USD Coin (USDC)
USDC is a widely used regulated stablecoin with published governance and operational controls. It demonstrates how XemaS distinguishes between legitimate administrative authority and malicious attack surfaces using verifiable on-chain evidence. Administrative controls that would be high-risk in an anonymous contract are well-attributed and compliant here.
What the evidence shows
Ownership
Circle-controlled ProxyAdmin
Centralized by design; ownership is attributed to Circle Internet Financial.
Mint Authority
Active - Circle masterMinter role
Required for stablecoin redemption mechanics. Minting is Circle-operated, not anonymous.
Liquidity
$4B+ across Uniswap, Curve, and Aave pools
Extremely deep. No single pool concentration risk.
Holder Attribution
7.9M+ holders; top 20 custodians attributed
Polygon Bridge (2.39%) and exchange custody wallets attributed. Top single holder: 8.66% anonymous address - unattributed in entity registry. Retail long tail unattributed.
Proxy / Upgradeability
EIP-1967 transparent proxy; Circle admin can upgrade
Implementation upgrades are Circle-controlled. Required for regulatory and operational iteration.
Governance Controls
Pausable; OFAC blacklist active
Blacklist and pause functions are operational. These are regulatory compliance features.
What XemaS found
USDC is deployed as a transparent proxy pointing to Circle's FiatTokenV2_1 implementation. The ProxyAdmin address is a Circle-controlled multisig. The upgrade pathway exists and is by design - Circle can push implementation changes to maintain regulatory compliance and operational improvements. This is a documented and intentional architectural choice, not a hidden backdoor.
The mint authority is held by Circle's masterMinter role, which authorises specific minter addresses to mint up to their configured allowance. In practice, minting occurs when users deposit USD with Circle or an authorised partner and receive USDC in return. The same mechanism handles redemptions in reverse. The supply is not fixed and can expand or contract as demand changes.
An active OFAC blacklist allows Circle to freeze specific addresses to comply with US Treasury sanctions requirements. As of the scan date, a small number of addresses have been blacklisted, consistent with Circle's published compliance obligations. The pause function allows Circle to halt all USDC transfers globally if legally required - this has never been triggered on mainnet.
Holder attribution covers the major institutional holders. The Polygon Bridge (2.39%) is excluded from concentration analysis as a custody dependency. The single largest holder holds 8.66% of total supply with no entity label in the registry - this address is not attributed at scan time and represents the most significant open verification gap. Total registered holder count is 7.9M. Institutional custodians (exchange cold wallets, DeFi protocol reserves) account for the bulk of the attributed supply. The retail long tail was not individually attributed - this is expected and does not affect the risk assessment.
Why it matters
The primary risk in holding USDC is counterparty risk with Circle and Coinbase, not smart contract mechanics. Circle can theoretically freeze your address, upgrade the contract, or pause transfers. These powers exist and are real. The mitigation is Circle's regulatory accountability: they are a licensed US money services business subject to audits and regulatory oversight. For the vast majority of use cases, counterparty risk with a regulated entity is acceptable.
Evidence table
| Fact | State |
|---|---|
| Proxy implementation slot (EIP-1967) | VERIFIED |
| ProxyAdmin address attribution | VERIFIED |
| masterMinter role holder | VERIFIED |
| Active minter allowances | VERIFIED |
| Blacklist state - sampled top holders | VERIFIED |
| Pause state | VERIFIED |
| Liquidity pool balances | VERIFIED |
| Top-20 holder attribution | PARTIAL |
| Static analysis - Timestamp Dependence | VERIFIED |
| Sanctions match (contract + top holders) | VERIFIED |
What was not visible
Off-chain reserve verification
XemaS verifies on-chain supply and contract state only. Reserve backing (USD held by Circle) is off-chain and not independently verifiable by this scan. Circle publishes monthly attestations by Grant Thornton.
Regulatory risk is not on-chain
Circle's US money services business licence, banking relationships, and regulatory standing are off-chain facts. A regulatory action against Circle would not be visible in on-chain evidence before it takes effect.
Blacklist is dynamic
The blacklist state was checked at scan time. Circle can blacklist any address at any time post-scan. This page captures a point-in-time snapshot.
Holder attribution is partial
The retail long tail of 290k+ holders was not individually attributed. Concentration analysis covers the top 50 holders only.
Largest holder is unattributed
The single address holding 8.66% of USDC supply has no entity label in the registry at scan time. This is the most significant open verification gap. The address could be an exchange omnibus wallet, a custodian, or an institutional holder not yet in the label database.
Evidence freshness
This scan was run on 2026-07-10. On-chain state changes continuously. Run a fresh scan for current supply, pool balances, and blacklist state.
Same framework, different evidence
Squid Game Token (SQUID)
Anonymous deployer, honeypot transfer logic, no liquidity lock. Risk score 97.
USDC / SVB Depeg (2023)
A banking failure priced on-chain in hours: $3.3B reserve exposure, ~$0.88 low, DAI contagion, information-driven recovery.
Euler Finance Exploit (2023)
A governance upgrade skipped one health check: ~$197M drained via donate-and-self-liquidate, then returned over three weeks.
Nomad Bridge Hack (2022)
One zeroed initialization parameter made verification a no-op: ~$190M drained permissionlessly by hundreds of copycat addresses.
Ronin Bridge Hack (2022)
Five of nine validator keys compromised: 173,600 ETH and 25.5M USDC drained in two forged withdrawals and undetected for 6 days. Attributed to Lazarus Group by US Treasury.
Harmony Horizon Bridge Hack (2022)
Two of five validator keys compromised: ~$100M drained 91 days after Ronin, moved through Tornado Cash within hours. Same attacker group; complete loss. Attributed to Lazarus Group by FBI and OFAC.
Mango Markets Oracle Manipulation (2022)
No code exploit: oracle assumptions failed. MNGO oracle price inflated ~30x; $116M borrowed against manufactured collateral. Conviction: Avraham Eisenberg, SDNY, April 2024.
Beanstalk Farms Governance Exploit (2022)
No code exploit: governance assumptions failed. Flash-borrowed supermajority passed a malicious BIP in one block; $182M drained with no execution delay to stop it. Complete loss.
Aave (AAVE)
DAO governance with proxy upgradeability and delegate concentration. Risk score 13.
Scan any address with the same evidence engine
EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.
Scan a token or walletNo account required for a first scan.