//Zoth Protocol
C-

Zoth Protocol

Risk Score 54/100·D-Value
Compare
$2MTVL·RWAWebsite →

Elevated risk — proven $8.4M admin key exploit on current-architecture contracts, 92% TVL collapse with no recovery, and custom RWA oracle risk make Zoth a high-risk protocol with significant unresolved security questions.

Risk Breakdown

Top Risks

1

The protocol suffered two exploits within 21 days in March 2025, losing approximately $8.4M total — including an $8.4M admin private key compromise that drained USD0++ tokens from the USD0PPSubVaultUpgradeable proxy contract. The deployer wallet's key was stolen, enabling the attacker to upgrade the proxy and drain assets. Upgradeable proxy contracts with non-timelock admin keys remain the primary attack surface in the current architecture.

2

The protocol prices heterogeneous RWA collateral types (USYC, USD0++, TBILL, wSTBT, Wrapped $M) using a custom oracle system (KYC Manager + Oracle + Registry infrastructure). Custom RWA price oracles are not independently verified by Chainlink or industry-standard feeds, making manipulation or stale pricing a structural risk for ZeUSD's collateral valuation.

3

ZeUSD, the protocol's stablecoin, depends on regulated custodians and asset issuers for all underlying RWA backing. Regulatory action against any partner (USYC issuer Hashnote, Usual Protocol for USD0++, etc.) or ZeUSD itself could result in asset freezing — the asset issuers locked down 73% of remaining TVL after the March 2025 hack, demonstrating this centralized control.

4

TVL declined approximately 92% from the pre-hack peak of $29.3M to $2.2M, with no meaningful recovery over 15+ months. The protocol is operationally active (ongoing development, FINTRAC MSB registration, new product lines) but commercially fading — exit liquidity for remaining vault positions is limited.

Frequently Asked Questions

Is Zoth Protocol safe to use?
Zoth Protocol receives a C- risk grade (54/100) from Hindenrank, where lower scores indicate lower risk. Elevated risk — proven $8.4M admin key exploit on current-architecture contracts, 92% TVL collapse with no recovery, and custom RWA oracle risk make Zoth a high-risk protocol with significant unresolved security questions. Zoth Protocol is an RWA stablecoin and yield vault platform that issues ZeUSD (a CDP stablecoin backed by U.S. Treasuries and tokenized RWA assets) and zVaults (KYC-gated yield vaults managed by institutional strategy providers including BlackOpal and Superstate). The protocol suffered two exploits within 21 days in March 2025 — a $285K logic flaw and a critical $8.4M admin key compromise that drained USD0++ tokens from an upgradeable proxy vault — causing TVL to collapse approximately 92% from a peak of $29.3M to $2.2M with no recovery. Its C- grade reflects the confirmed major exploit on current-codebase contracts (maximum track record penalty), a critical upgradeable proxy admin key risk, custom RWA oracle dependency, and significant regulatory concentration from KYC-gated access and regulated custodian dependencies. The ZOTH governance token has not yet launched.
What are the main risks of using Zoth Protocol?
The key risks identified for Zoth Protocol are: (1) The protocol suffered an $8.4M hack in March 2025 via compromised deployer private key that enabled malicious proxy contract upgrade — the exact same attack vector (upgradeable proxy with unprotected admin key) remains the primary risk surface. Verify whether admin keys have been migrated to multisig + timelock since the exploit. (2) ZeUSD backing includes USD0++ (Usual Protocol), which has a 4-year lock mechanism and has experienced secondary market discounts. If any RWA collateral type depegs or is frozen, ZeUSD's backing falls below 1:1 and KYC-gated access prevents standard peg recovery via market arbitrage. (3) All vault and ZeUSD access requires KYC whitelisting. During stress events, non-whitelisted secondary market holders cannot redeem at par — amplifying any depeg or redemption crisis. (4) TVL has not recovered from the March 2025 hack (down 92% from peak, 15+ months after incident). Low TVL creates thin exit liquidity and operational sustainability risk for ongoing development. (5) The ZOTH governance token has not yet launched, making tokenomics unverifiable. Fee distribution, vesting schedules, and investor allocations from $21.5M in fundraising are not publicly documented.
What is Zoth Protocol's risk score breakdown?
Zoth Protocol scores 54/100 across eight risk dimensions: Mechanism Novelty: 0/15, Interaction Severity: 16/20, Oracle Surface: 7/10, Documentation Gaps: 4/10, Track Record: 15/15, Scale Exposure: 0/10, Regulatory Risk: 7/10, Vitality Risk: 5/10. The highest risk area is Track Record at 15/15.
How does Zoth Protocol compare to other RWA protocols?
Among 77 rated RWA protocols on Hindenrank, Zoth Protocol ranks #75 by safety (lowest risk score = safest). Its 54/100 risk score and C- grade place it among the riskier RWA protocols.
Has Zoth Protocol ever been hacked or exploited?
Zoth Protocol scores 15/15 on the Track Record risk dimension, indicating some history of security incidents or exploits. Higher scores reflect more severe or frequent incidents. Review the full risk report for details.
Last scanned 2026-06-13

Get risk alerts before it's too late

Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.