Engineer working on zero-knowledge proof verification code, mathematical notation on paper beside laptop, technical study session in bright apartment.
Protocols

Transparency and Attestation Trustworthiness

Critically examines the quality and completeness of the protocol's proof-of-reserves and attestation reports. Analyzes the gap between third-party attestation and real-time, on-chain proof of all exchange positions and custodian balances.
introduction
VERIFICATION BLIND SPOTS

The Attestation Gap

The critical difference between what Ethena's attestations prove and what they do not.

Ethena's transparency model relies on third-party attestation reports to assure the public that USDe is fully backed and that the delta-neutral hedge is in place. These attestations, typically provided by an accounting firm, confirm that the total value of assets held at custodians and exchanges equals or exceeds the circulating supply of USDe at a specific point in time. However, an attestation is not a real-time, on-chain proof of reserves. It represents a periodic, point-in-time snapshot that leaves a significant verification gap between reporting intervals.

The core of the attestation gap lies in what is not continuously verifiable. An attestor can confirm the existence of assets in a custodian account but cannot provide cryptographic proof that those assets are unencumbered or that the corresponding short perpetual swap positions are open and correctly sized on centralized exchanges. The protocol's health depends on the simultaneous, continuous validity of both sides of the basis trade. An attestation report that validates only the asset side of the equation, or does so on a delayed basis, creates a window where the backing could become impaired without an external observer's knowledge. This is not a failure of the attestor but a structural limitation of the off-chain components in Ethena's design.

For due-diligence teams and institutional integrators, the operational question is not whether an attestation is 'good' or 'bad,' but what specific risks it does not mitigate. The gap introduces a dependency on the integrity of the Ethena Operations Account and multi-sig signers to honestly manage positions between attestation snapshots. A rigorous risk assessment must model the maximum potential divergence between the last known attested state and the real-time state, factoring in the frequency of attestations, the liquidity of backing assets, and the speed at which a hedge could be unwound. Chainscore Labs helps protocol architects and risk teams quantify this trust window and design complementary monitoring systems that can detect anomalies between official attestation cycles.

VERIFICATION GAPS AND OPERATIONAL BLIND SPOTS

Attestation Process at a Glance

Evaluates the trustworthiness and completeness of third-party attestations against the protocol's real-time, on-chain verification capabilities for exchange positions and custodian balances.

AreaWhat changes or is at riskWho is affectedAction

Attestation Frequency

Reports are periodic, not continuous or real-time. A solvency gap can emerge between attestation cycles.

Risk teams, institutional integrators, auditors

Verify the maximum time window between attestations and model the worst-case exposure during that gap.

Data Completeness

Attestations may not cover all exchange sub-accounts, pending settlements, or off-exchange collateral in transit.

Due-diligence teams, treasury managers

Reconcile attested balances against known exchange venue lists and publicly disclosed custodian addresses.

Liability Verification

The process confirms asset existence but may not independently verify the full scope of protocol liabilities (e.g., total USDe supply across all chains).

Protocol architects, risk modelers

Cross-reference attested assets with on-chain total supply of USDe and sUSDe to independently confirm over-collateralization.

Exchange Position Proof

Attestations often rely on exchange API data or signed letters, not on-chain proof of the perpetual swap positions that constitute the hedge.

Hedging engineers, security auditors

Demand granular breakdowns of open short positions by venue, including notional value and liquidation prices, not just asset balances.

Custodian Control Assurance

Reports confirm assets are held at a custodian but do not guarantee the protocol's exclusive, timelocked control over those assets.

Custody risk teams, governance delegates

Request attestation language that specifies control mechanisms, withdrawal policies, and multi-signature configurations for custodian accounts.

Off-Exchange Settlement Exposure

Assets held in OES solutions like Copper or Ceffu may be attested to but their legal and operational segregation during an exchange failure is not verified.

Legal and compliance teams, systemic risk analysts

Seek legal opinions on asset treatment in OES provider bankruptcy and verify attestation scope includes these specific structures.

Oracle and Valuation Integrity

The value of attested assets depends on the pricing oracles used. A stale or manipulated oracle can misrepresent the true health of the backing.

Oracle integrators, DeFi risk managers

Identify the price sources used in the attestation report and independently verify them against robust, manipulation-resistant oracle networks.

technical-mechanism
VERIFICATION ARCHITECTURE

How the Attestation Process Works

A technical breakdown of Ethena's proof-of-reserves mechanism, its reliance on custodial APIs, and the resulting trust boundaries.

Ethena's attestation process is designed to provide off-chain assurance that the total supply of USDe is fully backed by assets held in custody. The core mechanism relies on third-party custodians and off-exchange settlement (OES) providers—primarily Copper and Ceffu—who generate cryptographically signed attestation reports. These reports detail the assets held in segregated accounts, which are then aggregated and published by Ethena to demonstrate that the custodied collateral meets or exceeds the circulating USDe supply.

The trustworthiness of this process is fundamentally limited by its reliance on API-driven data from centralized custodians rather than on-chain proof. An attestation is a point-in-time snapshot, not a real-time verifiable reserve. The process verifies that assets exist within a custodial environment, but it cannot independently prove that those assets are unencumbered, that the custodian's internal ledgers are accurate, or that the same assets are not simultaneously pledged to multiple parties. This creates a verification gap between what is attested and what is cryptographically proven, a critical distinction for risk teams evaluating the protocol's solvency guarantees.

For operators and integrators, the attestation process introduces a dependency on the operational integrity and legal solvency of the OES providers. A failure in the custodian's reporting API, a compromise of their signing keys, or a misrepresentation in their internal systems would directly corrupt the attestation's validity. Teams building on USDe should model this as a custodial trust assumption, not a trustless one, and implement their own off-chain monitoring of attestation frequency, asset composition drift, and custodian operational status. Chainscore Labs can assist with independent verification of attestation logic and integration of multi-source monitoring to reduce reliance on a single reporting pipeline.

ATTESTATION GAPS AND VERIFICATION BURDENS

Stakeholder Impact Analysis

Due-Diligence and Solvency Verification

Institutional integrators cannot rely solely on attestation reports for real-time solvency verification. The reports provide a point-in-time snapshot of custodian balances and exchange positions, but do not constitute continuous, on-chain proof of all backing assets.

Action Items:

  • Establish an independent verification process that cross-references attestation reports with on-chain custodian wallet activity and exchange proof-of-reserves.
  • Model the latency risk between the attestation timestamp and the current state of the hedge; a significant market move can invalidate the solvency picture within minutes.
  • Demand contractual clarity on the frequency and scope of future attestations, specifically whether they will cover all exchange positions or only a subset.

Chainscore Labs can design a bespoke monitoring framework that augments periodic attestations with real-time heuristic checks on custodian and exchange wallets to reduce the blind window between reports.

blind-spots
VERIFICATION GAPS

Key Blind Spots in the Attestation Process

Third-party attestations provide a point-in-time snapshot, but critical blind spots remain between what is attested and what is verifiable on-chain in real time.

01

Intra-Attestation Window Risk

Attestation reports confirm balances at a specific block height, but provide no visibility into collateral movements between reports. During this blind window, the protocol could theoretically move funds to cover a shortfall, or an exchange could freeze assets without detection. Risk teams should model the maximum loss exposure that could accumulate within a single attestation cycle and demand shorter reporting intervals from the protocol.

02

Off-Exchange Settlement Opacity

Assets held with OES providers like Copper and Ceffu are attested through the custodian's own reporting, not through direct on-chain verification. The attestor relies on API feeds and custodial statements, creating a chain of trust that a compromised or insolvent custodian could falsify. Due-diligence teams should independently verify the legal segregation of these assets and the attestor's direct access to custodian systems.

03

Exchange Liability Netting

Attestations typically report net equity on each exchange, not the gross long and short positions that constitute the delta-neutral hedge. A report showing a healthy net balance could conceal a scenario where the protocol's short positions are deeply underwater while the long collateral is impaired. Integrators should demand gross position reporting to independently verify delta-neutrality at the time of attestation.

04

Collateral Composition Drift

Attestation reports may confirm total asset value without disclosing the precise composition of stablecoin vs. LST vs. ETH collateral. A shift toward lower-quality or less liquid collateral between attestation windows could materially change the protocol's liquidity profile without detection. Risk managers should require collateral composition breakdowns in each attestation to monitor for drift toward riskier backing assets.

05

Attestor Independence and Scope Limitations

The attestor's engagement scope is defined by the protocol itself, potentially excluding specific accounts, venues, or liability types. If the protocol can unilaterally modify the scope or switch attestors without governance approval, the independence of the process is compromised. Governance teams should verify that attestation scope changes require ENA holder approval and that the attestor's mandate covers all material venues.

06

Real-Time Verification Gap

Even a perfect point-in-time attestation cannot replace continuous on-chain verification. The gap between attested snapshots leaves the protocol vulnerable to rapid collateral deterioration during market volatility. Chainscore Labs can help teams design complementary monitoring systems that track on-chain signals, exchange wallet activity, and funding rate anomalies to detect divergence from attested states between reporting cycles.

BLIND SPOTS IN PROOF-OF-RESERVES

Risk Matrix: Attestation Failure Modes

Evaluates the gap between third-party attestation and real-time, on-chain proof of all exchange positions and custodian balances. Due-diligence teams and auditors use this to identify verification blind spots.

Risk AreaFailure ModeAffected ActorsSeverityMitigation / Action

Data Freshness

Attestation report is a point-in-time snapshot that becomes stale immediately, masking intra-period fund movements or loss events.

Risk teams, institutional integrators, auditors

High

Require real-time or near-real-time on-chain proof-of-reserves; implement independent balance monitoring with alerting on material changes.

Scope Limitation

Attestation covers only custodian balances but excludes open exchange derivative positions, hiding the true net asset value and hedge health.

Due-diligence teams, protocol architects, risk modelers

Critical

Demand attestation that includes exchange account statements and open derivative positions; verify net asset calculation independently.

Custodian Collusion

A compromised or negligent custodian provides falsified balance confirmations to the attestation provider, overstating backing assets.

Institutional integrators, governance delegates, auditors

Critical

Cross-reference attestation data with on-chain custodian wallet activity; use multiple independent attestation providers; implement proof-of-liabilities.

Exchange Reporting Integrity

Exchange-provided balance and position data is unverified or manipulated, misrepresenting the hedge's delta-neutrality.

Risk teams, hedging engineers, security auditors

Critical

Require cryptographic proof from exchanges (e.g., Merkle proofs) for balances and positions; validate against on-chain exchange wallet activity.

Attestation Provider Independence

The attestation firm has a conflict of interest, lacks technical expertise, or applies insufficient scrutiny to management-provided data.

Governance delegates, due-diligence teams, investors

High

Evaluate attestation provider's reputation, methodology, and independence; rotate providers periodically; commission independent verification audits.

Liability Omission

Attestation confirms assets but ignores protocol liabilities (e.g., outstanding USDe supply, pending redemptions), overstating solvency.

Risk modelers, institutional integrators, auditors

High

Require attestation that explicitly reconciles total assets against total protocol liabilities; verify USDe supply independently on-chain.

Off-Chain Settlement Risk

Assets held in off-exchange settlement venues (e.g., Copper, Ceffu) are attested but the legal or operational control of those assets is misrepresented.

Legal and compliance teams, risk managers, operators

High

Obtain legal opinions on asset control and bankruptcy remoteness; verify OES provider attestation methodology; monitor for regulatory actions against custodians.

Frequency and Latency

Attestation is performed monthly or quarterly, creating a large window for undetected loss, theft, or operational failure.

Risk teams, incident responders, governance

Medium

Advocate for continuous or daily attestation; implement independent on-chain monitoring of known protocol wallets; establish circuit-breakers for anomalous balance changes.

VERIFICATION RIGOR AND BLIND SPOTS

Due-Diligence and Monitoring Checklist

A practical checklist for risk, security, and integration teams to evaluate the trustworthiness of Ethena's attestations and to monitor for gaps between reported and actual backing on an ongoing basis.

What to check: The exact scope of the third-party attestation report. Does it cover all custodian accounts, all exchange wallets, and the net derivative positions, or only a subset? Confirm the frequency of attestations (e.g., daily, weekly) and the lag between the snapshot time and report publication.

Why it matters: A report that only covers a subset of venues or is published with a significant delay creates a window where the protocol could be under-collateralized without public knowledge. The attestation is a point-in-time proof, not a real-time guarantee.

Signal of readiness: The attestation provider's report clearly enumerates all covered venues and accounts. The protocol's documentation explicitly states the attestation frequency and the expected publication lag. Any deviation from this schedule should trigger an immediate review.

Chains We Build On

Looking to build on a specific blockchain?

We build smart contracts, DeFi applications, wallets, tokenization platforms, and blockchain infrastructure across the major ecosystems teams choose today. That includes Ethereum, Arbitrum, Optimism, Polygon, Avalanche, Solana, Sui, Aptos, Hedera, Stellar, and NEAR, with support for additional EVM and non-EVM networks based on your product requirements.

EVM ecosystems

  • Ethereum logo
    Ethereum
  • Arbitrum logo
    Arbitrum
  • Optimism logo
    Optimism
  • Polygon logo
    Polygon
  • Avalanche logo
    Avalanche
  • Cronos logo
    Cronos

Non-EVM ecosystems

  • Solana logo
    Solana
  • Sui logo
    Sui
  • Aptos logo
    Aptos
  • Hedera logo
    Hedera
  • Stellar logo
    Stellar
  • NEAR logo
    NEAR

Additional ecosystems

  • Polkadot logo
    Polkadot
  • Cosmos logo
    Cosmos
  • TON logo
    TON
  • Cardano logo
    Cardano
  • Algorand logo
    Algorand
  • Tempo logo
    Tempo

Also available for Base, appchains, custom EVM networks, and cross-chain product architecture.

ATTESTATION INTEGRITY

Frequently Asked Questions

Critical questions for due-diligence teams, auditors, and institutional integrators evaluating the completeness and trustworthiness of Ethena's proof-of-reserves and attestation reports.

The attestation report confirms the existence and valuation of assets held at custodians and on exchanges at a specific point in time. However, it does not provide real-time, on-chain proof of all positions.

What to verify:

  • Scope limitation: The report confirms custodian balances and exchange wallet balances but does not typically provide a cryptographic proof of the open derivative positions (the short perpetual swaps) that are critical to the delta-neutral hedge.
  • Liability matching: Confirm whether the report explicitly attests that the total value of assets equals or exceeds the total supply of USDe, or if it merely lists assets without a solvency assertion.
  • Intra-period risk: The attestation is a point-in-time snapshot. It does not guarantee solvency between reports. Ask what monitoring exists to detect a solvency gap that opens and closes between attestation windows.
  • Exchange proof-of-reserves: If the report relies on exchange-provided balance statements rather than direct on-chain verification or Merkle proofs, this introduces a trust dependency on the exchange's own reporting integrity.
Trusted by Industry Leaders

Delivering blockchain solutions for 5+ years.

We have partnered with 50+ leading DeFi protocols, NFT ecosystems, and fintech innovators to build secure, scalable, and capital-efficient blockchain products.

Selected Partners & Clients

ChainVote logo
Reax logo
Sokail logo
Swapsicle logo
SyntheX logo
Tekika logo
Telos logo
Zexe logo
ChainVote logo
Reax logo
Sokail logo
Swapsicle logo
SyntheX logo
Tekika logo
Telos logo
Zexe logo
ChainVote logo
Reax logo
Sokail logo
Swapsicle logo
SyntheX logo
Tekika logo
Telos logo
Zexe logo
ChainVote logo
Reax logo
Sokail logo
Swapsicle logo
SyntheX logo
Tekika logo
Telos logo
Zexe logo
“I've been working with Chainscore Labs for last 3+ years, they've consistently delivered with strong ownership across multiple projects. The team is reliable and detail-oriented.”
L
Lee Erswell
CEO, Telos Foundation
how to get started

How to get started?

If you're looking for blockchain integration, ChainScore Labs has 5+ years of experience helping teams build and integrate exchanges, wallets, smart contracts, tokenization solutions, and protocol-connected products, we can help you choose the right path, integrate securely, and get to production faster. Our team consists of experienced blockchain developers and architects who can help you with your blockchain integration needs.

01

Exploration & Strategy

Define your product goals and choose the right blockchain architecture for your use case.

02

Architecture & Design

Design the smart contracts, tokenomics, and security parameters of your system.

03

Development & Integration

Build and integrate with wallets, oracles, and front-end dApps for a seamless experience.

04

Security & Launch

Comprehensive audits followed by a risk-managed mainnet deployment to protect your users.

Start a build

Need a blockchain engineering team?

Send the project context and we will respond with next steps, scope questions, and a practical path to delivery.