{"investigation":{"slug":"us-permissionless-dollar","entity_name":"US Permissionless Dollar","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"US Permissionless Dollar (USPD) is a decentralized, over-collateralized stablecoin protocol built on Ethereum by Permissionless Technologies, the team behind the Morpher trading platform. In December 2025, the protocol suffered a critical exploit via a clandestine proxy deployment attack — later dubbed CPIMP — that had silently compromised admin privileges since September 2025, resulting in approximately $1 million in losses. The project has undergone audits by Nethermind and Resonance Security but the exploit bypassed audited code by targeting the deployment layer, raising unresolved questions about operational security and the viability of the planned V2 relaunch.","sections":[{"content":"US Permissionless Dollar (ticker: USPD) is an ERC-20 stablecoin issued on Ethereum (contract address: 0x476ef9ac6D8673E220d0E8BC0a810C2Dc6A2AA84) by Permissionless Technologies. The protocol is designed as a yield-bearing stablecoin pegged to the US dollar, with all reserves held on-chain in stETH (staked Ether). Users mint USPD by depositing stETH, receiving native yield from underlying staking rewards. A network of third-party Stabilizers provides a minimum 25% over-collateralization buffer. USPD is developed by the team behind Morpher, a leverage trading platform on Base, and was founded by Martin Froehler, a mathematician and former quantitative hedge fund manager with prior experience at Quantiacs. As of the Etherscan on-chain record, the contract shows a total supply exceeding 1.5 billion USPD and only 112 token holders, reflecting significant post-exploit collapse in adoption.","heading":"Protocol Overview","sources":[{"url":"https://uspd.io/","name":"uspd.io","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x476ef9ac6D8673E220d0E8BC0a810C2Dc6A2AA84","name":"etherscan.io","type":"other","credibility":3},{"url":"https://www.lbank.com/price/us-permissionless-dollar/what-is","name":"lbank.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 4-5, 2025, USPD publicly disclosed a critical security breach that had been active since the protocol's proxy contract deployment on September 16, 2025. The attack vector, labeled CPIMP (Clandestine Proxy In the Middle of Proxy), exploited the smart contract initialization window during deployment. The attacker front-ran the team's proxy initialization transaction using a Multicall3 bundle, seizing administrative privileges before the legitimate deployment script completed execution. The attacker then installed a shadow malicious implementation contract that forwarded calls to the audited contract while secretly manipulating storage slots and event data to mask its presence from block explorers. The malicious admin access remained undetected for approximately 78 days. On December 4, 2025, the attacker exploited this hidden access to mint approximately 98 million USPD tokens without authorization and drain approximately 232-237 stETH from the protocol's collateral reserves. The stolen stETH and USPD were liquidated for approximately $300,000 in USDC via the Curve decentralized exchange. Total reported losses across minted tokens and drained collateral were estimated at approximately $1 million. Attacker addresses identified by the team include 0x7C97313f349608f59A07C23b18Ce523A33219d83 and 0x083379BDAC3E138cb0C7210e0282fbC466A3215A.","heading":"December 2025 Exploit — CPIMP Proxy Attack","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-uspd-hack-december-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://en.cryptonomist.ch/2025/12/05/uspd-stablecoin-proxy-attack/","name":"en.cryptonomist.ch","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/12/05/hackers-exploit-uspd-stablecoin-via-proxy-deployment-vulnerability/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.tronweekly.com/uspd-protocol-suffers-exploit-through-cpimp-at/","name":"tronweekly.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/0db76-uspd-stablecoin-exploit-million","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to its mainnet deployment, USPD underwent a two-week security audit by Nethermind Security completed on or around September 3, 2025. The Nethermind audit covered collateral aggregation mechanisms, automated liquidation processes, oracle pricing integration (Chainlink, Uniswap, Morpho), access control boundaries, and over-collateralization guarantees. The audit identified 3 critical severity issues, 3 high severity issues, 2 medium severity issues, and additional low-severity findings, all of which the team alleged were remediated prior to mainnet launch. An additional audit was conducted by Resonance Security. Despite this dual-audit posture, the December 2025 exploit bypassed all audited code entirely by targeting the deployment process itself — an attack surface not covered by standard smart contract audits. The incident is widely cited in security research as evidence that smart contract audits alone are insufficient protection against deployment-layer attacks. The Etherscan listing of the token notes no audit submission to Etherscan and flags two compiler warnings including a high-severity TransientStorageClearingHelperCollision warning.","heading":"Audit History and Pre-Exploit Security Posture","sources":[{"url":"https://www.nethermind.io/blog/audit-of-uspds-multi-stabilizer-protocol","name":"nethermind.io","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-uspd-hack-december-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x476ef9ac6D8673E220d0E8BC0a810C2Dc6A2AA84","name":"etherscan.io","type":"other","credibility":3},{"url":"https://medium.com/@InfyniSec/permissionless-dollar-not-without-safeguards-e3a52dc49ecb","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following public disclosure on December 4-5, 2025, the USPD team issued an emergency advisory urging users to revoke all approvals and refrain from buying USPD. The team offered the attacker a whitehat bounty arrangement: return 90% of stolen funds in exchange for keeping 10% (approximately $100,000) as a bug bounty and avoiding legal action. The team stated it engaged law enforcement and whitehat security groups to trace stolen funds and flagged attacker addresses with major centralized and decentralized exchanges. The protocol announced a structured recovery plan including a USPD V2 relaunch targeting Q2 2026, distribution of Recovery Tokens to approximately 230 affected holders proportional to their holdings at the time of the exploit, and a dedicated recovery pool funded from future protocol revenue. The V2 architecture is described as featuring a simplified modular design, DeFi-compatible yield mechanics, and ZK-privacy layers. As of the investigation date, V2 had not yet launched and no public confirmation of recovered funds was found.","heading":"Team Response and Recovery Plan","sources":[{"url":"https://uspd.io/blog/path-forward","name":"uspd.io","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/12/05/hackers-exploit-uspd-stablecoin-via-proxy-deployment-vulnerability/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/0db76-uspd-stablecoin-exploit-million","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the December 2025 exploit, USPD's on-chain liquidity collapsed significantly. Etherscan data shows a total supply of over 1.5 billion USPD tokens (reflecting the unauthorized mint of ~98 million tokens) with only 112 registered holders and zero transfers in a 24-hour window at time of review, indicating the protocol is effectively inactive. The token maintains a nominal listing on Coinbase's price tracker and LBank, but trading activity is described as negligible. The protocol maintained a nominal $1 peg immediately post-exploit according to reporting, but subsequent market data reflects near-zero economic activity. DeFiLlama also tracks the token but shows marginal TVL. The project's recovery remains contingent on a successful V2 launch that has not been independently verified as delivered.","heading":"Market and Liquidity Status Post-Exploit","sources":[{"url":"https://etherscan.io/token/0x476ef9ac6D8673E220d0E8BC0a810C2Dc6A2AA84","name":"etherscan.io","type":"other","credibility":3},{"url":"https://defillama.com/stablecoin/us-permissionless-dollar","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coinbase.com/price/us-permissionless-dollar","name":"coinbase.com","type":"other","credibility":3}],"severity":"medium"},{"content":"USPD has been flagged by ZachXBT, the blockchain investigator known for exposing crypto fraud and protocol exploits. The specific basis and timing of ZachXBT's flag were not independently recoverable in verifiable public sources at the time of this investigation; no specific ZachXBT post or report directly citing USPD by name was located in Tier 1 or Tier 2 sources. PeckShield Alert, a blockchain security monitoring service, was cited in multiple news reports as having warned users about the exploit in real time during the December 2025 incident. The InfyniSec Medium analysis published in December 2025 provided an independent post-mortem highlighting deployment-layer safeguard failures. The absence of a verifiable on-chain or published ZachXBT report does not contradict the flag; it may reflect unpublished intelligence, private alerts, or a Telegram-based disclosure not indexed by standard search.","heading":"ZachXBT Flag and Third-Party Warnings","sources":[{"url":"https://medium.com/@InfyniSec/permissionless-dollar-not-without-safeguards-e3a52dc49ecb","name":"medium.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/12/05/hackers-exploit-uspd-stablecoin-via-proxy-deployment-vulnerability/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"No SEC enforcement actions, CFTC orders, DOJ filings, or OFAC sanctions against USPD, Permissionless Technologies, or founder Martin Froehler were found in publicly available regulatory databases at the time of this investigation. The team stated it engaged law enforcement following the exploit, but no public court filings or regulatory proceedings were identified. The broader stablecoin regulatory environment shifted significantly in 2025-2026 with the GENIUS Act establishing a federal framework for payment stablecoins and the SEC issuing guidance that certain dollar-backed stablecoins do not constitute securities; USPD's status under these frameworks has not been publicly adjudicated.","heading":"Regulatory and Legal Context","sources":[{"url":"https://www.sec.gov/newsroom/speeches-statements/statement-stablecoins-040425","name":"sec.gov","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/12/05/hackers-exploit-uspd-stablecoin-via-proxy-deployment-vulnerability/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024","event":"Martin Froehler, founder of Morpher, establishes USPD.io / Permissionless Technologies and begins building USPD stablecoin protocol.","source":"","date_original":"2024-01-01"},{"date":"2025-09-03","event":"Nethermind Security completes a two-week audit of USPD's Multi-Stabilizer Protocol, identifying 3 critical, 3 high, and 2 medium severity issues; team claims all were remediated.","source":""},{"date":"2025-09-16","event":"USPD deploys proxy contracts to Ethereum mainnet. Attacker front-runs initialization using a Multicall3 transaction, seizing admin privileges via CPIMP attack vector — undetected at time of deployment.","source":""},{"date":"2025-12-04","event":"Attacker activates hidden admin access, minting approximately 98 million USPD tokens without authorization and draining approximately 232-237 stETH from protocol reserves. Estimated loss: ~$1 million.","source":""},{"date":"2025-12-04","event":"Stolen USPD and stETH liquidated for approximately $300,000 USDC via Curve DEX. USPD team publicly discloses exploit, urges users to revoke approvals and avoid purchasing USPD.","source":""},{"date":"2025-12-05","event":"Multiple crypto news outlets including Cryptopolitan, CryptoTimes, Tron Weekly, and Halborn publish exploit analysis. USPD offers attacker 10% whitehat bounty to return 90% of stolen funds.","source":""},{"date":"2025-12-31","event":"USPD publishes 'Path Forward' blog announcing Recovery Token program for ~230 affected holders and targeting V2 relaunch for Q2 2026.","source":""},{"date":"2026-05-26","event":"As of investigation date, USPD V2 has not been independently verified as launched. Token shows 112 holders and near-zero on-chain activity. V1 contract remains effectively inactive.","source":""}],"sources_used":[{"url":"https://uspd.io/","name":"uspd.io","type":"other","archive_url":"http://web.archive.org/web/20260516052128/https://uspd.io/","credibility":3,"archive_timestamp":"2026-05-16T05:21:28+00:00"},{"url":"https://etherscan.io/token/0x476ef9ac6D8673E220d0E8BC0a810C2Dc6A2AA84","name":"etherscan.io","type":"other","archive_url":"https://web.archive.org/web/20260829032842/https://etherscan.io/token/0x476ef9ac6D8673E220d0E8BC0a810C2Dc6A2AA84","credibility":3,"archive_timestamp":"2026-08-29T03:28:42+00:00"},{"url":"https://www.lbank.com/price/us-permissionless-dollar/what-is","name":"lbank.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-uspd-hack-december-2025","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260513011734/https://www.halborn.com/blog/post/explained-the-uspd-hack-december-2025","credibility":3,"archive_timestamp":"2026-05-13T01:17:34+00:00"},{"url":"https://en.cryptonomist.ch/2025/12/05/uspd-stablecoin-proxy-attack/","name":"en.cryptonomist.ch","type":"other","archive_url":"http://web.archive.org/web/20260209112554/https://en.cryptonomist.ch/2025/12/05/uspd-stablecoin-proxy-attack/","credibility":3,"archive_timestamp":"2026-02-09T11:25:54+00:00"},{"url":"https://www.cryptotimes.io/2025/12/05/hackers-exploit-uspd-stablecoin-via-proxy-deployment-vulnerability/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20251205100222/https://www.cryptotimes.io/2025/12/05/hackers-exploit-uspd-stablecoin-via-proxy-deployment-vulnerability/","credibility":3,"archive_timestamp":"2025-12-05T10:02:22+00:00"},{"url":"https://www.tronweekly.com/uspd-protocol-suffers-exploit-through-cpimp-at/","name":"tronweekly.com","type":"other","archive_url":"http://web.archive.org/web/20260131235241/https://www.tronweekly.com/uspd-protocol-suffers-exploit-through-cpimp-at/","credibility":3,"archive_timestamp":"2026-01-31T23:52:41+00:00"},{"url":"https://cryptorank.io/news/feed/0db76-uspd-stablecoin-exploit-million","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829074847/https://cryptorank.io/news/feed/0db76-uspd-stablecoin-exploit-million","credibility":3,"archive_timestamp":"2026-08-29T07:48:47+00:00"},{"url":"https://www.nethermind.io/blog/audit-of-uspds-multi-stabilizer-protocol","name":"nethermind.io","type":"other","archive_url":"http://web.archive.org/web/20260208100802/https://www.nethermind.io/blog/audit-of-uspds-multi-stabilizer-protocol","credibility":3,"archive_timestamp":"2026-02-08T10:08:02+00:00"},{"url":"https://medium.com/@InfyniSec/permissionless-dollar-not-without-safeguards-e3a52dc49ecb","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://uspd.io/blog/path-forward","name":"uspd.io","type":"other","archive_url":"http://web.archive.org/web/20260213231127/https://uspd.io/blog/path-forward","credibility":3,"archive_timestamp":"2026-02-13T23:11:27+00:00"},{"url":"https://defillama.com/stablecoin/us-permissionless-dollar","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coinbase.com/price/us-permissionless-dollar","name":"coinbase.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.sec.gov/newsroom/speeches-statements/statement-stablecoins-040425","name":"sec.gov","type":"other","archive_url":"http://web.archive.org/web/20260430225311/https://www.sec.gov/newsroom/speeches-statements/statement-stablecoins-040425","credibility":3,"archive_timestamp":"2026-04-30T22:53:11+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:14.644397+00:00","updated_at":"2026-08-30T03:54:57.588867+00:00"}}