How Does Zoth Protocol Work?
Zoth Protocol is an RWA stablecoin and yield vault platform that issues ZeUSD (a CDP stablecoin backed by U.S. Treasuries and tokenized RWA assets) and zVaults (KYC-gated yield vaults managed by institutional strategy providers including BlackOpal and Superstate). The protocol suffered two exploits within 21 days in March 2025 — a $285K logic flaw and a critical $8.4M admin key compromise that drained USD0++ tokens from an upgradeable proxy vault — causing TVL to collapse approximately 92% from a peak of $29.3M to $2.2M with no recovery. Its C- grade reflects the confirmed major exploit on current-codebase contracts (maximum track record penalty), a critical upgradeable proxy admin key risk, custom RWA oracle dependency, and significant regulatory concentration from KYC-gated access and regulated custodian dependencies. The ZOTH governance token has not yet launched.
TVL
$2M
Sector
RWA
Risk Grade
C-
Value Grade
D-
Core Mechanisms
Stablecoin > CDP with RWA Collateral
ZeUSD: overcollateralized stablecoin minted via CDP against eligible RWA collateral (USYC, USD0++, TBILL, wSTBT, Wrapped $M); deployed on Ethereum, bridged to Base, Manta Pacific, Metis Andromeda, Avalanche via Wormhole NTT OFT
CDP stablecoins backed by tokenized RWA assets exist at Maker/Sky (accepting T-bills as collateral), Frax, and others. Multi-collateral RWA CDPs are a known mechanism pattern.
Yield > NAV-Appreciating Vault with Fund Manager Strategy
zVaults: yield-bearing vaults where NAV appreciates as fund managers execute strategies (LiquidStone II credit strategy via BlackOpal, market-neutral basis trading via Superstate); whitelisted KYC access; up to 16% APY advertised
Fund-manager-backed DeFi vaults with NAV appreciation (similar to Maple Finance, Goldfinch, Clearpool) are a known pattern. KYC-gated access is standard for regulated RWA products.
Infrastructure > Upgradeable Proxy Contract
USD0PPSubVaultUpgradeable and other vault contracts use OpenZeppelin upgradeable proxy pattern; admin key controls upgrade authority — this was the attack surface in the March 2025 $8.4M exploit
Upgradeable proxies are a standard but high-risk DeFi pattern. When admin key custody fails (as it did for Zoth in March 2025), the upgrade authority enables complete asset draining.
Bridge > Omnichain Fungible Token (OFT)
ZeUSD omnichain deployment via Wormhole NTT (Native Token Transfer); enables ZeUSD minting/burning on Ethereum with bridged supply on Base, Manta, Metis, Avalanche
Wormhole NTT / LayerZero OFT are standard cross-chain token bridge patterns.
Compliance > KYC/KYB-Gated Access Control
KYC Manager contract gates vault access; whitelisted addresses only for zVaults; embedded AML compliance; Canadian FINTRAC MSB registration (June 2026)
KYC-gated DeFi access is standard for regulated RWA and institutional products (Ondo, Maple, Centrifuge).
How the Pieces Interact
The March 21, 2025 exploit proved this interaction: an attacker who gained access to the deployer wallet key upgraded the USD0PPSubVaultUpgradeable proxy contract and drained $8.4M in USD0++ tokens in a single transaction. Upgradeable proxies with unprotected admin keys are a direct path to total loss of all assets in the vault. If other vault proxy admin keys share the same key custody setup, the remaining TVL faces the same attack surface.
ZeUSD is backed by RWA collateral that includes USD0++ (Usual Protocol), USYC (Hashnote), and other DeFi/RWA assets. If any collateral asset depegs, defaults, or is frozen by its issuer, ZeUSD's backing is impaired — potentially below 1:1 USDS coverage. The March 2025 hack directly exploited USD0++ holdings; Usual Protocol's USD0++ has its own de-anchor risk from its 4-year lock mechanism.
ZeUSD is bridged to four additional chains via Wormhole NTT. A Wormhole bridge exploit (Wormhole suffered a $320M exploit in February 2022) could enable unbacked ZeUSD minting on any chain, diluting the collateral backing on Ethereum. The cross-chain surface multiplies the attack surface for a stablecoin whose backing is concentrated on a single chain (Ethereum).
ZeUSD and zVault access require KYC whitelisting. During a ZeUSD peg stress event, non-whitelisted market participants cannot arbitrage the peg back to $1, severely limiting the peg stability mechanism. If secondary market ZeUSD holders are unable to redeem directly (KYC gated), they can only sell at a discount — amplifying any depeg event.
zVaults depend on off-chain fund managers (BlackOpal, Superstate) executing strategies that generate the 16% APY yield. If a manager fails to execute or underperforms, vault NAV stagnates but withdrawals are subject to lockup periods and KYC-only access — users cannot exit to secondary markets. This creates a trapped capital scenario in a fund manager failure event.
What Could Go Wrong
- The protocol suffered two exploits within 21 days in March 2025, losing approximately $8.4M total — including an $8.4M admin private key compromise that drained USD0++ tokens from the USD0PPSubVaultUpgradeable proxy contract. The deployer wallet's key was stolen, enabling the attacker to upgrade the proxy and drain assets. Upgradeable proxy contracts with non-timelock admin keys remain the primary attack surface in the current architecture.
- The protocol prices heterogeneous RWA collateral types (USYC, USD0++, TBILL, wSTBT, Wrapped $M) using a custom oracle system (KYC Manager + Oracle + Registry infrastructure). Custom RWA price oracles are not independently verified by Chainlink or industry-standard feeds, making manipulation or stale pricing a structural risk for ZeUSD's collateral valuation.
- ZeUSD, the protocol's stablecoin, depends on regulated custodians and asset issuers for all underlying RWA backing. Regulatory action against any partner (USYC issuer Hashnote, Usual Protocol for USD0++, etc.) or ZeUSD itself could result in asset freezing — the asset issuers locked down 73% of remaining TVL after the March 2025 hack, demonstrating this centralized control.
- TVL declined approximately 92% from the pre-hack peak of $29.3M to $2.2M, with no meaningful recovery over 15+ months. The protocol is operationally active (ongoing development, FINTRAC MSB registration, new product lines) but commercially fading — exit liquidity for remaining vault positions is limited.
Admin Key Compromise Draining Remaining Vault Assets
ElevatedTrigger: An attacker gains access to the proxy admin key controlling any remaining zVault upgradeable contract, enabling a malicious upgrade similar to the March 21, 2025 exploit that drained $8.4M
- 1.Attacker gains access to proxy admin key (social engineering, phishing, or reuse of compromised keys from March 2025 incident) — Attacker can call upgradeProxy() on any vault proxy that has not been migrated to a multisig/timelock admin setup since the March 2025 remediation
- 2.Malicious implementation contract deployed; proxy upgraded to drain vault assets — All deposited RWA collateral or vault LP tokens drained in a single transaction; KYC-gated access prevents rapid community response
- 3.Drained assets (likely USYC, wSTBT, or other RWA collateral) sold or bridged to attacker wallet — ZeUSD backing collapses proportionally; if ZeUSD was minted against drained collateral, ZeUSD becomes undercollateralized
- 4.RWA asset issuers may freeze stolen assets (as occurred with 73% frozen in March 2025), but attacker avoids KYC-controlled assets by targeting liquid DeFi assets in vault — Frozen assets provide partial but incomplete recovery; unrecovered portion becomes a ZeUSD bad debt
- 5.TVL collapses from $2.2M to near zero; team announces investigation and bounty (as in March 2025) — Protocol enters second existential crisis; recovery unlikely given prior unsuccessful recovery attempt; remaining users cannot exit KYC-gated vaults until protocol completes wind-down
Risk Profile at a Glance
Overall: C- (54/100)
Lower score = safer