KPK USDT Prime
Risk reportEthereum0x870f…c8a8
Risk
Depositing into KPK USDT Prime means underwriting risks you usually can't see: how much you could lose, whether you'd get out in time, and what would cover it.
Collateral and oracle exposure
Each token you're exposed to, and the market it backs. If that market breaks, this is how much the vault loses, in dollars and as a share of the vault. Open a row for the price feed, stress curve, and supply-cap detail. Below, the oracles those prices depend on and what is at stake if one is compromised.
Driven by WBTC −30% 6% · wstETH −30% 6% · sUSDS −30% 5% · other <1% · −100% 89% modeled all-to-zero bad-debt ceiling
WBTCMarketChainlink33%of vault · bad debt · $698,027.14Oracle exposure 4%37%of vault · $791,096.3433%of vault · $698,027.144%separate path
What it's made of
WBTC is priced via WBTC / BTC × BTC / USD, quoted in USDT / USD — 3-hop market-rate feeds (Chainlink).
- → USDT86% LLTV0x008b…e1efChainlink
If it breaks
−30% default
wstETHMarketChainlink33%of vault · bad debt · $691,020.41Oracle exposure 4%36%of vault · $772,956.6233%of vault · $691,020.414%separate path
What it's made of
wstETH is priced via Custom price feed for wstETH / ETH, quoted in USDT / ETH — 2-hop market-rate feeds (Chainlink).
- → USDT86% LLTV0x95db…6992Chainlink
If it breaks
−30% default
sUSDSHybridChainlink19%of vault · bad debt · $396,387.47Oracle exposure 2%21%of vault · $439,828.1519%of vault · $396,387.472%separate path
What it's made of
sUSDS mixes exchange-rate/NAV (ERC4626 vault share-rate) with market-rate (DAI / USD, USDT / USD) — insulated from ERC4626 vault share-rate market deviation, but exposed to DAI / USD, USDT / USD.
- → USDT97% LLTV0x0c42…4c79Chainlink
If it breaks
−30% default
XAUtMarketChainlink3%of vault · bad debt · $57,000.72Oracle exposure 0.6%3%of vault · $68,700.353%of vault · $57,000.720.6%separate path
What it's made of
XAUt is priced via XAU / USD — market-rate feed (Chainlink).
- → USDT77% LLTV0xc7d1…d9dcChainlink
If it breaks
−30% default
cbBTCMarketChainlink2%of vault · bad debt · $37,815.48Oracle exposure 0.2%2%of vault · $42,445.172%of vault · $37,815.480.2%separate path
What it's made of
cbBTC is priced via BTC / USD — market-rate feed (Chainlink).
- → USDT86% LLTV0x0e05…38acChainlink
If it breaks
−30% default
weETHHybridChainlink0.2%of vault · bad debt · $3,229.26Oracle exposure <0.1%0.2%of vault · $3,645.750.2%of vault · $3,229.26<0.1%separate path
What it's made of
weETH mixes exchange-rate/NAV (weETH / ETH) with market-rate (ETH / USD, USDT / USD) — insulated from weETH / ETH market deviation, but exposed to ETH / USD, USDT / USD.
- → USDT86% LLTV0x631b…0f87Chainlink
If it breaks
−30% default
syrupUSDTHybrid0.1%of vault · bad debt · $1,768.42Oracle exposure <0.1%0.1%of vault · $2,018.710.1%of vault · $1,768.42<0.1%separate path
What it's made of
syrupUSDT is priced from an exchange-rate/NAV leg (ERC4626 vault share-rate) — no market-rate feed, so it tracks redemption value, not market price.
- → USDT92% LLTV0x34e5…e997
If it breaks
−30% defaultOracle dependencies
1 feed · 1 control pointUp to11%of vault drainable if these feeds are mispriced · $235,442.2
Each price traces to a feed and the on-chain admin that can move it. Compromise either to misprice the collateral and borrow against it. Per-row amounts overlap and are not summed.
- Chainlink·a 4/9 Safe multisigprices cbBTC, WBTC, wstETH, weETH, sUSDS, XAUt0x21f7…73ca11% of vault · $235,191.91drainable if it is compromised
- On-chain exchange rate· no external feed or adminprices syrupUSDT<1% of vault · $250.29mispriceable only via the issuing contract
Loss scenarios
Each row is a distinct failure, and every loss is a share of your deposit — the same percentage whatever you deposited. Loss is that share at a −30% collateral crash, the standard stress; Worst case is the ceiling if everything goes wrong, a conditional loss if it happens rather than a likelihood. Open a row for the loss at every crash depth, the dollar amounts, conditions, and the math.
| Full-deposit & protocol-level(2) | ||||
| 100% | Full deposit | Instant | ||
| 18% | up to 89% | Instant | ||
| Price-driven collateral stress(1) | ||||
| 18% | up to 89% | Instant | ||
| Oracle & liquidation failures(5) | ||||
| 18% | up to 89% | Instant | ||
| 18% | up to 89% | Instant | ||
| 2% | up to 21% | Instant | ||
| 5% | up to 19% | Instant | ||
| — | up to 11% | Instant | ||
| Vault role & allocator(3) | ||||
| — | Full deposit | 3 days | ||
| — | Full deposit | Instant | ||
| — | up to 50% | 3 days | ||
Trust and control
The people and processes that can change this protocol under you.
Vault operators
The roles that can actually move your deposit — the real principal-loss path.
Role timelock 3 days to exit before owner/curator actions land
Sentinels1 · 1 multisigSafety role · veto only
Safety role, not an attack role: can revoke ANY pending timelocked curator change, instantly cut caps, and pull funds from adapters back to idle. Strictly risk-reducing — a captured sentinel cannot introduce new risk.
- 5-of-8 multisig0x354c…7478
Allocators4 · 1 multisig · 3 EOAsReaches deposit · instant
Moves funds between markets the curator has ALREADY approved — instantly, with NO timelock and no exit window. Cannot reach a brand-new market, but can concentrate you into an approved-but-stressed market or order withdrawals so you hit weak liquidity first.
- single key (EOA)0x331d…1204
- 2-of-5 multisig0x834e…7de8
- single key (EOA)0xaf15…9440
- single key (EOA)0xf0cf…2a75
Audits
- Certora· Dec 15, 2025report
- Blackthorn· Dec 4, 2025report
- Spearbit· Dec 4, 2025report
- Blackthorn· Sep 15, 2025report
Governance & control
Protocol-wide governance: bounded context, not the path to your deposit.
Dependencies that can affect your deposit
8 things this pool relies on but doesn't control. Select one for its story.
Every Morpho Blue market chooses an immutable oracle contract at creation; implementations can be Chainlink-like, exchange-rate, fixed-price, or custom. Failure modes: attacker-favourable price feed (covered in market-oracle-compromise) or price() revert / staleness blocking liquidations (covered in oracle-liveness-or-malfunction).
No quantified loss scenario references this dependency directly.