On-Chain Evidence Review

USD Coin (USDC)

CENTRALIZED - DOCUMENTED|15/100
Ethereum·0xa0b869...06eb48token
LiveLast scanned 10 July 2026
Run your own scan
Why this example?

USDC is a widely used regulated stablecoin with published governance and operational controls. It demonstrates how XemaS distinguishes between legitimate administrative authority and malicious attack surfaces using verifiable on-chain evidence. Administrative controls that would be high-risk in an anonymous contract are well-attributed and compliant here.

Evidence Summary

What the evidence shows

Ownership

VERIFIED

Circle-controlled ProxyAdmin

Centralized by design; ownership is attributed to Circle Internet Financial.

Mint Authority

VERIFIED

Active - Circle masterMinter role

Required for stablecoin redemption mechanics. Minting is Circle-operated, not anonymous.

Liquidity

VERIFIED

$4B+ across Uniswap, Curve, and Aave pools

Extremely deep. No single pool concentration risk.

Holder Attribution

PARTIAL

7.9M+ holders; top 20 custodians attributed

Polygon Bridge (2.39%) and exchange custody wallets attributed. Top single holder: 8.66% anonymous address - unattributed in entity registry. Retail long tail unattributed.

Proxy / Upgradeability

VERIFIED

EIP-1967 transparent proxy; Circle admin can upgrade

Implementation upgrades are Circle-controlled. Required for regulatory and operational iteration.

Governance Controls

VERIFIED

Pausable; OFAC blacklist active

Blacklist and pause functions are operational. These are regulatory compliance features.

Findings

What XemaS found

USDC is deployed as a transparent proxy pointing to Circle's FiatTokenV2_1 implementation. The ProxyAdmin address is a Circle-controlled multisig. The upgrade pathway exists and is by design - Circle can push implementation changes to maintain regulatory compliance and operational improvements. This is a documented and intentional architectural choice, not a hidden backdoor.

The mint authority is held by Circle's masterMinter role, which authorises specific minter addresses to mint up to their configured allowance. In practice, minting occurs when users deposit USD with Circle or an authorised partner and receive USDC in return. The same mechanism handles redemptions in reverse. The supply is not fixed and can expand or contract as demand changes.

An active OFAC blacklist allows Circle to freeze specific addresses to comply with US Treasury sanctions requirements. As of the scan date, a small number of addresses have been blacklisted, consistent with Circle's published compliance obligations. The pause function allows Circle to halt all USDC transfers globally if legally required - this has never been triggered on mainnet.

Holder attribution covers the major institutional holders. The Polygon Bridge (2.39%) is excluded from concentration analysis as a custody dependency. The single largest holder holds 8.66% of total supply with no entity label in the registry - this address is not attributed at scan time and represents the most significant open verification gap. Total registered holder count is 7.9M. Institutional custodians (exchange cold wallets, DeFi protocol reserves) account for the bulk of the attributed supply. The retail long tail was not individually attributed - this is expected and does not affect the risk assessment.

Interpretation

Why it matters

The primary risk in holding USDC is counterparty risk with Circle and Coinbase, not smart contract mechanics. Circle can theoretically freeze your address, upgrade the contract, or pause transfers. These powers exist and are real. The mitigation is Circle's regulatory accountability: they are a licensed US money services business subject to audits and regulatory oversight. For the vast majority of use cases, counterparty risk with a regulated entity is acceptable.

Evidence

Evidence table

FactState
Proxy implementation slot (EIP-1967)VERIFIED
ProxyAdmin address attributionVERIFIED
masterMinter role holderVERIFIED
Active minter allowancesVERIFIED
Blacklist state - sampled top holdersVERIFIED
Pause stateVERIFIED
Liquidity pool balancesVERIFIED
Top-20 holder attributionPARTIAL
Static analysis - Timestamp DependenceVERIFIED
Sanctions match (contract + top holders)VERIFIED
Honest Limits

What was not visible

Off-chain reserve verification

XemaS verifies on-chain supply and contract state only. Reserve backing (USD held by Circle) is off-chain and not independently verifiable by this scan. Circle publishes monthly attestations by Grant Thornton.

Regulatory risk is not on-chain

Circle's US money services business licence, banking relationships, and regulatory standing are off-chain facts. A regulatory action against Circle would not be visible in on-chain evidence before it takes effect.

Blacklist is dynamic

The blacklist state was checked at scan time. Circle can blacklist any address at any time post-scan. This page captures a point-in-time snapshot.

Holder attribution is partial

The retail long tail of 290k+ holders was not individually attributed. Concentration analysis covers the top 50 holders only.

Largest holder is unattributed

The single address holding 8.66% of USDC supply has no entity label in the registry at scan time. This is the most significant open verification gap. The address could be an exchange omnibus wallet, a custodian, or an institutional holder not yet in the label database.

Evidence freshness

This scan was run on 2026-07-10. On-chain state changes continuously. Run a fresh scan for current supply, pool balances, and blacklist state.

Investigation series

Same framework, different evidence

CRITICALBNB Chain

Squid Game Token (SQUID)

Anonymous deployer, honeypot transfer logic, no liquidity lock. Risk score 97.

DEPEG - RESTOREDEthereum

USDC / SVB Depeg (2023)

A banking failure priced on-chain in hours: $3.3B reserve exposure, ~$0.88 low, DAI contagion, information-driven recovery.

EXPLOITED - RETURNEDEthereum

Euler Finance Exploit (2023)

A governance upgrade skipped one health check: ~$197M drained via donate-and-self-liquidate, then returned over three weeks.

EXPLOITED - PARTIAL RECOVERYEthereum

Nomad Bridge Hack (2022)

One zeroed initialization parameter made verification a no-op: ~$190M drained permissionlessly by hundreds of copycat addresses.

EXPLOITED - PARTIAL RECOVERYEthereum / Ronin

Ronin Bridge Hack (2022)

Five of nine validator keys compromised: 173,600 ETH and 25.5M USDC drained in two forged withdrawals and undetected for 6 days. Attributed to Lazarus Group by US Treasury.

EXPLOITED - NO RECOVERYEthereum / Harmony

Harmony Horizon Bridge Hack (2022)

Two of five validator keys compromised: ~$100M drained 91 days after Ronin, moved through Tornado Cash within hours. Same attacker group; complete loss. Attributed to Lazarus Group by FBI and OFAC.

EXPLOITED - PARTIAL RECOVERYSolana

Mango Markets Oracle Manipulation (2022)

No code exploit: oracle assumptions failed. MNGO oracle price inflated ~30x; $116M borrowed against manufactured collateral. Conviction: Avraham Eisenberg, SDNY, April 2024.

EXPLOITED - NO RECOVERYEthereum

Beanstalk Farms Governance Exploit (2022)

No code exploit: governance assumptions failed. Flash-borrowed supermajority passed a malicious BIP in one block; $182M drained with no execution delay to stop it. Complete loss.

COMPLEXEthereum

Aave (AAVE)

DAO governance with proxy upgradeability and delegate concentration. Risk score 13.

Get started

Scan any address with the same evidence engine

EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.

Scan a token or wallet

No account required for a first scan.