Guardian's review of PSM Adapter for Ethena, published August 2026. The report records 8 findings across 2 review rounds, including 1 low and 7 informational.
- Published
- Review window
- August 5 to 10, 2026
- Rounds
- Main Review, Remediation Review
- Language
- Solidity
- Chains
- Ethereum
- Sector
- Stablecoins
- 0 Critical
- 0 High
- 0 Medium
- 1 Low
- 7 Informational
Findings 8
Main Review
7 findings · August 5 to 7, 2026-
L-01 Low Stale sell liquidity view Unexpected Behavior Acknowledged
Description
The adapter integration documents that Securitize must update
ExternalAssetProvider.availableAsset()to delegate toEthenaPSMAdapter.availableAsset(), but there is no equivalent sell-side liquidity view forExternalLiquidityProvider.availableLiquidity(). In the Securitize ELP implementation,availableLiquidity()resolves the liquidity custodian throughgetLiquidityCustodian()/_custodianOf()and, when the external provider isEthenaPSMAdapter, this reportsUSDC.balanceOf(address(adapter)).That value does not represent redeem-side executable liquidity. Sell output is sourced by
PSM.swap()from the PSM collateral send custodian and is bounded by custodian balance, custodian allowance, and sell-direction PSM caps. As a result,availableLiquidity()can underreport liquidity when the adapter holds no USDC, or overreport liquidity when USDC fees temporarily sit on the adapter beforesweep().This does not directly block redemptions because
ExternalLiquidityProvider.supplyExactIn()does not useavailableLiquidity()as an execution precheck, but frontends or off-chain integrators using the public off-ramp liquidity view may display or act on stale liquidity data.Recommendation
Consider adding a sell-direction liquidity view to
EthenaPSMAdapterthat accounts for collateral send custodian balance/allowance andswapForCollateralPSM caps, and have Securitize delegateExternalLiquidityProvider.availableLiquidity()to it. Alternatively, explicitly document thatavailableLiquidity()is not meaningful for this adapter integration and should not be used for off-ramp capacity decisions. -
I-01 Informational Adapter uses generic low amount error Informational Acknowledged
Description
In
swapExactIn(), the adapter checksamountIn < PSM_MIN_AMOUNT_INbefore resolving the swap direction with_resolveDirection(). As a result, both collateral-to-asset and asset-to-collateral swaps revert with the sameAmountInBelowPsmMinimumerror, instead of preserving the PSM’s direction-specific distinction betweenInvalidCollateralAmountandInvalidAssetAmount.Recommendation
Consider whether the adapter should keep the current generic
AmountInBelowPsmMinimumerror for simplicity, or introduce direction-specific low-amount errors. -
I-02 Informational Underdocumented same beneficiary reason Documentation Resolved
Description
The
READMEdocuments the following key invariant.Key invariant: the adapter always sets beneficiary: address(this) so it can measure the balance delta (received == amountOut) before forwarding funds to the ramp.
While this is technically true, there is another reason why
beneficiarymust be set to the adapter and it is because the benefactor of the order is the adapter as well.PSM._validateBenefactor()reverts if the benefactor and the beneficiary differ, unless the beneficiary is approved for the given benefactor.if (order.benefactor != order.beneficiary && !_benefactorState.config.approvedBeneficiaries[order.beneficiary]) { revert BeneficiaryNotApproved(order.beneficiary); }Because the adapter has no way to call
setApprovedBeneficiary(), this check would have always reverted if the two didn't match.Recommendation
Add this requirement to the key invariant documentation.
-
I-03 Informational Adapter lacks per-investor authorization Informational Resolved
Description
EthenaPSMAdapter.swapExactIn()does not identify or authorize the underlying investor. On the Securitize public on-ramp path, investor access is gated by theBUIDL/Securitize registry and token compliance checks rather than a ramp-specific allowlist. Therefore, any token-level eligible investor can buy or sell through the configured ramp path. The downstreamPSMorder sets bothbenefactorandbeneficiarytoaddress(this), so all ramp users consume the same adapter-level benefactor caps rather than separate per-investor caps.Recommendation
Consider documenting this trust boundary explicitly. If shared token-level investor eligibility is intended, no code change is required. If Ethena wants granular per-investor or per-ramp access control, add authorization or limits in the Securitize ramp/provider path.
-
I-04 Informational
availableAsset()may show dust capacity Informational ResolvedDescription
EthenaPSMAdapter.availableAsset()returns the remainingBUIDLcapacity without consideringPSM_MIN_AMOUNT_IN. If the amount ofBUIDLcan be received by paying USDC below the floor,availableAsset()will return thatBUIDLamount, even though it cannot be executed.This inconsistency affects only
viewpaths, sinceEAP.supplyExactIn()callspreviewSwapExactIn()beforeavailableAsset(), andpreviewSwapExactIn()reverts if the provided amount is below the floor.Recommendation
If this is fine, acknowledge the finding. If not, return 0 in case the
availablevariable is below the minimum executable amount.uint256 minExecutableOut = _pegAmountOut(uint128(PSM_MIN_AMOUNT_IN), true); if (available < minExecutableOut) return 0; -
I-05 Informational
PSMrotation can move pending fees Informational ResolvedDescription
EthenaPSMAdapter.setPsm()rotates the configuredPSMwithout first sweeping token balances held by the adapter.EthenaPSMAdapter.sweep()always reads the currentPSMand sends pending USDC/BUIDL balances to the current PSM custodian addresses.As a result, if USDC ramp fees or stray BUIDL are present on the adapter when
setPsm()is called, a latersweep()sends those pre-rotation balances to the new PSM custodians rather than the custodians configured on the previous PSM.Recommendation
Document that operators should call
sweep()beforesetPsm()when balances should be attributed to the previous PSM custodian set. -
I-06 Informational Incomplete
IGroveBasinLikedocumentation Documentation ResolvedDescription
The
previewSwapExactIn()documentation states that the preview may overestimate when the PSM oracle price deviates belowpegPrice. This only describes the buy-direction case.Since
previewSwapExactIn()replicates only the peg path whileswapExactIn()usespsm.getQuote()and returns the lower of the peg path and oracle path, overestimation for sells can happen whenever the oracle path is lower than the peg path. Whether this occurs below or abovepegPricedepends on direction: belowpegPricefor buys, and abovepegPricefor sells.Additionally, the
previewSwapExactInandswapExactIn()documentations refers totokenInandtokenOutwhile the actual parameters are namedassetInandassetOut.Recommendation
Consider updating the
previewSwapExactIn()documentation to state that overestimation can occur whenever the oracle path wins, with the side of peg depending on swap direction. Also replacetokenIn/tokenOutwithassetIn/assetOut.
Remediation Review
1 finding · August 10, 2026-
I-01 Informational README misstates minimum input units Documentation Resolved
Description
The README states that amounts below
PSM_MIN_AMOUNT_INrevert in collateral-token units. However,EthenaPSMAdapter.swapExactIn()appliesPSM_MIN_AMOUNT_INtoamountInbefore resolving the swap direction, so the floor is denominated in the input token’s units. For sells, this means the threshold is in asset decimals, not collateral decimals.Recommendation
Update the README to state that
PSM_MIN_AMOUNT_INis enforced in input-token units before direction resolution.
No findings match.
More from Ethena
All 7 reports-
Ethena Pay Updates
81 findings3 high 81 findings: 3 high, 14 medium, 39 low, 25 informational -
Onchain Minting
21 findings 21 findings: 3 medium, 9 low, 9 informational -
Ethena Pay
34 findings 34 findings: 3 medium, 7 low, 24 informational -
Execution Guard
12 findings 12 findings: 2 medium, 4 low, 6 informational
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.