Liquity v1 (LUSD)
The scheduled date is the outside bound. Kill criteria are checked every day, and a trigger reopens the memo that week.
UNDER REVIEW, with a recommendation to reject LUSD as an allocable client sleeve while retaining Liquity V1 as a research benchmark. The sovereignty case remains exceptional: Ethereum-only ETH collateral, immutable core contracts, no admin key, no governance parameter changes, and permissionless redemption of LUSD for $1 of ETH before fees. The record is stronger and more nuanced than “zero issues.” Liquity processed 310 Trove liquidations when ETH fell from about $3,400 to $1,800 on 2021-05-19, with the Stability Pool absorbing the debt. In 2022 the team disclosed that its immutable fallback-oracle integration consumed Tellor prices without a dispute delay; it was never exploited on Ethereum mainnet, was exploited on the ETHW fork, and could be repaired only through a custom change in Tellor because Liquity itself was unupgradeable. Immutability removed administrator seizure risk and also removed the normal patch path. The investability failure is decisive. CoinGecko reported only 27.74M LUSD outstanding, a $1.001 price, and about $10.5k of trailing 24-hour volume on 2026-08-14; DefiLlama still showed $211.1M of collateral TVL, but collateral is not holder exit liquidity. The V1 bug bounty was discontinued after V2 launched. A $25M minimum-liquidity rule cannot be satisfied by a token whose entire supply is only modestly larger. Direct redemption provides a hard economic floor, not institutional market capacity: fees rise with the fraction of supply redeemed, execution returns volatile ETH, and a large client order would be material to the system. Sovereignty is necessary for the lesson and insufficient for the allocation.
- LUSD supply falling below $20M (unusable at any client size)
- Sustained LUSD trading above $1.10 or below $0.97
The research file
The mechanism
Liquity V1 lets a borrower open an Ethereum Trove, post ETH, and mint LUSD with no recurring interest and no maturity. The minimum collateral ratio is 110%; a one-time borrowing fee has a 0.5% floor and a 5% cap under normal operation. When a Trove falls below 110%, anyone can liquidate it. LUSD in the Stability Pool is burned against the defaulted debt and the Trove’s ETH is distributed to Stability Providers. If the pool is empty, debt and collateral are redistributed across remaining Troves. Recovery Mode activates below a 150% system total collateral ratio and restricts risk-increasing operations while widening the liquidation regime.
The peg is enforced by permissionless redemption: a holder can exchange LUSD for $1 of ETH at the oracle price, starting with the lowest-collateralized Troves. The normal redemption fee is baseRate plus 0.5%. baseRate increases by the redeemed amount divided by twice total LUSD supply and decays with a twelve-hour half-life. This creates a credible floor when LUSD trades below par, but it also makes large redemptions increasingly expensive and contracts both LUSD supply and borrower ETH exposure. There is no issuer reserve account, bank deposit, or off-chain redemption promise.
Who controls it
Nobody can upgrade or re-parameterize the V1 core after deployment. There is no DAO vote, multisig, pause key, collateral-listing process, or issuer blocklist. LQTY staking receives system fees but does not govern the contracts. Users reach the protocol through independent frontends; Liquity’s site expressly says it does not operate its own frontend or attest to listed frontend operators. Interface and wallet risk therefore remain even though frontend failure cannot seize or rewrite the contracts.
External dependencies still exercise de facto control over system inputs. Chainlink is the primary ETH/USD oracle and Tellor the fallback. The 2022 disclosure is the cleanest statement of the tradeoff: Liquity’s immutable TellorCaller used the latest report without a dispute window, and Liquity could not patch it. Tellor instead changed its finalized system so Liquity receives a report at least fifteen minutes old, allowing disputes. The custom fix was audited by Coinspect. The contracts are governance-minimized, not dependency-free.
The record
Liquity V1 has operated on Ethereum since April 2021. DefiLlama’s series peaked at $4.52B of TVL on 2021-05-11 and reported $211.1M at this review. During the 2021-05-19 ETH fall from roughly $3,400 to $1,800, Liquity reported 121 Troves liquidated in Normal Mode and 189 in Recovery Mode; the Stability Pool absorbed all defaulted debt and the system exited Recovery Mode. No Ethereum-mainnet loss of LUSD backing or core-contract exploit was located in the reviewed sources.
The Tellor flaw remains a material near miss. It was reported on 2022-09-17, had not activated on mainnet because Chainlink had not failed, and was apparently used on the ETHW fork after Chainlink stopped updating there, allowing trillions of forked LUSD to be minted. The fix depended on Tellor changing the behavior of the external oracle. Audits before launch included two Trail of Bits engagements and Coinspect; nevertheless, the team says the oracle integration error escaped both internal testing and external audits. The V1 bounty ended after four years when V2 launched, reducing forward security incentives for an immutable legacy system.
The exit
The strongest exit is on-chain redemption, available to any address without an issuer gate. It returns ETH, not dollars, and charges a fee that is at least 0.5% and rises with recent redemption volume. A redeemer also bears gas, oracle, and transaction-execution risk and must sell the received ETH to finish a dollar exit. Because the fee increment is proportional to the redeemed share of total supply, capacity gets worse as LUSD shrinks: a $1M redemption is now a material fraction of the 27.74M-token float.
The secondary market is not institutional. CoinGecko’s 2026-08-14 snapshot showed about $10.5k of trailing daily volume despite a near-par $1.001 price. That figure may omit some on-chain routing and is used as a warning, not a complete liquidity map. Even granting deeper executable DEX liquidity, the registry’s $25M floor is almost the entire token supply. A single client cannot size a prudent sleeve without becoming a material holder and redemption participant.
The comparison
Against USDC or USDT, LUSD removes issuer, bank-account, blacklist, and direct regulatory-seizure risk but gives up primary-market dollar redemption and deep liquidity. Against DAI or GHO, it removes governance changes and diversified or centralized collateral but concentrates backing and oracle dependence in ETH. It pays no native holder yield; Stability Pool returns require accepting liquidation inventory and are a different exposure from holding LUSD.
Liquity V2/BOLD is the project’s attempted answer to V1’s weak demand and Stability Pool incentives, but it changes the mechanism and belongs in a separate memo. The recommendation is to reject V1 for client allocation, preserve LUSD as the benchmark for censorship-resistant stablecoin design, and correct any asset education that equates sovereignty with sufficient liquidity or suitability.
Open questions
Measure executable LUSD-to-USDC and LUSD-to-ETH depth at 10, 50, and 100 basis points across aggregators; record Stability Pool size, total debt, active Trove count, system collateral ratio, current baseRate, oracle status, and frontend availability. Confirm whether any maintained security-response process replaced the discontinued V1 bounty and who monitors the Tellor fallback.
Reopen investability only if circulating supply and executable secondary depth both exceed the registry floor by a wide margin for six months, normal redemption fees remain near the floor under the proposed client-size exit, and V1 again has a credible public vulnerability-reporting program. A price near $1 alone does not reopen the file.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Liquity V1 documentation — general protocol mechanics · primary · accessed 2026-08-14
Supports: ETH-backed borrowing, fees, governance minimization - Liquity V1 documentation — borrowing · primary · accessed 2026-08-14
Supports: 110% collateral ratio, liquidation, redemption impact - Liquity V1 documentation — Stability Pool and liquidations · primary · accessed 2026-08-14
Supports: Stability Pool, debt offset, redistribution - Liquity V1 documentation — LUSD redemptions · primary · accessed 2026-08-14
Supports: permissionless redemption, redemption fee, baseRate - Liquity V1 documentation — technical resources and audits · primary · accessed 2026-08-14
Supports: audit history, whitepaper, technical resources - Liquity V1 documentation — discontinued bug bounty · primary · accessed 2026-08-14
Supports: bounty discontinuation, legacy security process - Liquity — Tellor fallback-oracle issue and fix · primary · accessed 2026-08-14
Supports: fallback-oracle flaw, ETHW exploitation, external fix - Liquity — first major stress-test report · primary · accessed 2026-08-14
Supports: May 2021 stress, liquidation counts, Stability Pool performance - CoinGecko API — Liquity USD market data · secondary · accessed 2026-08-14
Supports: LUSD supply, price, trading volume - DefiLlama — Liquity protocol data · secondary · accessed 2026-08-14
Supports: current TVL, historical peak, Ethereum deployment
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |
| Asset | Grade | Who can freeze it |
|---|---|---|
| LUSD | sovereign | Liquity. Immutable contracts, no governance, no admin key, no blocklist — the most censorship-resistant stablecoin that exists. But supply has contracted from a ~$1.5B peak to roughly $30M, so it is not usable at client size. Sovereignty and availability are separate questions, and this is the clearest case where they diverge. |