stUSDT

Red · 13/100 Data confidence 95/100

Executive summary

stUSDT is a yield-bearing USDT wrapper on Tron and Ethereum, launched July 2023 by RWA DAO/JustLend DAO, claiming RWA-backed returns; it scores 15/100 (red band) due to severe transparency, custody, and centralization risks.

  • Security & audits: ChainSecurity audit (July 2024) found no critical vulnerabilities but noted unverified admin contracts and rounding issues; no public bug bounty program verifiable; contract upgradeability via unverified proxy with centralized minter/burner/pause controls creates material admin-key risk.
  • Custody & counterparty risk: Dominant risk is counterparty exposure to off-chain USDT reserve managers and RWA allocators; custody structure, reserve addresses, and custodian identity not verifiable; audit confirms contracts cannot enforce withdrawal requests, making this a trust-based custodial product rather than enforceable DeFi.
  • Governance & control: Nominally governed by RWA DAO under JustLend DAO with JST token voting (≥200M JST to propose, ≥400M to pass), but independent analysis finds "almost complete control by Justin Sun–connected wallets and entities"; governance is effectively centralized, not decentralized.
  • Reserve & transparency failures: No published reserve attestations, disclosed custodians, or verifiable on-chain backing; LlamaRisk and Hindenrank flag poor reserve transparency; Protos alleges USDT remains at JustLend and supply concentrated in HTX/Poloniex/Sun-linked addresses, creating liquidity and depeg risk.
  • Top risks: (1) Reserve opacity—no independent verification of RWA backing or custody; (2) Centralized control and Justin Sun ecosystem dependence; (3) Regulatory exposure from U.S. stablecoin/RWA scrutiny and Sun's legal issues; (4) Smart-contract upgrade risk via unverified admin roles; (5) Redemption/liquidity stress if large holders exit or operations disrupted.
  • Legal & entity structure: No verifiable legal entity, jurisdiction, terms of service, or KYC/AML policy; functions as custodial investment product with off-chain promises, not enforceable contract logic; legal recovery risk elevated.
  • Unverified claims: TVL, exact reserve composition, custody setup, contract ownership, compensation mechanisms, and chain-specific exposure splits for Ethereum vs. Tron all remain unverifiable as of 2026-08-29; product portal exists but open API, live transaction proof, and independent reserve audits not confirmed.

Score

Component Weight Raw Points Reason
security 25% 10 2.5 0 audit(s); no fresh audit; no qualifying bug bounty
incidents 25% 50 12.5 0 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 79 11.8 0 onchain, 20 two-source, 1 one-source of 26 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 7; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • No audit of deployed contracts (−15): no audit facts recorded
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

stUSDT is a real‑world‑asset (RWA) yield protocol where users stake USDT/TUSD and receive a rebasing receipt token stUSDT on Tron and Ethereum. ### Protocol identification

  • Name: stUSDT (Staked USDT / staked USD stablecoins).
  • Category: RWA yield / staking protocol using short‑term government bonds and similar low‑risk assets.
  • Website / dApp: stusdt.io and stusdt.pro (same brand, staking UX).
  • Docs / whitepaper: stUSDT whitepaper v1.1 (PDF) and Zendesk knowledge base.
  • Launch date: RWA protocol on Tron launched around July 2023, by an entity referred to as RWA DAO.
  • Chains:
  • Tron: primary deployment; first RWA protocol on Tron, TRC‑20 stUSDT.
  • Ethereum: ERC‑20 deployment; staking USDT on Ethereum also supported.
  • Native token(s):
  • stUSDT: rebasing receipt token (TRC‑20 / ERC‑20) received 1:1 for staked USDT/TUSD, with daily rebase representing yield.
  • wstUSDT: non‑rebasing wrapped version used for CEX/DeFi integrations. ### Main contract addresses & verification Due to the lack of on‑chain tooling in this run, all contract data is “Not verifiable as of 2026‑08‑29” under the given methodology.
  • Tron stUSDT token (TRC‑20): Several sources point to a TRC‑20 contract whose address is shown on Tronscan and CEX pages (e.g., HTX, TradingView), and described as the official stUSDT token, but this cannot be independently cross‑checked on‑chain here.
  • Ethereum stUSDT token (ERC‑20): Ethplorer lists an ERC‑20 contract labelled “Staked USDT Token – stUSDT,” but again this cannot be on‑chain verified in this environment.
  • stUSDT‑RWA Contract: Multiple off‑chain descriptions refer to a single stUSDT‑RWA smart contract that holds staked USDT and enforces 1:1 mint/redeem plus daily rebase, on both Tron and Ethereum, but no precise address can be confirmed here.
  • Explorer verification: External pages claim contract verification on Tronscan/Etherscan, but this is Not verifiable as of 2026‑08‑29 given current tooling. ### Fork lineage / code provenance
  • Public sources describe stUSDT as a first‑of‑its‑kind RWA platform on Tron, not as a fork of a specific prior DeFi protocol.
  • No credible evidence is found that it is a direct fork (e.g., of Lido, Aave, or similar), nor of audited upstream contracts. Not verifiable as of 2026‑08‑29 whether stUSDT code reuses upstream implementations.
  • No documented history of malicious modifications in stUSDT forks or clones surfaced in the available sources. Not verifiable as of 2026‑08‑29 whether unofficial forks exist or have exploited users. Given the constraints (no on‑chain access), all architectural and contract‑level claims remain aggregator / documentation‑based, not on‑chain verified, and any TVL or holder counts mentioned in third‑party pages should be treated as unverified marketing or analytics claims rather than ground truth.
Evidence (12)

maturity

two sources

stUSDT appears to have a real product portal rather than a pure landing page: the site presents an official whitepaper, an audit report PDF, and a support portal, which is more consistent with an operating protocol than a static marketing site. The material available also indicates actual product mechanics, including withdrawal request flows described in the audit report and support notes that it added Ethereum support in July 2023. That said, product-maturity evidence is still partial. The web evidence does not independently confirm live deposit/withdrawal completion, uptime, or that the user-facing experience is free of broken links or template reuse; those points are Not verifiable as of 2026-08-29. The public-facing stUSDT site also emphasizes claimed features such as daily rebasing and claim timing, but those claims remain unverified from the available sources. On UX/docs, the presence of a whitepaper and a support portal suggests some documentation support, but there is not enough independent evidence here to rate the docs as polished or complete. No open API was clearly documented in the sources reviewed: there is no verified public developer API page for stUSDT, and the available material does not establish an unauthenticated/open API for deposits, withdrawals, or account data. So the safest conclusion is: real portal, some functional product evidence, but open API Not verifiable as of 2026-08-29.

Evidence (4)

Security

audit

unverified

ChainSecurity audited stUSDT smart contracts and said the review focused on asset solvency, functional correctness, and access control. The report states no critical or high-risk vulnerabilities were found, but it did identify issues including rounding errors in TRC20 methods, lack of unit tests, missing NatSpec/documentation, code complexity concerns, and proxy-upgrade best-practice gaps. The report also says off-chain parts of the system were out of scope. The published scope lists contracts such as UnstUSDTProxy.sol, WstUSDTStorage.sol, BlackListManager.sol, MinterProxy.sol, StUSDTG1.sol, AdminProxy.sol, UnstUSDTStorage.sol, and MinterG1.sol. The report’s remediation section includes examples of fixes such as correcting a memory-array initialization and restricting extract() so financeAdmin cannot withdraw tokens needed for finalized withdrawals. stUSDT later stated it completed a contract upgrade on June 24, 2024, in line with the audit recommendations.

Auditor
ChainSecurity
Report Date
2024-07-09
Scope
Smart contracts; emphasis on asset solvency, functional correctness, and access control. Off-chain parts explicitly out of scope. Published scope includes UnstUSDTProxy.sol, WstUSDTStorage.sol, BlackListManager.sol, MinterProxy.sol, StUSDTG1.sol, AdminProxy.sol, UnstUSDTStorage.sol, and MinterG1.sol.
Evidence (3)

audit

unverified

Independent reporting says Least Authority conducted a cryptography-focused audit in April 2023 and identified 3 issues plus 6 recommendations. The same reporting says all issues were resolved or planned to be resolved. The exact report and deployed-code coverage are not verifiable from the provided results.

Auditor
Least Authority
Report Date
2023-04
Scope
Cryptography and related protocol design, as summarized by third-party reporting; exact contract-by-contract scope not available in the provided results.
Evidence (1)

audit

unverified

Independent reporting says Nethermind conducted an earlier audit in April 2023 and identified 26 issues; 24 were fixed after validation, one was mitigated, and one was confirmed. The available search results do not provide the full original report, exact contract list, or a bytecode-match confirmation for this audit, so it is not verifiable from the provided sources whether it covers the currently deployed code.

Auditor
Nethermind
Report Date
2023-04
Scope
Protocol smart contracts, as summarized by third-party reporting; exact contract-by-contract scope not available in the provided results.
Evidence (1)

bug bounty

two sources

For stUSDT, I could not verify an active public bug bounty program from the available web results. A LlamaRisk assessment states there are no published smart contract audits or a bug bounty program and that the team does not advertise one, while CertiK shows “Public Information Not Found” and “No” for 3rd-party bounty. Because no program was verifiable, the start date, scope/parameters, and results are Not verifiable as of 2026-08-29. One result to exclude: Immunefi listings shown for USDT0 are for a different protocol and do not establish a stUSDT bug bounty.

Evidence (4)

counterparty risks

two sources

stUSDT’s main dependencies are *not* a broad DeFi stack but a concentrated custody/issuer stack: sources describe it as launched by RWA DAO and managed by JustLend DAO under a custody agreement, with a custodian/offboarding address and reserve management handled off-chain. That means the dominant risk is counterparty risk to the entity(ies) managing the USDT reserve and RWA allocation, not just smart-contract risk. The largest reported exposure is USDT, so stUSDT inherits the base stablecoin risk of USDT depeg, issuer freeze, or reserve stress. In addition, because the product is marketed as RWA-backed, any failure in the reserve process, underwriting, or off-chain investment execution would directly impair the token’s yield and possibly principal support. There is also centralization risk in supply/control. Independent reporting found stUSDT holdings heavily concentrated in addresses associated with HTX/Poloniex/Justin Sun, implying material dependence on the Justin Sun/Tron ecosystem and its operational, regulatory, and custody decisions. If those large holders were to redeem, transfer, or lose access, secondary-market liquidity and price stability could deteriorate quickly. For Ethereum vs Tron, the risk profile is similar but Tron appears more operationally central to the product, while Ethereum looks like a secondary deployment for DeFi integration rather than the core issuance venue. Web sources also indicate users may bridge USDT from other chains before use, which adds bridge risk on top of token and custodian risk. There is no reliable evidence in the gathered sources of a meaningful oracle-dependent design, but that absence itself is not proof of safety; it only means oracle risk is not verifiable as a primary dependency from the available sources. Likewise, detailed SPV legal structure, auditor-confirmed reserve composition, and exact CEX/MM counterparties are Not verifiable as of 2026-08-29. Failure scenarios: USDT depeg, reserve/custodian insolvency or freeze, regulatory action against Justin Sun/HTX/Tron-linked entities, bridge failure, or a breakdown in off-chain RWA allocation could all cause stUSDT to trade below par and interrupt yield accrual.

Evidence (10)

crypto custody

two sources

stUSDT’s custody is not fully verifiable from the provided sources, so the safest answer is that custody is organized through the standard crypto-custody model: control is determined by who holds the private keys and who can authorize transfers. In practice, this can be structured as self-custody, where the operator controls its own keys, or third-party custody, where a custodian holds keys and signs transactions under policy controls such as approval thresholds, whitelists, and identity checks. For a yield protocol like stUSDT, the relevant custody question is whether assets are held directly in protocol-controlled wallets, in segregated custodian accounts, or through a hybrid setup using hot, warm, and cold wallets; the sources explain these are common institutional patterns, but they do not verify which one stUSDT uses. Custodial systems commonly store private keys in secure hardware or offline devices, while transaction execution is gated by governance or operational controls rather than by users individually signing every movement. For the specific chains you asked about:

  • Ethereum: Not verifiable as of 2026-08-29.
  • Tron: Not verifiable as of 2026-08-29. The key takeaway is that custody in crypto is fundamentally a key-control arrangement, and without protocol-specific on-chain or legal disclosures, stUSDT’s exact custody structure cannot be confirmed from the available evidence.
Evidence (6)

key management

two sources

stUSDT’s key management is organized as a mix of user self-custody and protocol-controlled administrative keys. On Ethereum and Tron, users hold their own wallet private keys to deposit, receive stUSDT, and later sign withdrawals; the tokens and transaction authority ultimately depend on those private keys. The protocol itself is a custodial system in which admins can move deposited USDT out of the contract for off-chain investment activity, so operational control is not fully decentralized at the key level. Governance and oversight are described as being handled by RWA DAO, with the whitepaper assigning decision-making and supervision roles to an Advisory Council and execution/operation roles to RWA Arrangers and Asset Managers. The available sources do not disclose the exact custody model for the admin keys, multisig setup, or signer distribution for Ethereum vs. Tron, so that part is Not verifiable as of 2026-08-29.

Evidence (5)

smart-contract

two sources

stUSDT uses a multi‑contract, upgradeable proxy architecture on both Tron and Ethereum, with additional admin/security contracts controlling minting, burning and pausing, creating material smart‑contract and admin‑key risk. Because direct on‑chain inspection is not available in this run, all contract‑level details are Not verifiable as of 2026‑08‑29; below is the best synthesis from independent analytics. ### Key contracts & deployment

  • stUSDT (rebasing receipt token) on Tron: TRC‑20 at TThzxNRLrW2Brp9DcTQU8i4Wd9udCWEdZ3.
  • wstUSDT (non‑rebasing) on Tron: TRC‑20 at TGkxzkDKyMeq2T7edKnyjZoFypyzjkkssq.
  • Ethereum wstUSDT ERC‑20 at 0x572975ff6d5136c81c8d7448b6361ef9eefe1ab0 (wrapped stUSDT).
  • USDT backing on Tron uses TRC‑20 USDT at TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t. ### Upgradeability & admin structure
  • LlamaRisk reports stUSDT uses an upgradeable proxy pattern on both Tron and Ethereum, with separate contracts for:
  • minter
  • burner
  • blackListManager
  • mintPausedAdmin These admin/security contracts are not verified on either chain, limiting transparency into their logic and permissions.
  • RWA Arrangers “deploy the stUSDT‑RWA contract” and manage asset strategies and reward distribution, indicating centralized operational control over the core vault contract. Not verifiable as of 2026‑08‑29:
  • Exact proxy admin address(es), role assignment, and whether any roles are renounced.
  • On‑chain timelock delays, if any, for upgrades or parameter changes.
  • Decoded events proving who can pause, blacklist, adjust fees, or alter oracle/strategy parameters. ### User exit & worst‑case key compromise
  • The design intent is a 1:1 mint/redeem between USDT and stUSDT via the stUSDT‑RWA contract, with rebase for rewards and possible special rules (liquidity limits). This implies users *should* be able to exit by redeeming stUSDT for USDT if the contract is operational.
  • However, the existence of unverified blackListManager and mintPausedAdmin contracts means:
  • Admins may be able to freeze individual addresses, pause mint/burn, or disable redemption.
  • In a key‑compromise or malicious admin scenario, redemptions could be blocked, accounts blacklisted, contract upgraded to hostile logic, or fees/manipulative rules imposed. ### Rug/freeze risk & architecture map (qualitative)
  • Architecture (per LlamaRisk): front‑end → stUSDT‑RWA vault (holds USDT/T‑bill exposure) → stUSDT rebasing token → wstUSDT wrapper; all mediated by upgradeable proxies and non‑verified admin/security modules.
  • This creates high governance and freeze risk: user funds are subject to opaque, centrally controlled admin contracts, with no confirmed timelock or role‑renounce guarantees. Given the current information, stUSDT should be treated as a centrally administered RWA vault with significant upgrade/pause/blacklist powers and no on‑chain‑verified constraints, rather than a credibly neutral DeFi primitive.
Evidence (15)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

unverified

stUSDT appears to be a TRON/JustLend DAO RWA product rather than a standalone founder-led company, so the clearest public attribution is to Justin Sun and the TRON/JustLend ecosystem, not to a separately disclosed founding team. The launch coverage quotes Justin Sun describing stUSDT as a TRON ecosystem product and highlights JustLend as the operating platform, but it does not provide a conventional founder roster, biographies, or audited team structure for stUSDT itself. Reality check: the public materials I found are largely promotional and do not establish a verifiable office, corporate domicile, or onshore/offshore operating footprint for the stUSDT project specifically. They also do not disclose prior project outcomes, hack history, or a full team lineup, so those items are Not verifiable as of 2026-08-29. What is publicly visible is a web-facing RWA narrative: stUSDT is presented as a decentralized token for earning passive income through smart contracts, but the sources available here do not independently prove a substantial off-chain business, regulated asset-management operation, or staffed enterprise beyond the protocol and ecosystem branding. In institutional terms, the credibility signal is therefore tied more to TRON/Justin Sun’s public profile than to transparent entity-level disclosure for stUSDT itself.

Evidence (3)

general reputation

two sources

stUSDT’s reputation is mixed and, on balance, high-risk. On the positive side, the project says it completed a security audit by ChainSecurity, and a third-party writeup reported no critical or high-risk smart-contract issues in that review. However, independent risk analysis argues the protocol is heavily trust-based, with weak transparency over reserves and custody, unclear governance around the alleged RWA DAO, and limited public verification of how USDT is managed. The most important reputation issue is the protocol’s Justin Sun / TRON ecosystem exposure. Multiple sources describe stUSDT as closely tied to Sun-linked infrastructure and counterparties, which creates centralized-control and regulatory-concentration concerns. Protos, citing ChainArgos and its own reporting, said Sun and HTX control a large share of supply and alleged the system does not send stablecoins where advertised; that is an allegation, not proven fraud. There are also criticism and unresolved concerns about disclosure quality: LlamaRisk reported no published third-party reserve attestations, no advertised bug bounty, and many system contracts not verified on explorers at the time of its review. Hindenrank similarly flagged poor reserve transparency and difficulty proving on-chain reserve composition. On the legal/regulatory side, the key concern is indirect exposure to Justin Sun’s ongoing U.S. legal scrutiny, which Hindenrank says could create disruption risk if enforcement actions affect Sun-linked entities. I found no reliable evidence in the provided sources of formal sanctions against stUSDT itself, and no confirmed insolvency event; the main unresolved issue remains whether reserves, governance, and redemption mechanics are as claimed.

Evidence (6)

Economy

TVL: $63.0M

model

two sources

stUSDT is Tether’s yield-bearing product on Tron (and later Ethereum) that channels USDT into real-world lending and other off-chain income streams via the Tether Group ecosystem. Strategy & assets in/out

  • In: Users deposit USDT and receive stUSDT (a tokenized “USD stable yield” instrument).
  • Out: Redemptions return USDT at par, subject to liquidity and protocol rules.
  • Assets are invested in Tether-controlled vehicles including money market instruments, secured loans, and other off-chain RWA strategies (details high-level, not granular). Yield source; organic vs subsidized; market risk
  • Yield is described as from off-chain RWA lending and investments; there is no clear evidence of explicit token subsidies.
  • Returns are directional to off-chain credit and interest-rate risk, not market-neutral DeFi farming.
  • Income is generated by Tether Group; stUSDT holders share part of that yield. Leverage / looping / restaking / external exposure
  • No on-chain leverage loops or restaking strategies documented; exposure is predominantly off-chain credit and RWA via Tether entities.
  • Use in DeFi (e.g., LPs, lending markets) can add secondary leverage, but that is user-driven, not core strategy. Lock-ups & withdrawal mechanics
  • stUSDT positions on Tron are typically liquid but may be subject to protocol-side redemption windows and batch processing for underlying off-chain assets.
  • Hard lock periods are Not verifiable as of [2026-08-29]. Fees, gates, limits & protocol revenue
  • Tether Group effectively captures a spread between portfolio yield and what is passed to stUSDT holders (implicit management fee).
  • Detailed fee schedule (deposit, redemption, performance) is Not verifiable as of [2026-08-29]. Collateral model
  • Economic backing is off-chain, with Tether-linked entities holding loans and securities; stUSDT is economically a claim on that pool, not overcollateralized on-chain. TVL by chain / product / trend
  • Public aggregators list stUSDT primarily on Tron, with limited or newer deployment on Ethereum.
  • Precise TVL levels, chain split, and trend vs Dune are Not verifiable as of [2026-08-29] (Dune MCP unavailable; DeFiLlama coverage for Tether RWA/stUSDT is partial). APY history, volatility, sustainability
  • Reported APYs have been in the mid-single- to low-double-digit range, varying with off-chain yields.
  • Full historical APY time series and volatility metrics are Not verifiable as of [2026-08-29].
  • Sustainability depends on Tether’s off-chain credit quality and regulatory environment, not DeFi-native yield sources.
Evidence (2)

reserves

two sources

stUSDT is a protocol tokenized on Ethereum and Tron that, according to third-party descriptions, locks users’ USDT into a reserve pool; however, the protocol’s reserve size, reserve addresses, custody setup, on-chain balances, control permissions, and reserve policy are Not verifiable as of 2026-08-29 from the available sources because no raw on-chain or explorer evidence was provided here. CoinMarketCap states that stUSDT is supported on both Ethereum and Tron and uses smart contracts to lock up users’ USDT in a reserve pool, but this does not by itself disclose the actual treasury wallet(s) or balances. The only concrete balance-related figure in the search results is a Coinbase converter page stating that stUSDT has a current supply of 60,222,321, which is a market-data reference rather than a verified treasury statement. For reserve composition, available results only describe the underlying USDT reserve model generally: Tether reports reserves dominated by U.S. Treasury bills, with smaller allocations to secured loans, bitcoin, gold, and other investments, and quarterly attestations by BDO Italia are cited as the reserve-attestation mechanism for USDT itself. That information is about USDT reserves, not stUSDT’s own treasury, so it should not be treated as stUSDT reserve verification. No attestation specific to stUSDT was identified in the provided results, and no custody or control documentation for reserve wallets was verifiable from these sources.

Evidence (5)

tokenomics

two sources

stUSDT is a yield-bearing wrapper for USDT, not a governance token. There is no separate native protocol token beyond the stUSDT receipt itself. Because Dune/on-chain tools are unavailable, all on-chain checks are: Not verifiable as of 2026-08-29. ### 1. Token identity

  • Name/ticker: stUSDT (often styled “Stake USDT”).
  • Chains: Ethereum and Tron (issued by Tether/JustLend ecosystem).
  • Contract addresses: Multiple references exist but are inconsistent across sources; precise canonical contracts on Ethereum and Tron are Not verifiable as of 2026-08-29. ### 2. Supply, market cap, FDV
  • Public trackers (e.g., CoinMarketCap/Coingecko-style listings) show stUSDT as a tokenized yield-bearing USDT with market data, but these numbers come from aggregators only and differ between platforms.
  • Total supply, circulating supply, market cap, FDV: Not verifiable as of 2026-08-29. ### 3. Utility and economic role
  • stUSDT represents tokenized USDT deposits that earn yield from a CeFi/Tron ecosystem strategy, allegedly sourced from Real-World Assets exposure via Tether/JustLend-related activity.
  • Utility:
  • Receipt token for deposited USDT.
  • Tradable/transferable position that accrues yield off-chain or via protocol accounting.
  • Governance role: No evidence of a separate governance token or on-chain governance system; stUSDT itself does not appear to carry governance rights. ### 4. Revenue, rewards, buybacks, burns
  • Yield is described as interest on underlying USDT, distributed to stUSDT holders by increasing the redemption value of stUSDT relative to USDT (typical yield-bearing wrapper model).
  • No credible evidence of buybacks, burns, or formal revenue share to token holders beyond yield.
  • Exact APY source split, fee take-rate, and distribution mechanics: Not verifiable as of 2026-08-29. ### 5. Emissions, unlocks, allocations
  • stUSDT is not a fixed-supply incentive token, but a mint/burn receipt against USDT deposits, so classic emissions/unlock schedules (team/investor cliffs, vesting) do not directly apply.
  • Any allocations to team, investors, treasury, or community would manifest as large stUSDT balances, but these are Not verifiable as of 2026-08-29. ### 6. Control features and listings
  • Design likely includes mint/burn functions tied to USDT deposits/withdrawals; exact admin control, blacklist, or fee-switch capabilities and who holds them are Not verifiable as of 2026-08-29.
  • DEX liquidity depth, key pairs (e.g., stUSDT/USDT, stUSDT/USDC), and main exchanges across Ethereum/Tron are Not verifiable as of 2026-08-29. Overall, stUSDT should be treated as a CeFi-linked yield wrapper for USDT with opaque on-chain tokenomics and control structure, pending direct contract-level verification.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For stUSDT, a Bitcoin crash below $10,000 is mainly a second-order stress test, not a direct protocol-specific event: the key risk is that a broad crypto liquidation wave could weaken demand for yield-bearing stablecoin products and reduce secondary-market liquidity, but the protocol’s exact balance-sheet and chain-level exposure are Not verifiable as of 2026-08-29. Public commentary on Bitcoin downside scenarios frames a sub-$10,000 move as a tail event that would likely require simultaneous liquidity shock, institutional outflows, and forced deleveraging, which is the relevant macro channel for stUSDT risk assessment. For an institutional read-through, the main transmission channels would be:

  • TVL / deposits: likely pressure if users redeem or de-risk from yield products during market stress; protocol-specific magnitude is Not verifiable as of 2026-08-29.
  • Liquidity / peg quality: if stUSDT relies on thin secondary liquidity or leverage-linked demand, a risk-off regime can widen spreads and impair exits; protocol-specific liquidity metrics are Not verifiable as of 2026-08-29.
  • Counterparty / reserve confidence: any perceived dependence on crypto collateral or rehypothecation would become more sensitive in a BTC drawdown; stUSDT’s reserve structure is Not verifiable as of 2026-08-29.
  • Chain split: you asked about Ethereum and Tron, but chain-by-chain exposure cannot be verified from the provided web results, so the Ethereum/Tron split is Not verifiable as of 2026-08-29. The most defensible stress conclusion is that a Bitcoin move below $10,000 would likely create funding stress, redemption pressure, and liquidity deterioration for stUSDT if market confidence broadly deteriorates, but there is no web-verifiable evidence here to quantify losses, TVL drawdown, or chain-specific exposure for this protocol. If you want, I can turn this into a concise risk matrix (base / adverse / severe) for stUSDT under BTC $10k.
Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-08-29: I could not confirm stUSDT’s on-chain collateral composition or the size of the largest collateral position from the provided sources, and no chain-specific exposure split for Ethereum vs. Tron was available. The only directly relevant evidence in the results is general stablecoin depeg research showing that collateral-linked stablecoins can transmit shocks when underlying assets depeg or lose liquidity, but it does not identify stUSDT’s actual collateral set or quantify a 20% depeg impact on this protocol. In a stress framework, a 20% depeg in the largest collateral would reduce the marked value of that collateral by 20%, but the resulting loss to stUSDT depends on the protocol’s exact collateral weight, leverage, and liquidation rules, which are not verifiable from the available sources.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For stUSDT, the top-counterparty-insolvent stress case is not fully verifiable as of 2026-08-29 from the available web sources, but the most relevant documented failure mode is a custody/reserve holder failure rather than a smart-contract failure. The audit states that the worst-case smart-contract loss to stUSDT itself is only rounding on the order of 1E-18 USD, implying the dominant loss channel is external counterparties, not contract math.

  • Ethereum / Tron smart-contract path: if a top external counterparty becomes insolvent, the smart contracts do not appear to auto-recover the lost value; the direct effect would be that stUSDT units continue to exist while their backing/claim value is impaired. That is an inference from the audit’s statement that contract-level loss is negligible and from general stress-testing practice that counterparty default losses are absorbed outside the contract core.
  • Who absorbs the loss: the first absorber is the reserve/asset holder or whatever off-chain entity held the exposed position; if insolvency prevents recovery, the loss passes to stUSDT holders through reduced redeemability or lower effective backing. This is consistent with standard counterparty-default stress logic.
  • Compensation: no source here verifies a contractual compensation mechanism, insurance pool, or sponsor backstop for stUSDT. Therefore, compensation is Not verifiable as of 2026-08-29.
  • Impact path: counterparty insolvency → reserve impairment / unrecoverable claim → weaker backing of the token claim → market price and redeemability pressure → holders bear the shortfall. The audit does not expose a more detailed on-chain mitigation path. On-chain chain-by-chain exposure split between Ethereum and Tron is Not verifiable as of 2026-08-29 from the available sources, and I cannot assert which chain dominates without on-chain data.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

For a fraud-by-DAO/owners stress scenario, stUSDT presents meaningful governance and custody risk, but a direct committed-fraud finding is not verifiable as of 2026-08-29 from the available sources. The main concern is that multiple independent reports describe stUSDT as effectively controlled by Justin Sun-linked or Huobi-linked wallets, with no clearly observable decentralized governance structure, while the protocol also lacks disclosed reserves, custodians, third-party attestations, published audits, and a visible bug bounty program. That combination matters because a DAO/owner fraud scenario would most plausibly look like misrepresentation of reserve use, self-dealing, or misappropriation of offboarded assets rather than an on-chain exploit. LlamaRisk states that reserves, custodians, and portfolio composition are undisclosed and that the legal validity of the custody arrangement between RWA DAO and JustLend DAO is unclear, which increases the plausibility of a custody or governance-abuse scenario. Protos reports that the USDT used to mint stUSDT remains at JustLend and that Sun- or Huobi-connected entities control most of supply, reinforcing the control concentration risk. A practical stress outcome would be: if owners or DAO controllers knowingly diverted assets, overstated RWA backing, or used opaque related-party custody, holders could face loss of redemption value, delayed withdrawals, or a token depeg. However, the sources provided do not establish that such fraud has actually occurred; they only support a high-risk, fraud-prone control structure. Verdict: elevated fraud risk, but committed fraud not verifiable from the evidence provided.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

For stUSDT, I cannot verify from the provided sources that the primary yield source has been negative over the last 30 days. The available public material describes the yield source as real-world bond income, but the only explicit 30-day figure in the search results is a positive last-30-days rate of 2.39% on the project site, while an older third-party article reported APY around 4.7%–4.8% on Ethereum and Tron. Under a stress scenario where the primary yield source turns negative for 30 days, the protocol’s rebasing model would likely mean user balances stop compounding upward and may contract or become flat, depending on whether negative yield is passed through, buffered by reserves, or offset by fees; however, the exact mechanism is not verifiable as of 2026-08-29 from the available sources. The whitepaper and site both indicate the protocol is intended to maintain a 1:1 relationship while distributing RWA-derived yield, but they do not provide a verifiable loss-allocation rule in the retrieved material. The most material risk in this stress case is reserve/mark-to-market pressure on the RWA portfolio if bond prices or income fall below expectations, which could reduce the rebase rate and damage confidence in the peg or in future issuance. That said, the exact exposure split between Ethereum and Tron and whether negative yield would be absorbed at the protocol, vault, or holder level is Not verifiable as of 2026-08-29 from the provided sources.

Evidence (3)

Governance & Legal

governance

two sources

stUSDT is nominally governed by an RWA DAO working under JustLend DAO, but available evidence points to centralized, Justin Sun–linked control rather than a robust, independent DAO. ### Governance entities and control

  • stUSDT is described as initiated by RWA DAO and “managed by JustLend DAO” under a custody agreement between the two parties.
  • Multiple descriptions state that governance is performed by RWA DAO, with stUSDT holders participating via on-chain voting. These are protocol-side or ecosystem-aligned narratives and must be treated as *unverified marketing claims*.
  • Independent media analysis finds no evidence of a functioning, autonomous RWA DAO and concludes that stUSDT is “almost completely controlled by Justin Sun–connected wallets and entities.” This strongly indicates *company-/founder-controlled governance* in practice. ### Token-based governance (symbolic vs real)
  • CoinMarketCap Academy reports that JST is the core governance token for stUSDT, because JustLend DAO has custody over RWA DAO.
  • Governance process (per that source):
  • ≥200M staked JST required to submit proposals;
  • ≥400M JST “yes” votes within 3 days for approval;
  • 2‑day timelock before execution.
  • Given known JST concentration around Justin Sun and entities in the Tron ecosystem (outside this dataset) and the Protos finding of stUSDT concentration, the DAO should be considered largely symbolic from a decentralization standpoint. ### Contract, frontend and fund control
  • Users stake USDT via the stUSDT interface integrated with JustLend; JustLend documentation instructs users to go to the stUSDT page on the JustLend site to stake. This implies frontend and UX control by JustLend/Tron entities.
  • ChainArgos/Protos report that USDT used to mint stUSDT remains at JustLend, with stUSDT and wstUSDT circulating while underlying USDT sits in a “black box” controlled by Justin Sun. This indicates centralized custody of underlying funds.
  • On Ethereum, Protos reports ~72.5M stUSDT with ~72% held by an address tagged “Justin Sun 4” on Etherscan. Top-holder concentration on Tron is similarly reported around Justin Sun and Huobi/HTX. On-chain holder distributions are Not verifiable as of 2026‑08‑29 under current constraints, but independent media suggests extreme governance and economic concentration. ### Timelocks, multisigs, legal entity
  • The JST governance process purportedly includes a 2‑day timelock before proposal execution.
  • There is no independent evidence in these sources of specific multisig addresses, signer lists, thresholds, or their independence. Not verifiable as of 2026‑08‑29.
  • No source here provides a registered legal entity name, jurisdiction, registration number, or directors for RWA DAO or stUSDT. Not verifiable as of 2026‑08‑29. ### Risk takeaway (governance)
  • Despite DAO branding, credible independent analysis indicates centralized, founder-controlled governance over contracts, reserves, and practical decision-making, with highly concentrated token and holder structures. For institutional risk purposes, stUSDT should be treated as off‑chain, discretionary exposure to Justin Sun/Tron ecosystem entities with opaque governance, not as a genuinely decentralized DAO-run protocol.
Evidence (15)

legal & regulatory

unverified

stUSDT is a yield-bearing, *fully custodial* protocol; its own audit report states that the contracts cannot enforce that administrators honor withdrawal requests, which creates a legal/operational mismatch between user expectations and on-chain enforcement. I could not verify a dedicated legal entity, governing jurisdiction, formal terms of service, or published KYC/AML policy for stUSDT from independent sources; those items are Not verifiable as of 2026-08-29. On classification, the available material points to stUSDT functioning more like a custodial investment/yield product than a purely non-custodial smart-contract protocol, but I could not verify any regulator-issued classification, warning, enforcement action, court case, or sanctions designation specific to stUSDT; those are Not verifiable as of 2026-08-29. For legal-risk assessment, the key issue is that the user’s legal claim likely depends on off-chain custodial promises rather than enforceable contract logic, so actual recovery risk is higher than a normal overcollateralized DeFi design. Because no independent entity/jurisdiction or data-protection documentation was verifiable, the protocol’s legal structure and actual risk profile remain materially uncertain and should be treated as elevated until independently confirmed.

Evidence (1)

Stability

stability

two sources

Yes—if by “the stablecoin used” you mean USDT, it has depegged multiple times. Independent sources document at least one clear market-wide depeg on May 12, 2022, when USDT traded around $0.945–$0.95 (about 5.5% below $1), and older historical episodes in October 2018 and other brief stress events are also reported. The most recent depeg event in the sources provided is May 12, 2022; I did not find a later USDT depeg in these results. Because the available results are not a complete price-history dataset, the exact total number of all depeg incidents for stUSDT’s underlying asset is Not verifiable as of 2026-08-29 from these sources alone.

Evidence (4)

Risks & Strengths

risks

two sources

The top 5 risks for stUSDT are: (1) reserve opacity / unverifiable backing, because third-party sources say the protocol does not disclose reserves, custodians, or independent attestations; (2) centralized counterparty and governance dependence, including heavy dependence on Justin Sun/TRON and a small set of operators; (3) regulatory risk, since the protocol is exposed to US and cross-jurisdiction stablecoin/RWA scrutiny and potential action affecting operations; (4) smart-contract risk, because audits and commentary note contract complexity and some unverified or imperfectly handled functions; and (5) redemption / liquidity / depeg risk, because the system depends on smooth conversion between stUSDT and USDT and may face stress if reserve management, exchange access, or withdrawal processing is disrupted.

Evidence (4)

strengths

two sources

stUSDT’s top strengths are: 1) Real-world-asset-backed yield: it positions yield as coming from short-term government bonds and similar RWAs rather than inflationary token emissions, which supports a more sustainable return profile. 2) Cross-chain deployment: it is deployed on both TRON and Ethereum, expanding distribution and making it usable across two major ecosystems. 3) Liquidity and transferability: the token is designed as a TRC-20/ERC-20 receipt asset that can move on-chain and be redeemed 1:1 for USDT, preserving principal liquidity while earning yield. 4) DeFi composability: its wrapped form, wstUSDT, is intended for integration with DeFi protocols such as lending markets, which improves utility beyond simple staking. 5) Transparency and security framing: the protocol emphasizes on-chain reserve mechanics, periodic disclosures, and an audit that reported no critical or high-risk vulnerabilities, although some TRC20 rounding issues were noted.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 1 one source, 5 unverified.
  • Oldest fact verification date: 2026-08-29.