USDY’s “tokenomics” live off-chain, and that is the point

USDY is a yield-bearing dollar instrument that behaves like a stablecoin in wallets and in DeFi, but its economic engine is traditional finance plumbing: an issuer taking in dollars (often via USDC), buying high-quality short-duration assets, then pushing yield to tokenholders through a deterministic price path. Ondo’s own docs are explicit that USDY is not a traditional stablecoin. It is a tokenized secured note.

On the product side, USDY is designed for non-US investors. The eligibility docs list the United States as a prohibited jurisdiction and also prohibit “U.S. persons” under Regulation S definitions. That is not marketing copy. It is a distribution constraint that shapes everything about supply growth, secondary liquidity, and how much censorship and transfer-control the token must support.

Structurally, the docs describe USDY as a note secured by a mix that can vary by issuance date. Depending on when it was issued, it may be secured by short-term US Treasuries, shares of iShares Short Treasury Bond ETF, or bank demand deposits, and it also has a parallel rebasing wrapper, rUSDY, intended to hold a $1.00 price while distributing yield via balance increases; see the product basics for the issuer’s framing and mechanics.

There is also a meaningful corporate and issuance transition. Ondo’s docs state USDY was formerly issued by Ondo USDY LLC and that, as of December 15, 2025, it was “folded into the Ondo Global Markets umbrella.” In other words, you should treat “USDY tokenomics” as issuer policy plus smart contract implementation, not as a credibly neutral onchain monetary policy.

Supply mechanics: USDY, rUSDY, and USDYc

If you come from L1 tokenomics, this is the first mental flip. USDY does not have an emissions schedule in the usual sense. Supply is demand-driven and created through subscription and destroyed through redemption, with a compliance-driven delay layer sitting in the middle.

If you want a quick baseline on the “usual” patterns this differs from, our tokenomics FAQ is a helpful reference point.

USDY (accumulating) is the base token whose per-token value is intended to appreciate over time as yield accrues. rUSDY (rebasing) is a wrapper that targets a $1.00 unit price and expresses yield as more tokens in your wallet after each rebase.

The wrapper is economically clean. rUSDY corresponds to USDY locked in a wrapper contract. Converting USDY to rUSDY locks USDY and mints rUSDY. Converting back burns rUSDY and unlocks USDY. This is important for supply accounting because “USDY supply” becomes a sum of (1) USDY freely held and (2) USDY locked as reserve backing rUSDY.

The compliance constraint shows up as a time-based gating function. After investing, holders receive a Temporary Global Certificate and cannot claim transferable tokens until the restricted period ends, which the docs describe as usually between 40 and 50 days from deposit timing. That delay is not an implementation detail. It is a supply throttle that can create a predictable wedge between “economic exposure started” and “onchain float exists.”

Ondo also introduces a third token type: USDYc. USDYc (“Cooking USDY”) is an onchain bookkeeping representation of subscriptions still inside the restricted period. USDYc is non-transferable and held only by the issuer, not by subscribers. When a Temporary Global Certificate is issued, USDYc is minted in an amount equivalent to the USDY that will later be minted. When the restricted period ends, USDY is minted and the associated USDYc is burned.

From a security-budget maximalist lens, this is a double-edged choice. USDYc improves observability for aggregators tracking TVL during the restricted period. At the same time, it makes “reported supply metrics” more dependent on issuer-managed bookkeeping contracts and conventions. That is not trustless monetary policy. It is issuer transparency tooling.

Yield setting and the on-chain price update loop

USDY’s yield is issuer-set and calendar-driven. On the first business day of each month, Ondo sets the token yield rate for that month, quoted as an annualized APY, then converts it to a daily rate because interest compounds daily; the issuer lays out this economics and fees logic (including rounding conventions) in its documentation.

That monthly APY becomes a deterministic path for the “Reference Token Price.” The docs describe the future-day reference price as a function of (1) the reference price on the first business day of the month and (2) the month’s token yield rate, with rounding before values are stored. Mechanically, USDY looks like an accumulating NAV token with a pre-committed slope that can change monthly.

rUSDY then mirrors that accrual through rebasing. Ondo’s docs describe rebasing as adjusting total supply so that the total token supply equals the total value locked, which is how the rUSDY unit price is intended to remain $1.00. They also spell out the “shares” approach that makes rebasing gas-efficient because only a small number of state variables change, not each holder’s balance. Practically, that means balances can increase without a visible transfer transaction in many wallets and explorers.

Two more details matter if you are integrating USDY into protocol accounting.

First, rUSDY is rebased daily at the same time the USDY price is updated. Second, Ondo states that holders who submit a redemption request prior to the daily price update do not accrue yield for that day, and that yield is not “paid out” as a separate cashflow. It is reflected in the higher USDY value or higher rUSDY balance.

This design is economically coherent. It is also centralized at the control plane. Someone must set the monthly rate. Someone must post the daily price updates that trigger rebase behavior. That is not a criticism. It is the security model you are opting into.

Fees and fiscal flows: where the spread goes

Ondo’s USDY docs are unusually direct about how the issuer gets paid. There are no management or performance fees. Instead, Ondo earns interest on the bank deposits and Treasuries it purchases and then sets the USDY rate “slightly lower” than what the underlying assets pay, capturing the difference.

There is also an explicit redemption fee of 20 bps on redemptions. And there is a service-provider wire or money transmission fee for redemptions under $100,000, which Ondo says it does not profit from. The docs give an example amount: $30 per outgoing international wire as of July 19, 2023, and note it can change. For redemptions at or above $100,000, Ondo states it will cover those fees.

USDY’s investor protection story includes overcollateralization. Ondo describes USDY as overcollateralized with a 3% first-loss position meant to absorb short-term US Treasury price fluctuations, and says it monitors collateralization daily with an end-of-quarter minimum; these details sit in its trust and transparency materials. They also state a general portfolio posture of 99%+ short-term US Treasuries.

Those buffers matter. They reduce small-market-risk drawdowns. They do not remove the dominant risk, which is legal and operational enforceability across multiple entities and service providers.

Control surface: governance, upgrades, and where “decentralization” ends

USDY’s governance is closer to bondholder rights than DAO governance. Ondo emphasizes bankruptcy remoteness, board structure, and segregation of assets, rather than tokenholder voting on parameters like yield rate.

The key on-paper control is the role of Ankura Trust. Ondo states USDY investors have a first security interest in the underlying deposits and Treasuries, with Ankura Trust acting as collateral agent, backed by control agreements with banks and custodians. They also state Ankura has the right and obligation, subject to USDY tokenholder approval, to take control of assets and repay tokenholders upon events of default, after acceleration by tokenholder vote. Triggers described include failure to repay redemptions, failure to keep USDY adequately capitalized, or Ondo USDY LLC filing for bankruptcy.

Ondo also contrasts USDY with stablecoins on the redemption path. The docs state that failure to meet redemptions in a timely manner triggers an event of default and a mandated liquidation and repayment process via Ankura, again “subject to USDY holder approval.” That is stronger than “trust the issuer,” but it is still an off-chain enforcement workflow with voting and legal process embedded inside it.

Onchain, the relevant control surface is upgradeability and transfer controls. A public audit repository for Ondo’s rUSDY design describes the USDY contract as an upgradeable contract using a Transparent Upgradeable Proxy with transfer restrictions, and describes allowlist and blocklist style gating including a sanctions list. You should assume the issuer or its delegates operate privileged roles to manage these controls, because they are required for the distribution regime described elsewhere in the docs.

USDY is also explicitly multichain. Ondo’s USDY technology FAQ lists availability on Ethereum, Mantle, Solana, Sui, Aptos, Noble, Arbitrum, Stellar, Plume, and Sei. On Ethereum, Ondo publishes the USDY and rUSDY contract addresses in its docs.

Audit coverage is non-trivial. Ondo’s audit index lists multiple audits across time for “Ondo Funds and USDY (Ethereum),” including Code4rena and other firms. That improves confidence in smart contract correctness. It does not change the economic fact that USDY’s yield and solvency sit on a legal structure and a portfolio of real-world assets.

Risk register (security-budget lens)

USDY is engineered to make off-chain yield composable on-chain. That creates a specific risk profile. Some of it is familiar TradFi risk. Some of it is pure crypto security budget reality. When you move a high-value instrument across chains, you are importing the weakest security domain in your path.

If you want more examples of how we frame these integration risks, our research reports often cover cross-chain and oracle failure modes.

Top 3 risks

  1. Issuer, legal, and enforcement risk. Trigger: regulatory change, issuer non-compliance, or failure to meet redemptions in a timely manner. Mechanism: event-of-default workflows rely on off-chain actions, tokenholder approvals, and legal enforcement by the collateral agent, which can be slow or contested. Who bears it: USDY and rUSDY holders holding economic exposure through the note structure. Indicators: missed or delayed redemptions, disclosures around events of default, and changes in public reserve reporting cadence or content.

  2. Admin-key, upgradeability, and price-update integrity risk. Trigger: compromise or misuse of privileged roles controlling upgrades, transfer restrictions, or the daily price update that synchronizes with rUSDY rebases. Mechanism: upgradeable proxy patterns and restriction lists create a powerful control plane that can halt transfers, change logic, or distort accounting until resolved. Who bears it: DeFi protocols using USDY or rUSDY as collateral, LPs holding it in AMMs, and end holders whose balances or transferability can be impacted. Indicators: unexpected contract upgrades, unusual price update behavior, abnormal rebasing outcomes, and sudden transfer failures across addresses.

  3. Cross-chain and base-chain security budget risk. Trigger: bridge or messaging failures, chain halts, deep reorgs, validator censorship, or governance interventions on any supported chain where USDY circulates. Mechanism: multichain deployments fragment liquidity and create multiple settlement domains. The “security budget” that protects USDY transfers is the underlying chain’s validator incentives and fee market, not USDY’s own issuance. Who bears it: holders and protocols on the affected chain, plus arbitrageurs and bridges that attempt to restore parity across domains. Indicators: sustained price deviations across venues, halted bridging routes, withdrawal pauses by exchanges, and chain-level liveness incidents.

Dominant risk: issuer, legal, and enforcement risk dominates because it is the only risk class that can turn “yield-bearing dollars” into a protracted recovery process even if every smart contract behaves perfectly. Ondo’s structure is built to mitigate this with bankruptcy remoteness, segregation of assets, and third-party roles. The issue is that enforcement is still conditional. It is conditional on what constitutes an event of default, on tokenholder voting and approvals, and on a collateral agent executing a liquidation and repayment process in the real world.

The 3% first-loss buffer and the stated 103% minimum collateralization ratio are meaningful. They reduce small drawdowns and operational slippage. They do not solve a scenario where redemptions are gated by regulatory interpretation, banking rails freezing, or disputes about eligible investments and servicing obligations. Ondo points to daily and monthly transparency reports reviewed by Ankura, with posting timelines of within three business days for daily reports and by the 20th of the following month for detailed monthly reconciliation. That reporting helps you detect problems earlier. It does not guarantee the unwind path is fast.

In a security-budget frame, this is the uncomfortable truth: USDY holders are not relying on emissions to incentivize a validator set to defend the asset. They are relying on legal rights, custodians, banks, and an agent to enforce security interests, plus whatever chain security budget exists on the networks they use for transfer and settlement. If you integrate USDY as “risk-free collateral,” you should model the worst case as a real-world credit-style workout with onchain IOUs, not as a clean smart contract liquidation.

If you are integrating USDY or rUSDY into a protocol, it can be worth a short, explicit design review with a tokenomics advisor or tokenomics consulting team focused on collateral policy, oracle selection, and liquidation paths. Keep it practical. Model the event-of-default workflow as a first-class state, not as an edge case.



This article is part of our Tokenomics Deep Dive series.