Carte d’Ethereum

Méthodologie de comptabilisation et de contrôle

Des jetons de même taille représentent la même somme. Un grand jeton vaut 100 petits. Les plateformes indiquent où se trouve cet argent, sans en ajouter.

Les montants sont en USD. Les heures d’observation sont en UTC. Données et attribution sont des estimations ; les observations sont asynchrones.

Inventaire et couverture

L’inventaire part de l’ETH en circulation, d’actifs USD adossés à des monnaies fiduciaires, de titres du Trésor, d’or tokenisé et de l’offre émise de WBTC, cbBTC et tBTC. Les jetons utilitaires ne comprennent que les réserves mesurées de contrats sélectionnés, pas toute l’offre ni la capitalisation. Le seuil de circulation par chaîne est de 1 M USD.

Répartition

Les positions localisées et l’estimation en portefeuilles égalent l’inventaire de chaque actif. Les garanties de ponts et les reçus ne sont pas ajoutés à nouveau. Aave et Morpho utilisent des réserves ajustées. Les pools Uniswap et certains coffres utilisent les soldes par adresse ; les compositions absentes ou paginées restent partielles.

Staking et actifs enveloppés

Le halo additionne les soldes des validateurs dans un état de consensus finalisé, y compris les retraits en attente. Il soustrait une seule fois la contrepartie estimée en ETH des positions de staking liquide suivies, selon le ratio de prix LST/ETH. Les contreparties non suivies restent dans le halo. La date provient du slot finalisé.

Échelle et structure

Toutes les plateformes positives partagent la même échelle dollars/surface ; les bases L2 sont des sous-ensembles d’Ethereum et le halo est séparé. Seules les puces monétaires ajoutent du capital. Une grande puce a 100 fois la capacité géométrique d’une petite. Les fractions préservent le montant exact. Géométrie et coupures restent fixes lors du zoom.

Flux nets sur 24 h

Variation estimée des quantités de jetons couverts, valorisée aux prix finaux. Peut inclure rendement, ajustements de quantité ou reclassements. Les flux internes des protocoles ne sont pas ajoutés aux flux des L2. Le mouvement indique le sens ; la luminosité suit la valeur absolue du flux net. Sans observations comparables, la zone reste éteinte.

Données et couverture

Une tâche quotidienne actualise les sources une par une. Actualiser lit un instantané enregistré. Les verrous partagés et les délais limitent les requêtes ; en cas d’échec, la dernière observation valide est conservée. L’heure d’observation financière est distincte de l’heure de collecte. Une vérification réussie ne rend pas récentes des observations anciennes.

Dans les portefeuilles et exchanges

Les montants en portefeuille sont estimés : offre moins les positions identifiées dans les protocoles, le staking et les ponts. Ils incluent l’ETH et les jetons détenus par des exchanges centralisés et d’autres dépositaires, pas seulement des portefeuilles en auto-conservation. Des contrats non suivis peuvent rester inclus.

Le spectre de la décentralisation à la centralisation

D0 est aussi décentralisé qu’Ethereum L1. D1–D9 décrivent les pouvoirs sur un système. Ils concernent les règles en chaîne, pas la garde des clés des portefeuilles. Ce sont des évaluations documentées, pas des garanties.

ETH est D0 sur L1. Sur un rollup D4, il devient D4 car il dépend aussi du rollup. Il en va de même pour les jetons dans les protocoles. Si seul un minimum est connu, nous affichons « au moins » (≥). Le panneau en explique la raison.

Décentralisation maximale

Aucun contrôle privilégié supplémentaire du capital ou de la sortie par rapport à Ethereum L1, dans le périmètre examiné.

Administration limitée

Réglages bornés, sans pouvoir connu de déplacer arbitrairement le capital.

Opération externe

Dépend de pouvoirs opérationnels externes : oracles, allocateurs ou pauses.

Gouvernance avec délai

La gouvernance peut modifier le système, avec un délai obligatoire documenté pour les changements ordinaires.

Conseil d’urgence indépendant

Un conseil élu et responsable peut agir en urgence ; les changements ordinaires sont retardés.

Conseil et fondation

Un conseil formel et une fondation partagent les mises à niveau immédiates, avec des pouvoirs de repli de la fondation.

Conseil et opérateur

Un conseil nommé et un opérateur contrôlent les mises à niveau immédiates ; la révocation publique est limitée.

Mise à niveau administrative

Un administrateur concentré peut modifier le système, sans délai efficace ni veto indépendant vérifiés.

Validation régie par l’opérateur

L’opérateur contrôle l’admission des validateurs ou contestataires et peut limiter l’inclusion forcée.

Réserves régies par l’émetteur

L’émetteur ou le dépositaire contrôle les réserves hors chaîne, le rachat ou le gel des actifs.

Preuves et examen

Les notes D sont des appréciations éditoriales des pouvoirs on-chain, pas des probabilités de perte ni des audits indépendants. Les actualisations financières ne modifient pas le registre de contrôle. Ses notes datées sont conservées en anglais, avec les liens justificatifs.

Évaluation révisée: . ETH, stablecoins sélectionnés, Bitcoin tokenisé et actifs réels, comptés une seule fois. Les anneaux montrent les actifs hors des apps cartographiées ; les plateformes, les capitaux à l’intérieur. Un inventaire partiel, pas une somme des TVL.

Notes des sources (anglais)
1inch limit-order v4 / router v6 · ≥ D2

Canonical Ethereum AggregationRouterV6 includes owner pause/unpause of trading and rescue of assets held at the router. These powers prevent blanket D0. Close live owner authority and order-selected predicates, interactions and custody scope before completing the grade.

Évaluation révisée:

Canonical router containing limit-order protocol v4; includes its actual pause and rescue powers.

Aave v2 · D3

Governance controls protocol updates and a guardian can pause emergency operations.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Aave v3 · D3

Governance can update the lending system; guardians can pause markets and risk roles manage parameters.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Aave v4 · ≥ D1

Aave officially launched v4 on Ethereum with three liquidity Hubs. The DAO can expand caps and add Spokes, establishing governed settings. Full Hub/Spoke implementation, oracle, governance delay and emergency authority closure remains pending; do not inherit Aave v3 or blanket D0.

Évaluation révisée:

Ethereum-mainnet v4 Hub/Spoke markets; exact live deployment/controller path remains unresolved.

Aerodrome Slipstream · ≥ D1

Pool administration and concentrated-liquidity configuration add local powers; underlying Base safeguards still apply.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Aerodrome v1 · ≥ D1

Factory fee and swap-pause roles add administration; underlying Base safeguards still apply.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Arbitrum One · D4

An elected 9-of-12 council can make immediate emergency changes; ordinary upgrades follow delayed DAO governance.

Évaluation révisée:

Arbitrum One; excludes AnyTrust/Nova.

Validation: Permissionless BoLD challenges; Ethereum data availability.

Upgrades: 9/12 emergency council; delayed DAO and non-emergency changes.

Accountability: DAO-elected cohorts, removal powers, organizational limits and a published constitution.

Exits: L1 inclusion and normal upgrade delays; emergency authority can bypass the delay.

Balancer V2 · ≥ D1

The v2 Vault has bounded fee/authorizer controls. Its original Vault pause window has expired, but individual pool contracts, rate providers and recovery paths still require review. At least D1; no blanket D0.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Balancer V3 · ≥ D2

The v3 Vault has a four-year pause window and six-month buffer. Paused pools permit permissionless recovery withdrawals, but operational controls, hooks and rate providers remain; at least D2.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Base · D6

An appointed 8-of-11 council and Coinbase must both approve upgrades; there is no timelock or DAO removal route.

Évaluation révisée:

Base mainnet, chain ID 8453; settlement and data availability on Ethereum.

Validation: TEE and ZK proof arms; permissionless challenges, with Coinbase controlling the TEE allowlist.

Upgrades: Coinbase 3/6 + Council 8/11 jointly approve; no timelock.

Accountability: Appointed council with self-administered membership; no token-governance removal route.

Exits: L1 forced inclusion; immediate upgrades provide no exit window.

Base canonical bridge · D6

This bridge inherits the upgrade and validation arrangements of base.

Évaluation révisée:

Canonical escrow/control path, not an additional capital stock.

Binance staked ETH · D9

Binance operates the staking and redemption service represented by WBETH.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

BUIDL · D9

Fund ownership and redemption depend on BlackRock, Securitize and qualified-investor transfer controls.

Évaluation révisée:

Canonical token mechanism; deployment-specific custody adds inherited bounds.

cbBTC · D9

Coinbase holds the BTC backing and controls the wrapped-token contract.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

cbETH · D9

Coinbase holds the underlying staking position and controls the token’s administration.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Celo · D8

Council participation limits upgrades, but cLabs separately controls proposer/challenger allowlists and withdrawal pauses.

Évaluation révisée:

Celo L2 mainnet, chain ID 42220; includes EigenDA and OP Succinct Lite dependencies.

Validation: OP Succinct Lite permits only registered challengers to initiate disputes; data availability also depends on EigenDA.

Upgrades: Joint 6/8 community council and 6/8 cLabs approvals; no enforced delay.

Accountability: Council participation is real, but allowlist and operational powers are separately held by cLabs.

Exits: cLabs can pause withdrawals and change proposer/challenger permissions without joint council approval.

Five of the six documented challengers are independent entities. An operator-managed allowlist still creates a D8 authority dependency; this does not erase their independence.

Compound III · D3

Timelocked governance can replace Comet and alter its configuration; a guardian can pause operations.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Curve, mixed pools · ≥ D1

The mapped legacy Curve pool family retains bounded fee/amplification administration, so it is at least D1. Pause powers, rate providers, lending integrations and per-pool ownership vary; no blanket D0 or complete family grade is assigned.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

DAI · ≥ D2

Governance-authorized issuance inherits Sky and the collateral backing used by the system.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

eETH · ≥ D3

The staking claim inherits ether.fi governance and any restaking dependencies of the underlying position.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

EigenLayer · D7

An emergency multisig can replace protocol rules immediately, bypassing the normal upgrade timelock.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Ethena · D9

The backing strategy depends on custodians, exchanges, and privileged mint/redeem operations.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Ethereum L1 · D0

Un terrain ouvert à tous. Même les plus grandes institutions tiennent mieux sur des fondations communes.

Évaluation révisée:

Baseline by definition; not a claim of absolute or maximal decentralization in every dimension.

ether.fi staking · D3

Contract changes are timelocked; a separate operator role can pause or invalidate pending withdrawals.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Euler V2 · ≥ D2

Governed vaults expose oracle, collateral, hook and parameter controls. Finalizing the vault governor does not remove factory beacon upgrades or dependency controls. At least D2 for the reviewed governed family; exact vault deployments need separate ratings.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

ezETH · ≥ D3

Renzo governance, its withdrawal arrangements and EigenLayer all affect the staking claim.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

FDUSD token · D9

First Digital issuer terms control issuance, backing and the availability of redemption. Current upgradeable source contains privileged mint/freeze controls.

Évaluation révisée:

Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.

Fluid · ≥ D2

The liquidity layer has configurable withdrawal limits and replaceable code. Its current upgrade safeguards need a deployment-specific review.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

frxETH · ≥ D3

Frax governance and staking operators administer issuance and backing; emergency safeguards require further review.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

GUSD token · D9

Gemini controls backing and redemption. Legacy proxy/store/custodian contracts support privileged transfer-rule replacement and seizure. Automated negative proxy detection does not remove these controls.

Évaluation révisée:

Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.

Ink · D5

The Optimism council and Foundation jointly control immediate upgrades; public proving and L1 inclusion do not remove those keys.

Évaluation révisée:

Ink mainnet, chain ID 57073.

Validation: Public fault-proof participation; transaction data on Ethereum.

Upgrades: SuperchainProxyAdminOwner requires both Foundation and Council; no enforced upgrade exit window.

Accountability: Optimism governance and council oversight, with Foundation fallback and guardian roles.

Exits: L1 inclusion and self-proposal are available; privileged pauses and upgrades remain.

The upstream assessment flags ongoing changes. This grade evaluates the documented authority paths, not a claim that every implementation byte was independently audited.

Lido · ≥ D3

Lido V3 core, oracle and withdrawal proxies are governed by DAO upgrades. CircuitBreaker pause powers, Reseal extension and Dual Governance protections must be evaluated together. D3 is a documented minimum; the entire live role/dependency graph is not certified complete.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Lighter on Robinhood · ≥ D2

The application has its own operator and proof system and is built on Robinhood; its full local authority is still being reviewed.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Linea · D8

Immediate upgrade authority combines with permissioned proposals and an address filter on forced transactions; the L1 route does not guarantee uncensorable exit.

Évaluation révisée:

Linea mainnet, chain ID 59144; canonical rollup and forced-transaction route.

Validation: ZK proofs validate state; proposers are permissioned during normal operation.

Upgrades: Council-controlled proxy administrators can upgrade immediately.

Accountability: Council and operational roles remain privileged; a council name alone does not establish an independent user veto.

Exits: Forced inclusion is address-filtered. A six-month inactivity fallback is not an ordinary permissionless exit guarantee.

Proof correctness, asset backing and withdrawal liquidity are not certified by the authority grade.

Liquity V1 · ≥ D2

The borrowing core has no admin key and is immutable. Liquidations depend on Chainlink with Tellor fallback: that oracle dependency prevents a blanket D0 for the complete position.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Liquity V2 · ≥ D2

The borrowing mechanism is immutable, but Chainlink prices and collateral-specific controls affect liquidations and redemptions. wstETH/rETH branches also inherit their issuers; at least D2.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Mantle · D8

The administrative multisig controls both immediate upgrades and the approved proposer set; withdrawals depend on those proposers.

Évaluation révisée:

Mantle mainnet, chain ID 5000; current OP Succinct configuration.

Validation: OP Succinct validity proofs with Ethereum data availability; proposals remain permissioned.

Upgrades: A 6/14 security multisig can immediately upgrade core contracts and change verifier configuration.

Accountability: Administrative authority includes proof mode and approved-proposer management.

Exits: L1 requests exist, but proposer failure can stop withdrawals.

This review uses the current Ethereum-blob/OP Succinct design; it does not reuse the older external-DA description.

Morpho markets · D0

Morpho Blue’s core cannot be upgraded or paused. Governance can enable parameters for new markets and set a bounded fee, but cannot replace existing market parameters. The holdings feed does not resolve market oracles, so positions remain incomplete; managed vaults do not inherit the core’s D0.

Évaluation révisée:

Immutable Morpho Blue lending core; market oracles, collateral and managed vaults are separate.

Morpho vaults · ≥ D2

Managed Morpho vaults add curator, allocator, owner and strategy controls. V2 gates can restrict withdrawals; adapters and their governance remain dependencies. These vaults do not inherit the Blue core’s D0.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

ETH · D0

Native ETH follows Ethereum account and consensus rules without a separate token issuer.

Évaluation révisée:

Native asset rules on L1; custody, staking, smart-wallet modules and protocol placement must be assessed separately.

OP Mainnet · D5

A 10-of-13 elected council and the Foundation jointly authorize upgrades; a signer-loss fallback can return authority to the Foundation.

Évaluation révisée:

OP Mainnet; an OP Stack brand alone is not sufficient to assign another chain.

Validation: Permissionless fault-proof participation; Ethereum data availability.

Upgrades: Joint Foundation + 10/13 Council approval; immediate emergency execution.

Accountability: Elected cohorts and a charter; Foundation fallback if council availability drops below eight.

Exits: L1 forced inclusion; there is no enforced exit window for immediate upgrades.

OP canonical bridge · D5

This bridge inherits the upgrade and validation arrangements of optimism.

Évaluation révisée:

Canonical escrow/control path, not an additional capital stock.

PAXG · D9

Paxos issuer custody and asset-protection controls remain part of the asset.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Pendle v2 · ≥ D2

Yield wrappers and underlying yield protocols add dependencies that differ by market.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

PYUSD · D9

Paxos issuer custody and asset-protection controls remain part of the asset.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

rETH · D0

The rETH claim inherits Rocket Pool governance and oracle reporting.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

RLUSD token · D9

Ripple issuer terms and current upgradeable implementation permit issuer-directed freezing, burning and redemption restrictions. Offchain reserves/redemption are material dependencies.

Évaluation révisée:

Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.

Robinhood Chain · D8

Immediate upgrades, two whitelisted challengers and operator transaction filtering concentrate authority beyond a public security council model.

Évaluation révisée:

Robinhood mainnet, chain ID 4663; Ethereum-settled rollup, not a child of Arbitrum One.

Validation: Fraud proofs are deployed, but only two whitelisted actors may challenge.

Upgrades: No enforced upgrade delay; operator-governed administration.

Accountability: No independent elected security council is documented for this deployment.

Exits: Transaction filtering can defeat forced inclusion; permissionless exit guarantees are limited.

Robinhood canonical bridge · D8

This bridge inherits the upgrade and validation arrangements of robinhood.

Évaluation révisée:

Canonical bridge contracts; balances represented on Robinhood must not also be counted as separate L1 capital.

Rocket Pool · ≥ D2

Oracle reporting and upgrade governance add dependencies; the complete current emergency and delay boundaries remain under review.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

rsETH · D9

The issuer documents per-address transfer holds and recovery of frozen balances to custody.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Sablier Flow · ≥ D1

The fixed streaming mechanism has bounded Comptroller administration. Stream participants retain contractual pause/refund powers, and asset controls remain separate. At least D1 for the family; assess each stream configuration.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Sablier Lockup · ≥ D1

Distribution code is non-upgradeable and the protocol admin cannot pause streams or seize user funds. Comptroller settings, fees and hook permissions remain; cancellation and token dependencies vary by stream. At least D1 for the current family.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Scroll · D7

The team admin multisig holds immediate upgrade authority, while public proving and L1 inclusion provide ordinary operator-failure fallbacks.

Évaluation révisée:

Scroll mainnet, chain ID 534352; reviewed current authority and permissionless fallback routes.

Validation: ZK proofs; public software supports independent proposals.

Upgrades: Team-controlled ScrollAdminMultisig can use the zero-delay emergency path.

Accountability: The reviewed governance record describes replacement of the independent council in June 2026; token voting does not directly execute upgrades.

Exits: Forced inclusion and self-proposal exist, but an immediate upgrade can bypass an exit window.

Authority, not a maturity stage, determines D7. Later council changes require a fresh review of actual on-chain powers.

Seaport 1.6 · D0

The canonical nonproxy Seaport 1.6 settlement core has no administrator, pause or implementation replacement path. Order makers choose assets, zones, conduits and contract offerers; those selected dependencies are separate reviews.

Évaluation révisée:

Canonical immutable Ethereum settlement core; excludes unreviewed zones, conduit channels, NFT contracts and contract offerers.

sfrxETH · D0

The yield wrapper inherits frxETH and its staking system.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

Sky / Maker · D3

Governance controls issuance, collateral policy, and system changes through executive actions.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Soneium · D8

Permissioned state proposals and challenges make ordinary exits depend on designated operators, in addition to immediate Foundation/council upgrades.

Évaluation révisée:

Soneium mainnet, chain ID 1868; protocol authority, not website terms alone.

Validation: Only designated proposers/challengers participate. The reviewed discovery reports a placeholder dispute prestate, not an independently executable fault-proof route.

Upgrades: Optimism Foundation and Security Council control upgrades without an enforced exit window.

Accountability: Shared Optimism governance does not make Soneium validation permissionless.

Exits: L1 inclusion exists; withdrawals can still stop when designated proposers stop.

The deployment review carries an upstream change warning; the permissioned validation and exit dependency is the controlling D8 finding.

Spark Liquidity Layer · ≥ D3

Governance controls allocation across destinations; each destination can add further administration or custody.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Spark Savings · ≥ D3

Savings and allocation contracts inherit Sky governance; destination-specific custody may add stronger restrictions.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

SparkLend · D3

Governance can upgrade the pool and execute changes after the governance delay.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Starknet · D8

Validity proofs constrain state correctness, but users still need permissioned operators or a council minority to get censored transactions processed.

Évaluation révisée:

Starknet mainnet core and mapped canonical asset routes; ancillary bridge escrows may have separate administration.

Validation: STARK-based validity proofs; state updates require a designated operator.

Upgrades: Core normal route: StarkWare multisig with eight-day delay. A 9/12 appointed council can act immediately; other bridge escrows have separate immediate administrators.

Accountability: Foundation-appointed council; token votes do not create permissionless execution rights.

Exits: L1 complaints cannot force execution. A 3/12 council minority can intervene, so independent exit still depends on that group.

D8 follows the exit/validation dimension despite stronger safeguards on the ordinary core upgrade path. Bridge-specific rights and proof assumptions remain separate risks.

stETH · ≥ D0

The stETH claim inherits Lido governance, oracle and withdrawal arrangements.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

sUSDe · D9

The staking receipt retains USDe’s custodial-backing dependencies.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

sUSDS · ≥ D3

The savings contract inherits USDS governance, collateral backing and its own upgrade arrangements.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

tBTC · ≥ D2

BTC redemption relies on an external threshold-signing network; governance and bridge safeguards add dependencies.

Évaluation révisée:

Canonical token mechanism; deployment-specific custody adds inherited bounds.

0x Protocol token · D0

Nonproxy ZRX initializes a fixed supply and exposes holder-authorized ERC20 transfers and allowances. No privileged mint, freeze or replacement path exists. Exchange protocol contracts are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

1INCH token · D0

Matched nonproxy OneInch code restricts mint and ownership changes to onlyOwner. The live owner is zero, making those paths permanently unreachable; the complete inherited ERC20/permit/burn code has no alternative mint, freeze, upgrade or controller path. Runtime was independently matched at the recorded block. This token holding is separate from router pauses and orders.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Aave token · ≥ D3

AAVE is an admin-upgradeable token, currently resolved to AaveTokenV3. The EIP1967 admin slot is nonzero. Implementation replacement can change balance/transfer rules; complete the admin execution, delay and emergency paths before assigning a complete grade. Aave lending versions are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Aerodrome Finance token · ≥ D1

Native AERO on Base chain 8453 has a changeable minter and mint path. This is not an Ethereum-mainnet ERC20. Close minter/controller roles and compose Base chain authority; Aerodrome pools and bridged representations are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 8453; excludes protocol positions and unreviewed representations.

Arbitrum token · ≥ D3

Ethereum ARB is an upgradeable L1 bridge representation with a nonzero proxy admin. Its gateway can mint and burn balances. Close gateway custody, native ARB backing and DAO/council upgrade timing; Arbitrum chain governance is a separate reviewed dependency.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Balancer token · ≥ D1

BAL has fixed token transfer code. Live enumeration found zero default admins and one minter; the initial admin-grant power is therefore absent. Close the remaining minter contract and its reachable issuance/controller path before a complete holding grade. Balancer vaults, pools and emergency roles are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Basic Attention token · D0

Nonproxy BAT is irreversibly finalized: live isFinalized() returned true and source provides no reset. Crowdsale creation/refund paths are disabled thereafter. Ordinary transfers have no administrator, freeze or replacement path. Brave services are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Chainlink token · D0

Fixed-supply nonproxy LINK transfer code has no privileged mint, pause, confiscation or implementation replacement. ERC677 callbacks are selected by the sending holder; Chainlink oracle and staking contracts are separate mechanisms.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Compound token · D0

Nonproxy COMP mints its fixed supply in the constructor. Transfers and governance delegation do not give a controller power to mint, seize, pause or replace token balances. Compound lending markets are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

CoW Protocol token · D1

COW has nonproxy transfer code and a fixed CoW DAO authority for minting, capped at 3% per year. The simulation delegatecall always reverts, including state changes; it is not an implementation upgrade path. Settlement solvers and orders are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Curve DAO token · ≥ D1

CRV source bounds emissions by its supply schedule and once-set minter. Admin can change token metadata/admin, not replace transfer code. Close the live minter and admin identity path before completing the holding review; Curve pools and gauges are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

EigenCloud (prev. EigenLayer) token · ≥ D3

EIGEN is a transparent proxy with a nonzero live admin. Current Eigen code wraps bEIGEN and contains issuance/transfer-restriction state. Complete proxy admin timing, restriction state and the bEIGEN backing/controller path before a complete holding grade.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Ethena token · D1

ENA is a nonproxy token with owner issuance capped at 10% of supply per mint after a 365-day interval. The source provides no owner freeze or replacement of ordinary transfer balances. ENA is separate from issuer-controlled USDe backing/redemption.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Ether.fi token · D0

Nonproxy ETHFI has constructor-only issuance. Burn and permit require the holder or their allowance/signature; vote delegation does not control transfers. No external administrator or upgrade entry point exists in the reachable token implementation. Ether.fi staking is separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Ethereum Name Service token · D1

ENS has fixed nonproxy transfer code and owner minting capped at 2% of supply per mint with a 365-day interval. Registrar, resolver and DAO execution powers are separate from the token holding.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Golem token · ≥ D0

GLM inherits a minter role that can add minters and issue tokens. Constructor grants the migration agent that role and renounces the deployer role. Active minter membership and migration-agent authority are unresolved: neither permanent D0 nor an active inflation controller is established by this source review.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Synthetix token · ≥ D3

SNX uses legacy ProxyERC20 owner-controlled target replacement and optional delegatecall. Live owner and target are nonzero even though the source provider reports no detected proxy. Close target, TokenState and governance timing before a complete holding grade.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Lido DAO token · ≥ D3

LDO MiniMe token delegates transfer/mint/burn/enableTransfers controls to a controller. The live controller is the Lido Aragon TokenManager, whose implementation can change through governance. Close governance delay/veto/emergency paths; LDO is separate from stETH and staking custody.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Loopring token · D0

Nonproxy LRC_v2 has fixed constructor supply. Batch transfers spend the caller balance and burns spend the holder balance or allowance. No privileged mint, pause or upgrade path exists. Loopring exchange and L2 custody are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Morpho token · ≥ D3

MORPHO is an ERC1967/UUPS token. Current MorphoTokenEthereum code permits owner minting and owner-authorized upgrades; live owner() is nonzero. Controller execution and timing remain unresolved. The immutable Morpho Blue lending core does not make MORPHO token D0.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Optimism token · ≥ D1

Native OP on chain 10 has owner-only minting. This is not an Ethereum-mainnet ERC20. Close the owner/issuance path and compose Optimism chain authority; an unknown bridged OP deployment cannot inherit this address review.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 10; excludes protocol positions and unreviewed representations.

Pendle token · ≥ D1

PENDLE governance can alter emissions, inflation, destination and voluntary burn configuration after a hardcoded seven-day config delay. The live governance path remains unresolved. These issuance/configuration powers are separate from Pendle markets and yield-bearing positions.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Rocket Pool token · ≥ D1

RPL token inflation consults RocketStorage and protocol settings; constructor-fixed token code alone does not close that dependency. Review live inflation settings, RocketStorage authority and the reachable replacement paths. RETH backing and node staking are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Safe token · D0

Nonproxy SAFE has fixed constructor supply and can only unpause once. The live paused() check returned false; no function can pause again. Owner rescue operates on assets accidentally sent to the token contract, and SAFE transfers to that contract are prohibited. Safe wallets and governance are separate.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Sushi token · ≥ D1

SUSHI token has an owner-only mint path without a token-level supply cap. The live owner and its reachable controller powers remain a monthly closure task. Sushi pools and farms have separate identities.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

The Graph token · ≥ D1

GRT exposes governor-controlled minter membership and minting in nonproxy token code. The governor/minter authority path still needs live closure. Graph staking, indexing and curation are separate mechanisms.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

Uniswap token · D1

UNI has fixed nonproxy transfer code but a changeable minter can issue at most 2% of supply per mint, with at least 365 days between mints. These issuance settings prevent permanent D0 for UNI; Uniswap v1-v4 cores are separate identities.

Évaluation révisée:

Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.

TUSD token · D9

Issuer controls reserve custody and redemption and can restrict/freeze accounts. The legacy OwnedUpgradeabilityProxy is replaceable even when automated proxy detection is negative.

Évaluation révisée:

Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.

Unichain · D5

Council and Foundation approval are required for upgrades. The documented three-party owner also includes Unichain; a proposed two-party transition does not remove the Foundation/council trust.

Évaluation révisée:

Unichain mainnet, chain ID 130; both documented owner arrangements retain the same D5 authority category.

Validation: Permissionless fault proofs and self-proposal; Ethereum data availability.

Upgrades: Current documented 3/3 owner: Unichain, Foundation and Council. September proposal removes Unichain from that owner set; execution is not independently confirmed here.

Accountability: Optimism governance/council model with Foundation safeguards and fallback roles.

Exits: L1 forced inclusion; immediate upgrades have no enforced exit window.

A proposal is not treated as an executed upgrade. The classification is unchanged under either documented owner arrangement.

Uniswap, unspecified version · D?

A version and pool scope are required; a brand-wide tier would conceal hook and wrapper differences.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

Uniswap V1 · D0

Canonical v1 exchanges have fixed exchange and withdrawal code, with no protocol administrator able to replace the core. Token controls remain separate.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

Uniswap v2 · D0

Core pool custody and LP exits are immutable; token controls are assessed separately.

Évaluation révisée:

Authentic v2 core pairs; excludes token issuers, routers with custody, hosted interfaces, and external staking wrappers.

Uniswap v3 · D0

Core pool custody and LP exits are immutable; token controls are assessed separately.

Évaluation révisée:

Authentic v3 core pools; excludes frontends, managed positions, and asset-issuer dependencies.

Uniswap v4 · D0

The Uniswap v4 PoolManager core is D0: its custody and settlement code cannot be upgraded. Protocol fees do not permit replacement of principal or withdrawal logic. Optional hooks can change a pool’s behavior; the aggregate holdings feed does not identify them, so those positions retain incomplete dependency reviews.

Évaluation révisée:

Canonical immutable PoolManager core. Pool hooks and token controls are assessed separately for each position.

USD1 token · D9

BitGo issuance, custody of reserves and offchain redemption establish issuer-controlled backing. Current proxy/source adds privileged mint/freeze/upgrade powers.

Évaluation révisée:

Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.

USDC · D9

Circle controls token blocking and the offchain reserves needed for redemption.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

USDe · D9

Backing depends on custodial and exchange operations with permissioned direct redemption.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

USDG · D9

Paxos controls reserve redemption and can freeze or wipe token balances.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

USDP · D9

Paxos issuer custody and asset-protection controls remain part of the asset.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

USDS · ≥ D3

Upgradeable issuance inherits Sky governance and the collateral backing used by the system.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

USDT · D9

Tether can freeze and destroy balances and controls redemption of the backing.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

USDY · D9

A permissioned issuer claim backed by Treasury assets and bank deposits; redemption depends on Ondo and its custodians.

Évaluation révisée:

Canonical token mechanism; deployment-specific custody adds inherited bounds.

USYC · D9

Tokenized fund shares depend on the fund manager, custody, investor eligibility and redemption rules.

Évaluation révisée:

Canonical token mechanism; deployment-specific custody adds inherited bounds.

WBETH · D9

The token represents ETH staked through Binance and inherits its custodial service.

Évaluation révisée:

Canonical deployed product; additional asset and chain dependencies compose separately.

WBTC · D9

BTC backing is held by institutional custodians and redeemed through authorized merchants.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

weETH · D0

The wrapper preserves eETH staking and restaking dependencies.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

WETH · D0

The canonical WETH9 wrapper has fixed deposit and withdrawal rules and no privileged owner.

Évaluation révisée:

Canonical Ethereum WETH9 only; same ticker on another chain or contract is not covered.

World Chain · D8

Permissioned dispute participation and immediate upgrades leave ordinary settlement and exits dependent on privileged actors.

Évaluation révisée:

World Chain mainnet, chain ID 480; chain protocol, not World ID biometric privacy.

Validation: Permissioned fault-proof games; one entity may propose and challenge in the reviewed deployment.

Upgrades: Immediate proxy upgrades and guardian powers remain.

Accountability: No permissionless participation is inferred from OP Stack or Superchain membership.

Exits: L1 inclusion exists, but designated proposers are still needed to advance withdrawal state.

The upstream review flags ongoing changes. This is a chain-authority review, not an assessment of identity products.

wstETH · D0

The fixed wrapper preserves the stETH and Lido dependencies underneath it.

Évaluation révisée:

Ethereum mainnet deployment; asset-level dependencies assessed separately.

XAUT · D9

Tether controls issuance and redemption of claims on physical gold held in custody.

Évaluation révisée:

Canonical token mechanism; deployment-specific custody adds inherited bounds.

Yearn V3 · ≥ D2

Allocator vault managers select strategies, debt allocations, accountants and withdrawal-limit modules. The fixed vault code alone does not make the managed position D0; at least D2 until each deployment and strategy is resolved.

Évaluation révisée:

Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.

ZKsync Era · D8

Delayed governance and a joint emergency board coexist with operator filtering and permissioned proposals that can block ordinary exits.

Évaluation révisée:

ZKsync Era, chain ID 324; includes shared Gateway and operator filtering dependencies.

Validation: Validity proofs constrain state; batch proposal and approval remain permissioned.

Upgrades: Normal DAO path has delays; Council, Guardians and Foundation can jointly execute an immediate emergency upgrade.

Accountability: Multiple governance bodies constrain upgrades, without removing operator-level censorship powers.

Exits: L1 queue cannot compel processing. An operator-installed transaction filter can censor withdrawals without delay.

The stronger upgrade process is recorded, but the controlling exit dimension is D8.

Téléchargements de données

Observation datée la plus ancienne: 29 sept. 2026, 00:55 UTC.

Certaines dates sources sont indisponibles.

Notes de comptabilisation · Notes des sources (anglais)
  • Aave and Morpho positions use provider-adjusted underlying reserves, excluding borrowed funds and specified recursive or issuer claims. These are reserve estimates rather than gross supplied balances.
  • Stablecoin circulation is already USD-valued and adjusts canonical source-chain escrow. Bridge backing is not subtracted a second time.
  • Asset identities come from reviewed source IDs and chain-specific evidence. A matching ticker alone does not establish token identity.
  • Uniswap and selected vaults can allocate directly measured token balances by chain, contract and owner address. Synthetic compositions, pool TVL and fully diluted values never create monetary inventory.
  • Negative or conflicting source balances are excluded. Asynchronous source observations and provider rounding limit attribution precision.
  • ETH in wallets & exchanges on L1 is the residual estimate after identified protocol, staking and bridge positions, not an address census. It includes ETH held by centralized exchanges and other custodians, and untracked contracts and bridges can remain in it. Native ETH has on-chain rating D0; holder custody is outside the rating scope.
  • Circulation uses a $1 million asset/chain cutoff. Protocol feeds use a $5 million TVL cutoff; selected pool discovery starts at $1 million. Direct custody balances add detail independently. Coverage is partial, not exhaustive.
  • L2 represented ETH uses the greater of covered canonical backing and directly located protocol reserves, with protocol positions carved out of the same inventory. It is a partial coverage bound, not total rollup TVS.
  • The staking halo subtracts tracked liquid-staking ETH backing once. Conversion uses provider LST/ETH price ratios as estimates, not audited redemption rates. Untracked backing may remain in the halo.
  • The staking aggregate sums validator balances from a finalized Ethereum consensus state, including balances awaiting withdrawal. Its slot determines the observation timestamp; price changes and failed requests do not renew it.
  • Tokenized Bitcoin counts the supply issued on each chain, read from its token contracts at one pinned block per chain. Copies bridged from Ethereum count where they circulate and are netted out of Ethereum’s supply. Selected utility/governance tokens cover measured reserves, not full minted supply, global market capitalization or complete wallet balances. New contract identities do not imply completed control reviews.
  • Financial observation dates, collection time and control-registry review dates are separate. Failed source requests retain prior useful observations.
  • ETH supply uses dated CoinGecko circulating supply, with ultrasound.money’s dated supply estimate as an independent fallback. The selected source remains attached to the residual inventory. Stablecoin bulk circulation has no measurement timestamp and remains explicitly undated.