Hyperithm USDC Apex
Risk reportMonad0x7899…f371
Risk
Depositing into Hyperithm USDC Apex means underwriting risks you usually can't see: how much you could lose, whether you'd get out in time, and what would cover it.
Collateral and oracle exposure
Each token you're exposed to, and the market it backs. If that market breaks, this is how much the vault loses, in dollars and as a share of the vault. Open a row for the price feed, stress curve, and supply-cap detail. Below, the oracles those prices depend on and what is at stake if one is compromised.
Driven by PT-USDat-14JAN2027 −30% 9% · aHYPER −30% 3% · cbBTC −30% 1% · other <1% · −100% 85% modeled all-to-zero bad-debt ceiling
PT-USDat-14JAN2027Unclassified37%of vault · bad debt · $9.55mOracle exposure 4%40%of vault · $10.5m37%of vault · $9.55m4%separate path
What it's made of
Oracle design not classified (long-tail market).
- → USDC92% LLTV0x5979…dab2
If it breaks
−30% default
aHYPERHybrid29%of vault · bad debt · $7.47mOracle exposure 10%38%of vault · $10m29%of vault · $7.47m10%separate path
What it's made of
aHYPER is priced from an exchange-rate/NAV leg rather than a direct market-rate feed.
- → USDC77% LLTV0x4af4…fbec
If it breaks
−30% default
cbBTCMarketChainlink14%of vault · bad debt · $3.73mOracle exposure 0.7%15%of vault · $3.92m14%of vault · $3.73m0.7%separate path
What it's made of
Priced off live market data — a depeg moves the price and can liquidate positions.
- → USDC77% LLTV0x0c68…5836Chainlink
If it breaks
−30% default
aHyperBTCMarketChainlink4%of vault · bad debt · $1.06mOracle exposure 0.3%4%of vault · $1.13m4%of vault · $1.06m0.3%separate path
What it's made of
Priced off live market data — a depeg moves the price and can liquidate positions.
- → USDC77% LLTV0xc30a…5c6eChainlink
If it breaks
−30% default
mHYPERHybrid1%of vault · bad debt · $364,778.34Oracle exposure <0.1%1%of vault · $374,775.91%of vault · $364,778.34<0.1%separate path
What it's made of
mHYPER uses a managed oracle path; verified external provider(s): no verified external provider.
- → USDC77% LLTV0x3a89…1e9c
If it breaks
−30% default
WBTCMarketChainlink0.2%of vault · bad debt · $59,463.02Oracle exposure <0.1%0.3%of vault · $66,069.230.2%of vault · $59,463.02<0.1%separate path
What it's made of
Priced off live market data — a depeg moves the price and can liquidate positions.
- → USDC86% LLTV0xff07…26f5Chainlink
If it breaks
−30% default
wstETHMarketChainlink0.1%of vault · bad debt · $23,861.4Oracle exposure <0.1%0.1%of vault · $26,512.310.1%of vault · $23,861.4<0.1%separate path
What it's made of
Priced off live market data — a depeg moves the price and can liquidate positions.
- → USDC86% LLTV0xf423…d329Chainlink
If it breaks
−30% default
WETHMarketChainlink0.1%of vault · bad debt · $16,687.3Oracle exposure <0.1%0.1%of vault · $16,688.30.1%of vault · $16,687.3<0.1%separate path
What it's made of
Priced off live market data — a depeg moves the price and can liquidate positions.
- → USDC86% LLTV0xf06b…5396Chainlink
If it breaks
−30% default+3 markets with no current position
Oracle dependencies
1 feed · 1 control pointUp to15%of vault drainable if these feeds are mispriced · $3.86m
Each price traces to a feed and the on-chain admin that can move it. Compromise either to misprice the collateral and borrow against it. Per-row amounts overlap and are not summed.
- Chainlink·a 4/9 Safe multisigprices WMON, wstETH, WETH, aHyperBTC, WBTC, mHyperBTC, cbBTC0x7387…c4f11% of vault · $369,165.55drainable if it is compromised
- On-chain exchange rate· no external feed or adminprices aHYPER10% of vault · $2.53mmispriceable only via the issuing contract
- Unidentified feeds· vendor and on-chain control not resolvedprices PT-USDat-14JAN2027, mHYPER4% of vault · $959,878.26mispriceable if these feeds lie
Loss scenarios
Each row is a distinct failure, and every loss is a share of your deposit — the same percentage whatever you deposited. Loss is that share at a −30% collateral crash, the standard stress; Worst case is the ceiling if everything goes wrong, a conditional loss if it happens rather than a likelihood. Open a row for the loss at every crash depth, the dollar amounts, conditions, and the math.
| Full-deposit & protocol-level(2) | ||||
| 100% | Full deposit | Instant | ||
| 13% | up to 85% | Instant | ||
| Price-driven collateral stress(1) | ||||
| 13% | up to 85% | Instant | ||
| Oracle & liquidation failures(5) | ||||
| 13% | up to 85% | Instant | ||
| 13% | up to 85% | Instant | ||
| 10% | up to 40% | Instant | ||
| 3% | up to 30% | Instant | ||
| — | up to 15% | Instant | ||
| Vault role & allocator(3) | ||||
| — | Full deposit | 3 days | ||
| — | Full deposit | Instant | ||
| — | up to 50% | 3 days | ||
Trust and control
The people and processes that can change this protocol under you.
Vault operators
The roles that can actually move your deposit — the real principal-loss path.
Role timelock 3 days to exit before owner/curator actions land
Curator changes queued
The timelock is your window to exit before each one takes effect.
- raise a market's supply cap ×4— applies now; no time to exit first
- decrease timelock— applies in 2 days; time to exit first
Allocators1 · 1 EOAReaches deposit · instant
Moves funds between markets the curator has ALREADY approved — instantly, with NO timelock and no exit window. Cannot reach a brand-new market, but can concentrate you into an approved-but-stressed market or order withdrawals so you hit weak liquidity first.
- single key (EOA)0x345e…3c5f
Audits
- Certora· Dec 15, 2025report
- Blackthorn· Dec 4, 2025report
- Spearbit· Dec 4, 2025report
- Blackthorn· Sep 15, 2025report
Governance & control
Protocol-wide governance: bounded context, not the path to your deposit.
Dependencies that can affect your deposit
8 things this pool relies on but doesn't control. Select one for its story.
Every Morpho Blue market chooses an immutable oracle contract at creation; implementations can be Chainlink-like, exchange-rate, fixed-price, or custom. Failure modes: attacker-favourable price feed (covered in market-oracle-compromise) or price() revert / staleness blocking liquidations (covered in oracle-liveness-or-malfunction).
No quantified loss scenario references this dependency directly.