QUSD Liquidity Pool Risk Disclosure
Risks of trading and providing liquidity in QUSD pools on decentralised exchanges — for users, regulators and custodians. Every figure is read from public chain data at build time and can be reproduced from a terminal without asking QVTX for anything.
This supersedes version 1.0, which stated that the liquidity contracts were audited and rated secure, that no critical vulnerabilities were identified and minor issues patched, and that the contract was built on OpenZeppelin libraries. None of those is true of QUSD. No auditor has reviewed these contracts; the audits previously cited covered Circle’s FiatToken contracts. The verified source on BscScan has no imports at all and no OpenZeppelin, ERC20, Ownable or SafeMath code in it — it is self-contained. What follows is measurement instead of attestation.
1. Purpose
Scope- Covers the QUSD side of every listed pool on decentralised exchanges, and the canonical QUSD contract those pools quote.
- Not in scope: line-by-line contract review, formal verification, and anything requiring an auditor. Absence of a finding here is not evidence of absence of a bug.
2. Contract Status
Measured, Not Attested- No audit rating is asserted. A rating requires an auditor who has reviewed these contracts. That engagement has not happened, and no third-party attestation of QUSD exists.
- The contract is self-contained. The verified source on BscScan (contract
QUSD, solc 0.8.30, 35,877 bytes) contains noimportstatements and no OpenZeppelin,ERC20,OwnableorSafeMathcode. Version 1.0’s OpenZeppelin claim was wrong. - One coin, five ledgers. Canonical QUSD
0xb57bf3c50f20096723b46645f741f632aef220facarries identical 19,338-byte runtime bytecode on BNB Smart Chain, Polygon, Base, Arbitrum and QVTX 42000. - Reserve accounting is clean. Cached
getReserves()matches the balance each pair actually holds, on every leg of every pool — so no donation attack or fee-on-transfer breakage is present at this reading. - Known defect, open: the contract answers TRUE to
supportsInterface(0x80ac58cd), so some explorers file QUSD as an NFT collection and suppress price and holder data.
3. The Pools, Measured
Live0x763aff9d01fa6412ea762659d8c8896515434ce5Reserves 1.39118881 QUSD / 1.39397000 USDC. Spot 1.001999, fee 30 bps. Last trade 13.1 days ago.
0xe848f417b7b91e381ccfedeba27ff2f6c4a1fa8cReserves 4.09946280 QUSD / 3.93704503 USDT. Spot 0.960381, fee 25 bps. Last trade 6.3 days ago.
This pool quotes the superseded QUSD contract
0x63c4664ceb3e93ef22d1e56826395fb1c927c118, not the canonical one. A buyer here receives the deprecated token.
reserve_in_usd counts our own QUSD as dollars and roughly doubles it.4. Risks, Rated From Measurement
Not From A Template- High A live pool quotes a superseded contract. PancakeSwap pairs against
0x63c4664ceb3e93ef22d1e56826395fb1c927c118. Version 1.0 warned about “fake QUSD clones” and never mentioned this one, which is our own deprecated token. - High Depth is $5.33 in total. Any trade of meaningful size fails or executes at a price nothing like par. Version 1.0 said liquidity “may be low”.
- High Flash-loan manipulation is not medium here. Version 1.0 rated it medium, which assumes an attacker needs capital. At this depth a $10 trade on QuickSwap moves spot +718%; a $10 trade on PancakeSwap moves spot +254%. This is exactly why pool spot must never be an oracle input, and it is not one — the QUSD oracle returns 1.00000000 and never reads a pool.
- Medium The pools are quiet. Last trades were 13.1 days and 6.3 days. Cached reserves drift further from any external price the longer nothing trades.
- Medium Explorer listing is suppressed by the ERC-165 defect above.
- Medium Invariant, fee-on-transfer and donation risks are the generic AMM surface. They are monitored: reserves are compared against real balances on demand, and the delta is currently zero everywhere.
5. Controls In Force
Built, Not PromisedCached reserves against the balance each pair actually holds, both legs, both pools, on demand. Currently zero delta everywhere.
The constant-product invariant and real price impact at size, computed with the pair's own arithmetic on live reserves.
This document and the pool audit page, both rebuilt from live chain state and reproducible by anyone from public RPCs.
Plain-language guidance for holders, with the exact call that reproduces each figure.
Open. Tiers $5,000 / $2,500 / $1,000 / $250, scope read from chain across contracts, wallet integrations and APIs, reports to security@quantvestrix.com.
6. User Advisory
Verify, Do Not Trust- Check the contract address, not the ticker. Canonical QUSD on EVM chains is
0xb57bf3c50f20096723b46645f741f632aef220fa. On the XRP Ledger the issuer isrJqjwDAwuSVoppQkrwjJSPzXivspYxZ239. - Official pools differ by ledger. On the XRP Ledger the QUSD books are QUSD/XRP, QUSD/USDC, QUSD/USD and QUSD/RLUSD, as measured 2026-09-18 — the issuer is checked live at build time, the books are not. On EVM chains the live pairs are QuickSwap on chain 137 (canonical); PancakeSwap on chain 56 (superseded). Version 1.0 listed “QUSD/XRP, QUSD/USDC” without saying which ledger.
- Redeeming is not trading. Redemption at par runs through
qusd.quantvestrix.io/redeem. A pool holding a few dollars is a listing, not an exit. - This is a disclosure, not financial advice.