Ethereum Pool 1 cross-margin branch
msUSD debt hardcoded to $1; no market-price or depeg input · Metronome USDPeggedTokenOracle · ethereum
Chainlink USDC/USD -> direct USDC value; Vesper pricePerShare -> vaUSDC value · Metronome ChainlinkOracle · ethereum · 1d staleness bound
Chainlink ETH/USD -> direct WETH value; Vesper pricePerShare -> vaETH value · Metronome ChainlinkOracle · ethereum · 4h staleness bound
Chainlink DAI/USD -> direct DAI value · Metronome ChainlinkOracle · ethereum · 4h staleness bound
Chainlink BTC/USD -> direct WBTC value · Metronome ChainlinkOracle · ethereum · 4h staleness bound
Chainlink FRAX/USD -> inactive FRAX value; Vesper pricePerShare -> inactive vaFRAX value · Metronome ChainlinkOracle · ethereum · 1d staleness bound
Chainlink stETH/ETH 0x86392dC19c0b719886221c78AB11eb8Cf5c52812 x ETH/USD x Vesper pricePerShare -> vaSTETH value · Metronome ChainlinkEthOnlyTokenOracle · ethereum · 1d staleness bound
Chainlink rETH/ETH 0x536218f9E9Eb48863970252233c8F271f554C2d0 x ETH/USD x Vesper pricePerShare -> vaRETH value · Metronome ChainlinkEthOnlyTokenOracle · ethereum · 1d staleness bound
Chainlink cbETH/ETH 0xF017fcB346A1885194689bA23Eff2fE6fA5C483b x ETH/USD x Vesper pricePerShare -> vaCBETH value · Metronome ChainlinkEthOnlyTokenOracle · ethereum · 1d staleness bound
Chainlink ETH/USD x Curve WETH/frxETH price_oracle clamped to [0.9, 1.0] x sfrxETH pricePerShare · Metronome SFraxEthTokenOracle · ethereum · 4h staleness bound
USDC · max LTV 85% · Active DepositToken 0x1A9551de6d56f7768398a82aA2186624a43d89e3.
WETH · max LTV 83% · Active DepositToken 0xA77B145c7Fa5B412eb8aD41D587bE892b9c1EfC3.
vaETH · max LTV 80% · Active DepositToken 0x45AC59746Ea5Eb74cF782855eca460A8Adc8925a.
FRAX · Legacy inactive DepositToken 0x608249cc11728E3b978f7B27F1EA13F607D484EF has a raw collateral factor of one wei of WAD and residual deposited balance.
DAI · max LTV 85% · Active DepositToken 0x1f9732B84e22E936cFc2FF6F2d4994097DCCC93e.
WBTC · max LTV 80% · Active DepositToken 0x7f9e66640Fec701D9f46ed5eD69F925fFDbb4683.
vaUSDC · max LTV 82% · Active DepositToken 0xdAec887E37e86ea9B78852EB7470D70bbF266258.
vaFRAX · Legacy inactive DepositToken 0x63EC45313149b1fa677b2b91CB93880232EF63AC has a raw collateral factor of one wei of WAD and residual deposited balance.
sfrxETH · max LTV 80% · Active DepositToken 0x24F2d1aC81eCFD8A808001a97349185EF1bCF4ad.
vaSTETH · max LTV 78% · Active DepositToken 0x691Af94cC63B99bd36173eD6Fb1eF5508b2774ec.
vaRETH · max LTV 75% · Active DepositToken 0x9e5bDf244a2Fcc44f1bcBd3aE108bE2a6dE5E379.
vaCBETH · max LTV 75% · Active DepositToken 0x1887e76914699B839B97A0B69FF6F8B865745321.
A permissionless caller may liquidate any other account immediately when current oracle-valued debt exceeds the sum of oracle-valued collateral multiplied by each collateral factor. The caller burns its own msUSD, the Pool burns the borrower's matching DebtToken, and the selected DepositToken seizes oracle-quoted collateral equal to repayment value plus a 10% liquidator incentive and 8% protocol fee. Each call is capped at 50% of that borrower's selected debt-token balance; debtFloorInUsd is zero. · liquidation delay None
No Stability Pool, collateral auction, insurance reserve, governance-token debt auction, or other bad-debt absorber exists in the reviewed Pool, DebtToken, FeeProvider, or registry graph. Liquidations are funded only by external liquidators supplying msUSD and are limited by available borrower collateral.
MasterOracle selects a token-specific oracle when configured and otherwise the default ChainlinkOracle; a configured custom-oracle failure does not fall through to the default. ChainlinkOracle rejects nonpositive or stale data and reverts, with no second provider or stored-last-good fallback. Vesper, Curve, and share-rate legs have no independent freshness timestamp, while msUSD debt remains fixed at $1.
Pool.liquidate reverts if the requested seizure exceeds the borrower's selected collateral balance. Collateral-backed partial liquidations can continue, but collateral-exhausted debt remains on the borrower's DebtToken balance; the reviewed contracts expose no write-off, redistribution, or socialization path. Governor or guardian shutdown sets everythingStopped and pauses issue, repay, deposit, withdraw, liquidate, and swap; the governor can later call open(), so shutdown is reversible but also disables liquidation while active.
Ethereum Pool 2 USDC branch
msUSD debt hardcoded to $1; no market-price or depeg input · Metronome USDPeggedTokenOracle · ethereum
Chainlink USDC/USD -> USDC collateral value · Metronome ChainlinkOracle · ethereum · 1d staleness bound
USDC · max LTV 85% · Active DepositToken 0x3cd510b7348c8e0303D8448Fd35A2789a5ac7f91; zero supply and 100,000 USDC cap at the observed block.
A permissionless caller may liquidate any other account immediately when current oracle-valued debt exceeds the sum of oracle-valued collateral multiplied by each collateral factor. The caller burns its own msUSD, the Pool burns the borrower's matching DebtToken, and the selected DepositToken seizes oracle-quoted collateral equal to repayment value plus a 10% liquidator incentive and 8% protocol fee. Each call is capped at 50% of that borrower's selected debt-token balance; debtFloorInUsd is zero. · liquidation delay None
No Stability Pool, collateral auction, insurance reserve, governance-token debt auction, or other bad-debt absorber exists in the reviewed Pool, DebtToken, FeeProvider, or registry graph. Liquidations are funded only by external liquidators supplying msUSD and are limited by available borrower collateral.
MasterOracle uses the default ChainlinkOracle for USDC. Nonpositive or data older than the configured 86,400-second bound reverts; there is no second provider or stored-last-good fallback, and msUSD debt remains fixed at $1.
Pool.liquidate reverts if the requested seizure exceeds the borrower's selected collateral balance. Collateral-backed partial liquidations can continue, but collateral-exhausted debt remains on the borrower's DebtToken balance; the reviewed contracts expose no write-off, redistribution, or socialization path. Governor or guardian shutdown sets everythingStopped and pauses issue, repay, deposit, withdraw, liquidate, and swap; the governor can later call open(), so shutdown is reversible but also disables liquidation while active.
Optimism Pool 1 cross-margin branch
msUSD debt hardcoded to $1; no market-price or depeg input · Metronome USDPeggedTokenOracle · optimism
Chainlink USDC.e/USD -> direct USDC.e value; Vesper pricePerShare -> vaUSDC value · Metronome ChainlinkOracle · optimism · 1d staleness bound
Chainlink ETH/USD -> direct WETH value; Vesper pricePerShare -> vaETH value · Metronome ChainlinkOracle · optimism · 1d staleness bound
Chainlink OP/USD -> direct OP value; Vesper pricePerShare -> vaOP value · Metronome ChainlinkOracle · optimism · 1d staleness bound
Chainlink wstETH/USD -> Vesper pricePerShare -> vawstETH value · Metronome ChainlinkOracle · optimism · 1d staleness bound
USDC.e · max LTV 85% · Active DepositToken 0xd2e32323686de92411639d446396AFA5E6149C28.
WETH · max LTV 83% · Active DepositToken 0x5c18f45c4C62B0687425598579B026B90785c28E.
vaETH · max LTV 80% · Active DepositToken 0x564baA321227abf6B2E88a38557b6517077aAD32.
OP · max LTV 70% · Active DepositToken 0x1E6039574bBf6b1F65650bC50B2Bca8911Fd9b27.
vaOP · max LTV 70% · Active DepositToken 0x25Ee6eA9353E0ffa3155655F3dF9140684671f36.
vawstETH · max LTV 78% · Active DepositToken 0x293aaC1fef48b2ebf95d0CB3a31A7B219e8Ece9E.
vaUSDC · max LTV 82% · Active DepositToken 0x4E71790712424f246358D08A4De6C9896482dE64.
A permissionless caller may liquidate any other account immediately when current oracle-valued debt exceeds the sum of oracle-valued collateral multiplied by each collateral factor. The caller burns its own msUSD, the Pool burns the borrower's matching DebtToken, and the selected DepositToken seizes oracle-quoted collateral equal to repayment value plus a 10% liquidator incentive and 8% protocol fee. Each call is capped at 50% of that borrower's selected debt-token balance; debtFloorInUsd is zero. · liquidation delay None
No Stability Pool, collateral auction, insurance reserve, governance-token debt auction, or other bad-debt absorber exists in the reviewed Pool, DebtToken, FeeProvider, or registry graph. Liquidations are funded only by external liquidators supplying msUSD and are limited by available borrower collateral.
MasterOracle selects a configured token-specific oracle or the default ChainlinkOracle. Stale or nonpositive Chainlink data reverts, with no alternate provider or last-good value; Vesper share rates have no independent timestamp and msUSD debt remains fixed at $1.
Pool.liquidate reverts if the requested seizure exceeds the borrower's selected collateral balance. Collateral-backed partial liquidations can continue, but collateral-exhausted debt remains on the borrower's DebtToken balance; the reviewed contracts expose no write-off, redistribution, or socialization path. Governor or guardian shutdown sets everythingStopped and pauses issue, repay, deposit, withdraw, liquidate, and swap; the governor can later call open(), so shutdown is reversible but also disables liquidation while active.
Base Pool 1 cross-margin branch
msUSD debt hardcoded to $1; no market-price or depeg input · Metronome USDPeggedTokenOracle · base
Chainlink USDC/USD -> direct USDC value; Vesper pricePerShare -> vaUSDC value · Metronome ChainlinkOracle · base · 1d staleness bound
Chainlink ETH/USD -> direct WETH value; Vesper pricePerShare -> vaETH value · Metronome ChainlinkOracle · base · 1d staleness bound
Chainlink cbETH/USD -> Vesper pricePerShare -> vacbETH value · Metronome ChainlinkOracle · base · 1d staleness bound
Chainlink wstETH/ETH 0xa669E5272E60f78299F4824495cE01a3923f4380 x ETH/USD x Vesper pricePerShare -> vawstETH value · Metronome ChainlinkEthOnlyOracle · base · 1d staleness bound
USDC · max LTV 85% · Active DepositToken 0xC7F2f79Daa7Ea4FBbF60b45b5D6028BDE2453476.
WETH · max LTV 83% · Active DepositToken 0x8b581d0013F571a792c3Aa8AF2a0366A309BF51E.
vaETH · max LTV 80% · Active DepositToken 0x631E4eFe520152b9aa98aCa50739a7F6a8f21319.
vaUSDC · max LTV 82% · Active DepositToken 0x329846f9e19dAa7fD9844065a62eD01BCf63Cf69.
vawstETH · max LTV 78% · Active DepositToken 0x3E5C739deC75aC5b8BC11D763b02B2a777046802.
vacbETH · max LTV 75% · Active DepositToken 0xE7Eb345866e07201f0dfe9Afb3a8f0637D998FC9.
A permissionless caller may liquidate any other account immediately when current oracle-valued debt exceeds the sum of oracle-valued collateral multiplied by each collateral factor. The caller burns its own msUSD, the Pool burns the borrower's matching DebtToken, and the selected DepositToken seizes oracle-quoted collateral equal to repayment value plus a 10% liquidator incentive and 8% protocol fee. Each call is capped at 50% of that borrower's selected debt-token balance; debtFloorInUsd is zero. · liquidation delay None
No Stability Pool, collateral auction, insurance reserve, governance-token debt auction, or other bad-debt absorber exists in the reviewed Pool, DebtToken, FeeProvider, or registry graph. Liquidations are funded only by external liquidators supplying msUSD and are limited by available borrower collateral.
MasterOracle selects a configured token-specific oracle or the default ChainlinkOracle. Stale or nonpositive Chainlink data reverts, with no alternate provider or last-good value; Vesper share rates have no independent timestamp and msUSD debt remains fixed at $1.
Pool.liquidate reverts if the requested seizure exceeds the borrower's selected collateral balance. Collateral-backed partial liquidations can continue, but collateral-exhausted debt remains on the borrower's DebtToken balance; the reviewed contracts expose no write-off, redistribution, or socialization path. Governor or guardian shutdown sets everythingStopped and pauses issue, repay, deposit, withdraw, liquidate, and swap; the governor can later call open(), so shutdown is reversible but also disables liquidation while active.
Hemi Pool 1 cross-margin branch
msUSD debt hardcoded to $1; no market-price or depeg input · Metronome USDPeggedTokenOracle · hemi
Unconfigured RedStone pull-cache main -> RedStone push ETH feed 0xb9D0073aCb296719C26a8BF156e4b599174fe1d5 -> WETH value · Metronome MainAndFallbackOracle / RedStone · hemi · 1d staleness bound
Unconfigured RedStone pull-cache main -> shared RedStone push USDC feed 0x31a36CdF4465ba61ce78F5CDbA26FDF8ec361803 -> USDC and USDC.e values · Metronome MainAndFallbackOracle / RedStone · hemi · 1d staleness bound
Unconfigured RedStone pull-cache main -> RedStone push USDT feed 0xe8D9FbC10e00ecc9f0694617075fDAF657a76FB2 -> USDT value · Metronome MainAndFallbackOracle / RedStone · hemi · 1d staleness bound
WETH · max LTV 83% · Active DepositToken 0x0B6f502F245bd17848a996eeE502F89381508317.
USDC · max LTV 85% · Active DepositToken 0xDC698D8fdB26459fB2473A315c518619387983F0.
USDT · max LTV 85% · Active DepositToken 0x5a64e1b924Aa8C55D44B239d0a83AB5de60535ad.
USDC.e · max LTV 85% · Active DepositToken 0x7E31E5864EeA3913C89F3E035F6B0C0C41A18727.
A permissionless caller may liquidate any other account immediately when current oracle-valued debt exceeds the sum of oracle-valued collateral multiplied by each collateral factor. The caller burns its own msUSD, the Pool burns the borrower's matching DebtToken, and the selected DepositToken seizes oracle-quoted collateral equal to repayment value plus a 10% liquidator incentive and 8% protocol fee. Each call is capped at 50% of that borrower's selected debt-token balance; debtFloorInUsd is zero. · liquidation delay None
No Stability Pool, collateral auction, insurance reserve, governance-token debt auction, or other bad-debt absorber exists in the reviewed Pool, DebtToken, FeeProvider, or registry graph. Liquidations are funded only by external liquidators supplying msUSD and are limited by available borrower collateral.
MainAndFallbackOracle first accepts a positive main-provider value within the token's 86,400-second outer bound. The RedStone pull-cache main additionally returns zero outside its 60-second cache tolerance; at observation it returned zero for every collateral. The contract then uses RedStone push fallback subject to the 86,400-second bound. If both paths are zero or stale it reverts both-providers-failed; there is no stored-last-good path beyond the push feed's latest round. Both routes share RedStone and the main was unusable, so this is not provider redundancy.
Pool.liquidate reverts if the requested seizure exceeds the borrower's selected collateral balance. Collateral-backed partial liquidations can continue, but collateral-exhausted debt remains on the borrower's DebtToken balance; the reviewed contracts expose no write-off, redistribution, or socialization path. Governor or guardian shutdown sets everythingStopped and pauses issue, repay, deposit, withdraw, liquidate, and swap; the governor can later call open(), so shutdown is reversible but also disables liquidation while active.