USDR Implementation ๐Ÿ”ง

The reference implementation of the USDR White Paper v3.2: 13 Solidity contracts (~1,700 LoC), a Foundry test suite with 36 tests including fork tests against live Arbitrum One, a triaged Slither report, and a complete audit package โ€” ready to hand to an independent security auditor.

Status โ€” audit-ready package

13
Solidity contracts โ€” full whitepaper coverage, Solidity 0.8.24 + OpenZeppelin v5
36
Tests passing: unit, 512-run fuzz of the invariant, and E2E fork tests vs live Arbitrum
6 / 6
Whitepaper stress scenarios covered in tests: S1, S2, S3, S4/S8, S9, S10
0
Unresolved Slither findings โ€” 41 raw results triaged, none exploitable
Verified against the live chain. The exposure adapter reads real Rain pools on Arbitrum One (via the rain-sdk-v2 ABI). On-chain verification caught two integration bugs no document would have revealed: options are 1-indexed, and baseTokenDecimals() returns the scale factor (1e6), not the digit count. The TWAP reader was fork-verified against the live ARB/USDC Uniswap v3 pool, and the full-system E2E test runs against real USDT and a real live Rain market on an Arbitrum fork.

Architecture

                        โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                        โ”‚   Timelock /    โ”‚  (risk params only;
                        โ”‚   Governance    โ”‚   core is immutable)
                        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                 โ”‚
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   mint/burn  โ”Œโ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”   mint/burn   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚    PSM    โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บโ”‚   USDR   โ”‚โ—„โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค CDPVault  โ”‚
 โ”‚ (stables) โ”‚              โ”‚  ERC-20  โ”‚               โ”‚(volatile) โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”˜              โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜               โ””โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”˜
       โ”‚ USDT/USDC in                                        โ”‚ prices
       โ–ผ                                                     โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  escrow top-up   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ReserveManager โ”‚โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บโ”‚ Settlement   โ”‚   โ”‚OracleHub โ”‚
 โ”‚ (USDT/USDC)   โ”‚                  โ”‚   Escrow     โ”‚   โ”‚(CL+TWAP+ โ”‚
 โ”‚ slack โ‡„ escrowโ”‚                  โ”‚(traders only)โ”‚   โ”‚ breaker) โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
         โ”‚ invariant check
         โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    exposure reports    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ SolvencyGuard โ”‚โ—„โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค RainMarketAdapterโ”‚
 โ”‚ MaxLoss/Stressโ”‚                        โ”‚ (live pools)     โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Contracts

ContractWhitepaper sectionWhat it enforces
SolvencyGuardยง4.1, ยง4.3The invariant. Stress-MaxLoss + shortfall โ‰ค Reserve checked on every exposure increase; depth that would breach the floor is refused. Immutable core โ€” no upgrade path.
USDRยง3, ยง10ERC-20 + Permit. No admin-mint: minter set finalized at deployment, forever. No owner.
ReserveManagerยง4.2Stable reserve accounting. Escrow funded first to exactly Stress-MaxLoss(t); only remaining slack backs redemption.
SettlementEscrowยง4.2, ยง4.4Traders' winnings only. Payable solely by registered market adapters; no other withdrawal path exists.
PSMยง3, ยง4.41:1 stable onramp; redemption best-effort from slack โ€” reverts beyond it, by design. Bounded pause (โ‰ค14 days).
CDPVaultยง3, ยง5.4, ยง6MakerDAO-style CDPs: ETH/wBTC 140%, ARB/RAIN 400% with shared correlated-group ceiling. Debt ceilings with hysteresis. No code path converts collateral to stables โ€” the anti-reflexivity rule.
OracleHubยง9Chainlink (ETH/wBTC/USDC) + Uniswap v3 TWAP (RAIN/ARB) + circuit breaker + Arbitrum sequencer-uptime guard with recovery grace period.
UniV3TwapReaderยง9โ‰ฅ30-min TWAP window enforced in the constructor, pool-liquidity floor, canonical TickMath. Fork-verified vs the live ARB/USDC pool.
LiquidationEngineยง7, ยง9, ยง4.6Dutch auctions for keepers. Under an active breaker: partial + rate-limited, never frozen; un-cleared stress shortfall is priced into the invariant.
SurplusBufferยง7, ยง8Vig fills the buffer to target first; only excess funds buyback-and-burn. Capped, timelock-gated RAIN backstop (waterfall step 4).
EmergencySettlementยง7 step 5One-way global shutdown; holders claim pro-rata share of all collateral at $1.
RainMarketAdapterยง4.1Bridges live Rain pools to the solvency layer: computes worst-case net delta across mutually exclusive outcomes, applies the stress multiplier, reports per correlated group.
SettlementRouterยง4.4Wires market resolution (optionWinner / getClaimableAmount) to the escrow. Permissionless settle, dispute/appeal-aware, double-pay blocked.

Live-chain integration

Integration was built against the real production surfaces, not assumptions:

Test suite

SuiteCovers
USDRProtocol.t.solCore: no-admin-mint, PSM 1:1 + slack-capped redemption (S10), invariant refusal of excess depth, escrow rebalancing, CDP open/borrow/close returns collateral only, ceilings + hysteresis, over-mint attack (S3), breaker blocks borrows, full liquidation flow (S1), 512-run fuzz: the invariant never breaks.
RainMarketAdapter.t.solBalanced book โ†’ ~0 exposure (S2); one-sided longshot โ†’ computed and capped (S9); correlated-group aggregation and refusal (S4/S8); retire/sync lifecycle.
SettlementRouter.t.solWinner paid from escrow, double-pay blocked, unresolved/disputed/unregistered/zero-claim all revert.
Oracle.t.solSequencer down blocks prices; recovery grace period; TWAP decimal parity; short-window and low-liquidity rejection.
TwapFork.t.sol + E2EFork.t.solFork tests vs live Arbitrum One: real ARB/USDC TWAP sanity; full-system E2E with real USDT and a live Rain pool.
# run everything
forge test

# fork tests against live Arbitrum
forge test --mc TwapForkTest --fork-url https://arb1.arbitrum.io/rpc
forge test --mc E2EForkTest  --fork-url https://arb1.arbitrum.io/rpc

Security review (pre-audit)

๐Ÿ“ฆ The audit package

๐Ÿ“‹ Specification

SPEC.md โ€” module map, flows, units & precision, audit checklist.

๐Ÿ” Audit notes

AUDIT-NOTES.md โ€” trust model, whitepaperโ†’code map, formal invariants, honest open-items list.

๐Ÿ›ก๏ธ Slither triage

SLITHER-TRIAGE.md โ€” every static-analysis finding, reviewed and reasoned.

๐Ÿš€ Deploy script

Deploy.s.sol โ€” full-stack deployment + wiring for Arbitrum.

All source files (contracts, adapters, oracle, tests) are browsable via the links in the tables above โ€” every file on this page is served from /usdr-code/.

Open items before mainnet

  1. Independent security audit โ€” this package is the input to that audit, not a substitute for it.
  2. Governance ratification of White Paper v3.2 (bzr), per the roadmap.
  3. Economic simulation of stress parameters (โˆ’50% markdown, 35% depth) against historical RAIN/ARB liquidity data.
  4. Per-market underwriting policy โ€” protocolShareBps defaults, set via timelock.
  5. Solvency Dashboard front-end (all on-chain views โ€” maxLoss(), stressMaxLoss(), headroom(), isSolvent() โ€” are already exposed).
  6. Extended invariant campaign (Echidna/Medusa) as auditor support material.
Sending to audit? Point the auditors at this page. Recommended reading order: whitepaper summary โ†’ SPEC โ†’ AUDIT-NOTES (invariants I1โ€“I5) โ†’ contracts โ†’ tests โ†’ Slither triage.