USDD’s peg is not just a collateral story. It is a control-surface story. The public narrative says “community-governed, fully decentralized.” The technical reality, even in the newer Maker-style system, still routes through privileged keys and a small validator set underneath it.

USDD’s peg is built on an admin surface, not just collateral

USDD’s current “new version” positions itself as an over-collateralized stablecoin with Vault minting, liquidations, and a Peg Stability Module (PSM). The core architecture is explicitly patterned on MakerDAO-style components (Vat, Jug, Dog, Clip, Spot), plus a governance timelock pattern (DSPause) and oracles with delayed pricing via an OSM-style module. That lineage is not speculative and is described in an independent audit report.

That is the “mechanism layer.” The decentralization question sits above it: who can change risk parameters, add collateral, alter PSM fees, move protocol-owned capital, and override safety rails during stress. The same audit states that governance delay in DSPause is set to 0, and that USDD V2 is controlled by an “admin multisig” that can execute privileged actions immediately.

From a decentralization-purist lens, that single fact dominates. Over-collateralization reduces one class of failure. Privileged, fast-path governance increases another.

What USDD does today: minting through Vaults and PSM

The “new version of USDD” is documented as a crypto-collateral-backed USD-pegged stablecoin that maintains its peg via over-collateralization, liquidation processes, and a PSM that supports stablecoin swaps in its system architecture.

Vault minting is straightforward: users lock eligible collateral and mint USDD debt against it. The docs are UI-oriented, but the underlying design is explicit: collateral ratios are monitored, and positions below a minimum threshold become eligible for liquidation.

PSM mint/burn provides a second issuance and redemption path. USDD’s docs describe fixed 1:1 stablecoin conversions (example given: USDD <-> USDT) with “no slippage,” and present it as a mechanism that mints USDD when users swap in stable collateral and burns USDD on redemption.

One important nuance: the audited PSM implementation has explicit fee parameters (tin and tout). The audit describes “sellGem” charging tin and “buyGem” charging tout, with the fee credited to VOW. That means “zero-fee” is a governance setting, not a hard property of the mechanism, as detailed in the PSM fee model.

Supply, “emissions,” and where USDD comes from

USDD supply is elastic. CoinGecko lists USDD’s max supply as infinite, consistent with a debt-minted stablecoin model; CoinGecko also reports a circulating supply of 712,053,218 USDD on March 5, 2026. USDD supply data

In the new Vault-based system, “new USDD” is minted when users borrow against collateral and is burned on repayment, plus minted and burned via PSM flows as users swap stable collateral in and out.

There is no conventional “emission schedule” in the way you would model for a capped asset. The closest analog is how aggressively governance configures (1) which collateral types exist, (2) per-collateral stability fees, (3) liquidation parameters, and (4) PSM fees and quotas. The docs acknowledge per-collateral differences in fees and liquidation thresholds, but do not publish a full parameter table in the docs themselves.

Cashflows: stability fees, liquidation incentives, PSM spreads, and sUSDD yield

USDD’s economic loop combines user-paid risk premia with protocol-managed capital deployment. If you’re mapping stablecoin design components, start with these cashflows.

Stability fees are part of the inherited Maker architecture. The audit identifies Jug as the stability fee module that calculates stability fees per collateral type, even if the docs do not enumerate current rates.

Liquidations are incentive-driven. The docs describe liquidation eligibility when a Vault falls below minimum collateral ratio, and pay liquidators via a formula composed of a relative incentive, a constant incentive, and net of transaction fees. Exact constants are not specified in the docs page, but the presence of both variable and fixed components matters because it affects keeper economics at small vs large Vault sizes.

Collateral auctions are Dutch auctions. Liquidated collateral moves into an auction process with a decreasing price over time.

PSM spreads exist at the contract layer even when UI markets it as “zero-fee.” In practice, tin/tout becomes a policy lever for peg defense and balance-sheet management. It can be set to 0 during expansion, then dialed up during stress.

sUSDD is the yield-bearing wrapper. The docs state sUSDD is minted when users deposit USDD into “USDD Earn,” and that the mechanism is based on ERC-4626 tokenized vault standard. sUSDD’s value accrues via an exchange-rate style mechanism, so yield shows up as sUSDD appreciating versus USDD rather than as explicit token inflation.

The yield source is positioned as protocol-directed deployment of “cash reserve” capital via Smart Allocator into external venues like Aave, with platform selection done by the USDD and JUST DAO teams under “dynamic monitoring,” and with net returns redistributed while a portion is retained as a risk reserve. This is a real economic design choice. It is also a real governance and operational-risk choice because it turns USDD into a stablecoin with an embedded asset management function.

Governance and decentralization: TRON validators vs USDD admins

USDD inherits decentralization constraints from two layers: the TRON base chain, and the stablecoin protocol’s own admin and governance machinery.

Base chain (TRON): small validator committee. TRON’s committee consists of 27 Super Representatives (SRs) who maintain and modify network parameters, and only SRs can vote on proposals. Proposals pass with 18 or more SR votes within a validity window under the SR committee rules.

That 27 / 18 structure is a governance trade-off. It supports fast coordination and high throughput. It also concentrates fault domains. For a stablecoin that depends on reliable liquidation execution, oracle updates, and unhalted block production, “how distributed is the validator set” is not a philosophical question. It is direct risk pricing.

Protocol layer (USDD V2): multisig-first reality. The governance documentation in USDD’s docs is aspirational and thin on thresholds. It states that governance is “community-driven” and mentions proposals and on-chain voting mechanisms, but it does not define who votes with what token, what quorum applies, or what timelock protects users.

Meanwhile, the audit documents an “admin multisig” control model, and flags that governance delay is disabled. This is not a minor detail. In a Maker-style system, “slow governance” is part of the security model. With a delay of 0, users have no time buffer to exit before parameter or permission changes execute.

Parameter control shows up in subtle places. The PSM audit assumes warded admin privileges are concentrated into DSPauseProxy for PSM contracts, and that wards are a core administrative permission concept. If that privileged path is multisig-controlled, that becomes the effective governance root regardless of what “community governance” might later become.

On paper, the docs also emphasize freeze resistance (“tamper-proof and cannot be frozen”). In practice, freeze resistance depends on contract design and admin capabilities, plus base-chain censorship risk. USDD’s docs state the intent. They do not publish a governance threat model that would let you quantify it.

History: USDDOLD (TDR reserve model) to USDD V2 (Maker fork)

USDD has at least two structurally different eras that matter for tokenomics modeling.

USDDOLD (TRON DAO Reserve era): whitelist minting + reserve narrative. In June 2022, TRON DAO’s official blog described USDD as having a guaranteed minimum collateral ratio of 130%, with minting by TRON DAO Reserve members via burning TRX, and reserves including BTC, TRX, and stablecoins like USDC and USDT.

USDD’s own “USDDOLD” documentation defines it as an over-collateralized stablecoin issued by TRON DAO Reserve, minted by whitelisted institutions through burning TRX, and backed by liquid crypto assets under TDR custody including BTC, USDT, USDC, and TRX.

USDD protocol doc (December 2022) shows explicit institutional custody and multisig control. The USDD protocol PDF (V2.3, December 2022) sets a minimum collateral ratio of 120% and describes responsive monetary policy managed by TRON DAO Reserve.

USDD V2 (new version): CDP-based, Maker-like, and explicitly integrated with JST. The audit states USDD V2 uses JST as the governance token (gem) in contracts like Flop and ESM. It also highlights a key divergence from Maker: Flop does not mint governance tokens to recapitalize. Instead it sells an existing gem token (JST) that must be pre-deposited, and there is “no guarantee” that enough JST will be available to cover bad debt auctions.

USDD’s docs explicitly provide a migration path from USDDOLD to the new USDD with no deadline, describing it as gas-only and “no fees, no deadlines.”

Risk analysis

Dominant risk: governance centralization and rapid admin action. The “new USDD” story is built on decentralization language. The audited system reality still describes an admin multisig with immediate execution because DSPause delay is 0.

Why this dominates: every other risk category is mediated by governance action. Oracle configuration, collateral onboarding, PSM fees (tin/tout), liquidation incentives, and Smart Allocator venue selection are policy decisions. When policy can change instantly, users cannot rely on “exit before the change.” They must rely on “the change will not be malicious or incompetent.” That is trust. It may be practical in early phases. It is not decentralization. We track similar patterns and updates in our crypto research.

Even the “security posture” implied by warding concentrates power. If your governance root is a multisig controlling a privileged proxy, then “on-chain voting later” is a promise, not a property. Public docs do not publish the multisig signer set, threshold, rotation policy, or incident response process. That limits modelability and lowers confidence in parameter stability.

Top 3 risks

  1. Trigger: compromise, coercion, or unilateral action by the admin multisig signers; Mechanism: immediate execution of privileged actions because governance delay in DSPause is 0, enabling rapid parameter and permission changes; Who bears it: Vault users (liquidation and collateral rules can shift), USDD holders (peg defense knobs can change), and sUSDD depositors (yield routing can change); Measurable indicators: DSPause delay configured to 0, privileged transactions from governance proxies, changes to ward assignments on core contracts.
  2. Trigger: sharp collateral drawdown (especially volatile collateral like TRX) or oracle disruption; Mechanism: Vault collateralization drops below minimum thresholds, causing liquidations and Dutch auctions, amplified by oracle design choices including delayed pricing through OSM; Who bears it: Vault owners first (liquidation losses), then USDD holders if system-wide bad debt emerges; Measurable indicators: liquidation volumes, auction throughput, oracle health (price update failures), and documented 1-hour OSM delay behavior in the oracle stack.
  3. Trigger: protocol deficit that exceeds available buffers; Mechanism: bad debt recapitalization relies on Flop selling pre-deposited JST rather than minting a backstop asset, with no guarantee of sufficient JST balance, creating a potential “stalled recapitalization” failure mode; Who bears it: USDD holders (peg confidence and liquidity), and the protocol’s solvency over time; Measurable indicators: Vow bad-debt accumulation, Flop contract JST balance, frequency of deficit events, and auction completion rates.

If you are doing tokenomics consulting or token economy design work around stablecoins, USDD is a case study in how “mechanism decentralization” (Vaults, auctions) can coexist with “control centralization” (multisig-first governance). Model the admin surface first. Then model collateral.



This article is part of our Tokenomics Deep Dive series.