026‑08‑30. ### 5. Custodians, CEX/MM, and RWA issuer/SPV risk No evidence of:
  • Off‑chain custodians or segregated accounts.
  • Centralized exchange or market-maker relationships.
  • RWA issuers, SPVs, or legal structures backing onchain claims. All of these remain Not verifiable as of 2026‑08‑30. ### 6. Institutional risk stance Given the near-total lack of independent technical docs, audits, or transparent integration maps, Spiko should be treated as high counterparty and dependency opacity risk. Any institutional exposure would require, at minimum:
  • Full technical documentation plus contract addresses per chain.
  • Detailed integration list (oracles, bridges, supported tokens and protocols).
  • Updated audits and real‑time monitoring before underwriting material capital.
Evidence (2)

crypto custody

one source

Spiko’s custody is split between the underlying fund assets and the tokenized fund units. The Treasury-bill cash/fund assets are held by CACEIS, described by Spiko and Crédit Agricole as the depositary/custodian and a subsidiary of Crédit Agricole; Spiko says the cash is never held by Spiko itself. The blockchain units are issued as tokenized fund shares on public blockchains, and CACEIS provides the wallet infrastructure used to custody those units on-chain. Spiko also says investors can use their own wallets to hold and transfer the fund shares, meaning token custody can be self-custodial at the user level.

Evidence (4)

key management

unverified

Spiko appears to organize key management as a layered access-control system rather than a single shared admin key. On the smart-contract side, it uses a Permission Manager with permission groups: a multisig-controlled super-admin group for upgrades and permission changes, plus separate roles for emergency pausing, minting/redemptions, NAV publication, investor onboarding, and allowlisted investors. On Stellar, operations are split across multiple accounts: a main wallet signs authorization, a channel account provides sequence numbers for throughput, and a sponsor wallet pays fees via fee-bump transactions. For user-facing operational access, Spiko says the app supports multiple access levels across an organization, with 2FA on critical functions and an optional four-eyes mode for approvals of sensitive actions such as withdrawals. Spiko also states its blockchain infrastructure uses a managed wallet from Dfns for transaction signing, which indicates outsourced wallet/key custody for some operational signing flows. What is not verifiable as of 2026-08-29 from the available sources is the exact internal key ceremony, recovery process, HSM usage, or whether all chains in scope (Ethereum, Arbitrum, Polygon, Base, Starknet, Etherlink, Stellar) share the same key-management model.

Evidence (4)

smart-contract

two sources

Spiko’s contract system appears upgradeable and permissioned, but several key risk details are not verifiable as of 2026-08-30 because on-chain decoding was unavailable in this run. Independent web evidence indicates Spiko uses a proxy-based architecture for its tokenized securities contracts, with verified source on Etherscan/Polygonscan for at least some deployments and a separate PermissionManager referenced in the codebase and deployment instructions. A third-party explainer on the EUTBL product says the token was deployed behind a UUPS proxy in April 2024 and that there had been a single upgrade event, but that claim is not independently on-chain verified here. What is verifiable from the gathered web evidence: Spiko’s supported ledgers include Ethereum, Polygon, Arbitrum, Base, Starknet, Etherlink, and Stellar, so risk must be assessed per chain rather than as one system. The contracts repository shows deployment/verification workflows for proxy contracts and a PermissionManager, which implies role-gated administration rather than fully immutable contracts. Spiko’s own technical post also states it operates across EVM chains, Starknet, and Stellar, reinforcing a multi-chain administrative surface. What is not verifiable as of 2026-08-30: the exact proxy admin type, on-chain admin/owner addresses, emergency roles, timelock delay, pause/withdrawal/upgrade/fee/oracle/strategy function permissions, renounced-role status, and whether users can always exit without admin intervention. The same applies to chain-by-chain exposure percentages and any claim about the worst-case effect of key compromise at the contract level. Risk assessment: if the proxy/permission keys are compromised, the practical worst case is that an attacker could potentially upgrade logic, change permissions, pause transfers/operations, or otherwise block redemptions/withdrawals depending on the specific contract wiring; however, the exact powers are not verifiable as of 2026-08-30. That means the protocol should be treated as carrying material admin-key and upgrade risk, with a possible freeze/rug vector typical of permissioned upgradeable systems until on-chain role checks are confirmed. Architecture map (high-level):

  • User-facing token / fund contracts
  • Proxy layer for upgradeability
  • PermissionManager / role control layer
  • Chain-specific deployments across Ethereum, Polygon, Arbitrum, Base, Starknet, Etherlink, and Stellar Diagram: Users -> Proxy -> Implementation ^ | Admin / PermissionManager Overall: upgradeable, permissioned, non-immutable; exact admin controls and exit guarantees are Not verifiable as of 2026-08-30.
Evidence (5)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Spiko is a fully doxxed, Paris-based fintech that tokenizes AMF‑regulated money market funds and then bridges them to multiple chains; it is closer to a regulated RWA issuer using blockchains than to a typical anonymous DeFi yield farm. Founders & senior team

  • Co‑founder/CEO – Paul‑Adrien Hyppolite: French economist and former public‑sector official. He worked at the French Treasury on financial instruments market regulation and previously at the European Commission. IQ.wiki and Spiko’s site both describe him as co‑founder and CEO of a Paris‑based firm founded in 2023.
  • Co‑founder/COO – Antoine Michon: Former ministerial adviser in charge of France’s digital transformation, previously responsible for deployment at Palantir. Co‑founder of Spiko in 2023.
  • Other listed team members (CTO, operations, legal/compliance) appear on third‑party venture/analytics profiles (e.g., RootData), including a Head of Legal and Compliance (Victor Charpiat), suggesting an in‑house regulatory function. Public vs anon; credibility
  • Founders are fully public, using real names, with bios in mainstream media, venture investors’ pages, and job listings; this is atypical for anonymous DeFi teams and increases traceability.
  • Backgrounds in French Treasury, EU institutions, and Palantir plus coverage in regulated‑finance media (CrowdfundInsider, venture firm Index Ventures) support a profile of experienced, career‑risk‑bearing founders rather than pseudonymous operators. Jurisdiction, office, and business reality
  • Multiple sources describe Spiko explicitly as a Paris‑based fintech or “European financial technology company,” co‑founded in 2023 and licensed by the French AMF to offer tokenized money market funds.
  • Job postings show roles located in Paris (75002), implying a physical office presence.
  • The product is described as AMF‑regulated tokenized MMFs with custody/banking via BNP Paribas and distribution via on‑chain tokens (USTBL/EUTBL) across Ethereum, Polygon, Base, Arbitrum, Starknet, Stellar, and Etherlink. Prior projects, hacks, controversies
  • Public bios emphasize prior work in government and large enterprises, not previous crypto protocols.
  • As of the latest articles, there are no reported protocol hacks or major security incidents for Spiko itself; independent commentary frames it as *not* a typical permissionless DeFi protocol but a regulated issuer using blockchain rails.
  • Any on‑chain incident or holdings analysis is Not verifiable as of 2026‑08‑29 due to lack of direct on‑chain querying in this context. Reality check
  • Overall profile: on‑shore, heavily regulated, non‑anonymous team with real‑world careers and an identifiable Paris office, backed by institutional VCs and operating under French AMF oversight. This is structurally closer to a traditional financial institution integrating crypto rails than to a web‑only, offshore DeFi yield protocol.
Evidence (15)

general reputation

two sources

Spiko currently has a generally positive, institution‑friendly reputation, with some noted structural and integration risks rather than accusations of fraud or misconduct. Protocol / product positioning

  • Spiko is described as a Paris-based fintech tokenizing EU‑regulated money market funds (USTBL, EUTBL) on public blockchains, not a typical permissionless DeFi protocol.
  • Multiple outlets highlight Spiko as a prominent RWA player in Europe and an institutional‑grade provider of tokenized T‑bill money market funds on Arbitrum.
  • Arbitrum DAO’s STEP 2 initiative selected Franklin Templeton, Spiko, and WisdomTree to expand on‑chain RWA adoption, with a proposed 35% allocation to Spiko’s USTBL in its treasury diversification plan—an explicit governance‑level endorsement. Regulation, auditors, and structure
  • Spiko’s money market funds are repeatedly reported as UCITS- and MMFR‑compliant and regulated by the French Financial Markets Authority (AMF), which materially supports its credibility.
  • Yields are described as net‑of‑fees, accrued and paid daily by a banking counterparty (BNP Paribas) on the official site; absent independent confirmation, this is an unverified marketing claim.
  • No independent smart‑contract audit reports or named blockchain security auditors surfaced in the retrieved data. Not verifiable as of 2026‑08‑29. Sentiment and market perception
  • DefiLlama and MrDeFi list Spiko as a top RWA protocol with substantial TVL across 7 chains, and Cryptonews notes it among top Arbitrum DeFi projects by TVL, supporting a perception of traction and institutional interest.
  • An independent “DeFi Bullshit Detector” report characterizes Spiko’s core regulated MMF product as LOW‑TO‑MODERATE risk, but flags ELEVATED risk when used through DeFi lending layers (e.g., Morpho) or on newer chains like Stellar, Starknet, Etherlink, citing thinner audits and infrastructure maturity. Founders, investors, and governance
  • Media identify Paul‑Adrien (co‑founder & CEO) as a public representative; this aligns with press materials but deeper founder background and cap table details are not verifiable as of 2026‑08‑29.
  • No specific VC investors, fundraising rounds, or ownership concentration data appear in the retrieved sources. Not verifiable as of 2026‑08‑29. Criticisms, fraud/rug, legal and sanctions
  • Across media, analytics, and commentary, there are no reported fraud, rug pull, insolvency, or sanctions allegations against Spiko.
  • The key substantive criticism is structural: users bear traditional finance product risk and regulator/jurisdiction risk, plus DeFi integration risk when using Spiko via lending/leveraged protocols. Overall, reputation risk is driven more by regulatory/structural and integration considerations than by any history of misconduct or legal action, based on currently available data.
Evidence (15)

Economy

model

two sources

Spiko appears to be a tokenized money-market/fund protocol, not a leveraged DeFi strategy: the on-web evidence says its tokenized U.S. and E.U. T-Bills funds are deployed across Stellar, Arbitrum, Polygon, Ethereum, Base, Starknet, and Etherlink, and Spiko’s own FAQ says subscriptions/redemptions in USDC or EURC have no extra fees and that displayed yields are net of fund-management fees. The economic model is therefore *real-asset / cash-equivalent exposure* rather than directional trading, looping, restaking, or market-making; however, the exact composition, lock-ups, gates, and withdrawal mechanics are Not verifiable as of 2026-08-29 from the gathered evidence. Yield source: DeFiLlama’s methodology states Spiko “yields are generated from investment assets,” and Spiko’s product copy identifies USTBL/EUTBL as tokenized money-market funds invested in U.S. / Eurozone T-bills. That implies the yield is primarily *organic* (short-term government securities and money-market instruments), with no evidence in the gathered sources of subsidies, incentives, or leverage. Protocol revenue is partly observable only at the fee layer: DeFiLlama lists recent fees, while Spiko says the only associated fees are management fees and displayed yields are net of fees; the split between protocol revenue and fund-manager economics is Not verifiable as of 2026-08-29. TVL / chain mix: DeFiLlama shows materially different chain distribution depending on view and denomination; one current snapshot places Stellar at $537.6m, Arbitrum $373.6m, Polygon $82.6m, Ethereum $79.7m, and Etherlink $8.5m, while another POL-denominated view shows Arbitrum $160.7m, Polygon $157.1m, Ethereum $45.3m, Starknet $24.4m, and Etherlink $5.2m. A third independent web result reported yet another breakdown (Stellar $1.56b, Arbitrum $471.8m, Ethereum $213.8m, Polygon $174.4m, Base $38.9m, Starknet $34.0m, Etherlink $4.9m), so the exact total and chain percentages are contradictory across sources and should be treated as Not verifiable as of 2026-08-29 without on-chain rechecking. APY / sustainability: Spiko’s model is structurally low-volatility because it is tied to short-duration T-bills / money-market assets, so APY should mainly track policy rates and fund expenses, not token emissions; but an APY history or volatility series was not verified from the gathered sources, so it is Not verifiable as of 2026-08-29.

Evidence (5)

reserves

one source

Spiko’s reserves appear to be the assets of its money-market funds, described as backed by U.S. Treasury bills or, for the euro product, securities held by CACEIS, a Crédit Agricole subsidiary; Spiko says client money is never held on Spiko’s balance sheet and is kept by the custodian. The composition is therefore primarily short-dated sovereign debt and related fund assets, but the precise reserve mix, treasury addresses, and on-chain balances are not verifiable as of 2026-08-29. Spiko’s own materials also claim a treasury policy of keeping almost all of its corporate treasury in its own funds (99%), but this is an unverified marketing claim without an on-chain cross-check. Independent third-party coverage indicates the products are backed by Treasury bills and that custody is centralized with CACEIS/PwC-style reserve attestations for some products, but the exact reserve size and control addresses remain Not verifiable as of 2026-08-29. On-chain verification across Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, and Etherlink is Not verifiable as of 2026-08-29.

Evidence (3)

tokenomics

two sources

Spiko does not appear to have a single native governance/reward token in the DeFi sense; the on-chain assets are regulated fund-share tokens for its money-market funds, mainly USTBL and EUTBL. Those tokens are described as ERC-20 (or Stellar asset for Stellar) representations of fund shares, not incentive tokens, and the available sources do not show any governance role, staking utility, revenue share, buybacks, burns, or protocol emissions schedule. For token identifiers and contract addresses, the best-supported public references identify USTBL on Ethereum at 0xe4880249745eac5f1ed9d8f7df844792d560e750, with a separate Arbitrum deployment at 0x021289588cd81dc1ac87ea91e91607eef68303f5; EUTBL/other chain deployments are referenced in secondary materials, but a complete multi-chain address set is Not verifiable as of 2026-08-29 from the gathered sources alone. The sources do not provide a reliable circulating-supply, total-supply, market-cap, or FDV framework comparable to a crypto-native token, because these are regulated fund shares whose supply is functionally tied to fund subscriptions/redemptions rather than token emissions. There is no evidence in the gathered sources of team/investor/community allocations, unlock schedules, or announced unlocks; accordingly, whether such unlocks occurred on-chain is Not verifiable as of 2026-08-29. Likewise, top-holder concentration, insider wallets, mint/blacklist/fee-switch controls, and who controls them are Not verifiable as of 2026-08-29 from the available sources. The GitHub material does confirm the contracts are upgradeable ERC-20s with ownership patterns in the codebase, but it does not support a full tokenomics or control-risk assessment by itself. For DEX liquidity and main listings, the gathered sources show market-tracker/explorer references for USTBL and EUTBL, but not enough independent liquidity data to quantify depth or identify primary DEX venues robustly; this is Not verifiable as of 2026-08-29.

Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Spiko, a Bitcoin drop below $10,000 is not verifiable as of 2026-08-29 from the available web results. The results you provided are only about Bitcoin price scenarios and do not establish whether Spiko has any BTC exposure, direct or indirect, on Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, or Etherlink. What can be stated is that a $10,000 BTC scenario is widely described by analysts as an extreme tail-risk macro shock rather than a base case, typically requiring forced deleveraging, liquidity stress, and broad market contagion. But because no on-chain or protocol-specific portfolio data for Spiko is available here, the impact on Spiko’s funds, reserves, or token mechanics is Not verifiable as of 2026-08-29. If you want, I can next help structure a protocol-specific stress checklist for Spiko (e.g., BTC-linked asset exposure, collateral concentration, stablecoin reserve quality, and chain-by-chain TVL exposure) using only verifiable sources.

Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

Spiko appears to be a tokenized Treasury-bill cash product, not a leveraged lending protocol; based on the available sources, a 20% depeg stress is more relevant to its *collateral assets* than to protocol insolvency mechanics. The strongest available evidence says Spiko’s core products are regulated money-market funds investing in U.S. or Eurozone T-bills, while the Arbitrum application states the fund holds highly secure assets and is prohibited from incurring debt. Because no on-chain exposure breakdown or collateral map is verifiable from the provided sources, the impact of a 20% depeg on the largest collateral is Not verifiable as of 2026-08-29. I cannot confirm what the “largest collateral” is, whether it is directly held in the protocol, or whether any integrated lending venue would see liquidations or insolvencies from that move. What can be said from comparable DeFi stress studies is that a 20% depeg can produce material liquidations in lending systems when the depegged asset is used as collateral, with outcomes depending heavily on liquidation thresholds and market liquidity; for example, Aave’s historical stETH stress analysis showed liquidations and a smaller but non-zero insolvency component at 20% depeg scenarios. That analogy is *directionally useful only* and does not establish Spiko-specific losses. For Spiko itself, the available sources support these constraints:

  • Core exposure is to short-duration sovereign cash-like instruments, which typically have limited price volatility relative to crypto collateral.
  • The DeFi layer risk, if any, would likely come from external integrations such as lending markets, not from the regulated fund wrapper itself.
  • There is no source here confirming a chain-specific collateral concentration across Stellar, Arbitrum, Ethereum, Polygon, Base, Starknet, or Etherlink. So the defensible risk conclusion is: potential impact exists only if a 20% depeg hits an externally used collateral asset; the magnitude is not verifiable from current evidence. If you want, I can next produce a chain-by-chain risk memo limited to what is verifiable from the web sources provided.
Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Spiko is a tokenized, regulated money‑market fund platform, not a pure DeFi lending protocol, so the “top counterparty insolvent” stress must be framed around insolvency of the *off‑chain banking/fund infrastructure* that underpins USTBL/EUTBL/other funds. Below is the generic path; on‑chain verification of specific positions is Not verifiable as of 2026-08-29. ### 1. Identify the “top counterparty” in Spiko’s stack Key off‑chain counterparties:

  • Custodian / banking partner (e.g., BNP Paribas) paying net‑of‑fees yields on the underlying MMFs.
  • Fund manager / issuer of the UCITS MMFs (Spiko and allied asset managers).
  • Sovereign T‑bill issuers (US Treasury, Eurozone sovereigns) as ultimate credit exposure for USTBL/EUTBL. On‑chain holders are *investors in fund shares*; chains (Ethereum, Arbitrum, Base, Polygon, Starknet, Stellar, Etherlink) are settlement layers, not credit counterparties. ### 2. Stress: banking/custodian insolvency Event path
  • Bank/custodian becomes insolvent or is placed into resolution; fund cash, repo collateral, and T‑bill positions may be frozen or impaired pending legal proceedings.
  • Fund NAV calculation is disrupted; transfer‑agent/share register may be suspended. On‑chain propagation
  • Smart contracts representing USTBL/EUTBL/gbpSAFO etc. continue to exist but redemptions and primary mints are halted by the issuer (pause/role‑based controls or off‑chain gating).
  • Token price on secondary markets may decouple from last reported NAV; protocols treating these tokens as “cash‑equivalent” collateral face mark‑to‑market losses. Who absorbs the loss?
  • Economic loss is borne by fund shareholders (USTBL/EUTBL/gbpSAFO token holders) via NAV haircut if assets are not fully recoverable.
  • Any DeFi protocol or DAO that holds these tokens (e.g., Arbitrum STEP 2 treasury exposure to USTBL) absorbs NAV losses and liquidity freeze. Compensation
  • UCITS/MMF frameworks may provide diversification, risk‑limits, and regulatory oversight, but not full principal guarantees; recovery depends on insolvency proceedings and asset segregation quality.
  • Deposit insurance schemes typically do not cover institutional MMFs; partial recoveries are possible but uncertain. ### 3. Stress: sovereign T‑bill / RWA issuer distress Event path
  • Extreme tail: default or restructuring on underlying sovereign bills. Impact path
  • NAV declines proportionally; daily yield turns negative.
  • On‑chain: token balance stays constant, but NAV per share falls; secondary markets re‑price. Loss absorption
  • Again borne by token holders and protocols using them as collateral; smart contracts only reflect updated NAV and do not absorb credit losses themselves. ### 4. Chain‑level and bridge‑level issues Protocol docs emphasize Spiko is a *multi‑chain register*, inheriting each chain’s censorship‑resistance and bridge risks.
  • Chain halts or bridge failures can freeze transfers or strand tokens, but do not change off‑chain NAV; they create *liquidity/operational* rather than credit losses. On‑chain quantification of exposure per chain is Not verifiable as of 2026-08-29.
Evidence (15)

stress scenario - committed fraud by the DAO or owners

two sources

For Spiko, a DAO-or-owners committed fraud scenario is not supported by the available evidence. The strongest material in the results instead describes a regulated tokenized money-market product, and an independent review states that no fraud signals were identified across the research layers. There is, however, a separate technical risk history: Halborn’s audit of Spiko’s Stellar contracts reported a Critical redemption bug that was later marked solved, which is an operational/code-risk issue rather than evidence of owner fraud. That audit specifically says redemptions were burning from the wrong account and could have led to locked funds, but it also records remediation on 09/21/2025. So, under a stress test for committed fraud by the DAO or owners, the current evidence is: no verified fraud event and Not verifiable as of 2026-08-29 for any claim that Spiko’s DAO/owners actually perpetrated fraud. The main credible concerns in the results are governance opacity and smart-contract risk, not demonstrated fraudulent conduct. If you need a risk label: fraud risk = unverified / not evidenced; operational smart-contract risk = elevated on some chains, especially where newer deployments were discussed.

Evidence (2)

stress scenario - primary yield source negative 30d,

one source

Spiko does not appear to have a primary yield source that can go negative in the usual DeFi sense. Its product page says yields are *net of fees* and are accrued and paid daily by BNP Paribas, and its Euro product states the banking counterparty pays a daily return tied to €STR plus a spread. On that basis, a negative 30-day primary-yield stress case is not verifiable as of 2026-08-29 from the available sources. The closest relevant stress interpretation is that the yield can compress toward zero or below fees, but the sources provided do not show a mechanism where Spiko’s underlying yield engine itself flips negative for 30 days. The user-facing materials describe the return as coming from the underlying regulated money-market portfolio / bank counterparty, minus fund costs, rather than from volatile crypto emissions or funding rates. Because the protocol’s own materials are the main available source here, this is best treated as an unverified marketing claim rather than independently confirmed stress evidence. For an institutional risk memo, the practical stress finding is: no on-chain or independent evidence supplied here verifies a negative-yield regime for 30 days; the only verifiable statement is that investor returns are dependent on counterparty-delivered net yield and could be reduced by fees or adverse market/rate conditions, but a sustained negative primary yield is Not verifiable as of 2026-08-29.

Evidence (3)

Governance & Legal

governance

two sources

Spiko does not appear to be a DAO-governed protocol; the available evidence points to a company-controlled, regulated fintech structure. Spiko states it is licensed and supervised by the French ACPR and AMF as a MiFID investment firm, and its funds are managed by Twenty First Capital, with CACEIS as custodian and PwC as statutory auditor. The protocol’s own materials describe fund governance as a board-of-directors model, not tokenholder governance. For smart-contract / admin control, there is a material transparency gap: a third-party review says Spiko’s EVM contracts are UUPS-upgradeable and that a super-admin multisig can upgrade all smart contracts, but the signer set, threshold, and timelock have not been publicly disclosed. Spiko’s homepage only says critical functions are protected with 2FA and a “four-eyes” mode for sensitive actions such as withdrawals; this is not enough to verify decentralized governance or multisig independence. Proposal process / voting: Not verifiable as of 2026-08-29. No public DAO proposal system, token voting, or on-chain governance process was verifiable from the gathered sources. DAO real vs symbolic: Based on the available evidence, any “DAO” framing would be symbolic rather than real; control appears to rest with the company/regulated entities and undisclosed admin keys, not tokenholder governance. Timelock / multisig signers / threshold / powers: Not verifiable as of 2026-08-29. The only sourced claim is that a multisig-based super-admin can upgrade contracts; signer identities, threshold, timelock duration, and whether signers are independent remain undisclosed. Legal entity / jurisdiction / reg number / directors / ToS: Spiko identifies itself as a French-supervised investment firm, but the specific corporate registration number, full director list, and binding terms-of-service details were not verifiable from the gathered sources.

Evidence (6)

Stability

stability

two sources

Not verifiable as of 2026-08-29. The available web results identify Spiko’s products and mention stablecoin rails (USDC and EURC), but they do not provide a verifiable price history for the specific stablecoin used, so the number of depeg events, the last occurrence, and the depeg percentage cannot be confirmed from the gathered sources. The protocol-site material describes stablecoin acceptance, not historical peg performance, and the third-party results are risk profiles or general stablecoin explanations rather than an event log for the exact token used by Spiko.

Evidence (3)

Risks & Strengths

risks

two sources

Spiko’s top five risks are: sovereign/default risk of the underlying Treasury-bill exposure, because the assets are ultimately backed by government debt rather than principal-protected cash; smart-contract / tokenization-layer risk, since blockchain wrappers add technical failure modes not present in traditional T-bill funds; custody and operational concentration risk, as tokenized fund operations depend on off-chain custodians and administrators; regulatory risk, because tokenized money-market funds rely on a specific legal framework that could change or be tightened; and rate / market risk, since the value of the underlying securities can move with interest-rate changes before maturity. A few clarifications matter: Spiko itself says its products are invested in risk-free assets or backed by large banks, but its own materials also acknowledge a residual sovereign-default risk even under protected-capital structures. Independent commentary adds that the protocol’s smart-contract and custody layers, plus regulatory concentration, are the main non-market risks for users.

Evidence (5)

strengths

two sources

Spiko’s top strengths are: regulated structure, because it is presented as a tokenized-money-market-fund platform rather than an unregulated DeFi experiment; daily yield, since the site says users earn interest every day; daily liquidity, since it says cash can be accessed anytime; fee simplicity, because the site says yields are net of fees and accounts are free; and operational controls, because it highlights multi-user access levels plus 2FA and four-eyes approval for sensitive actions. More broadly, independent coverage describes Spiko as a bridge between traditional cash management and blockchain rails, which strengthens its appeal for treasury and idle-cash use cases.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 2 of 24 fact categories not yet collected.
  • Fact verifiability: 18 two independent sources, 5 one source, 1 unverified.
  • Oldest fact verification date: 2026-08-29.