Is Ethena Safe in 2026? A Security Analysis

TL;DR verdict

Ethena is conditionally safe. No smart contract hacks have been recorded against the protocol, and its code has been reviewed by three reputable audit firms: Pashov, Quantstamp, and Spearbit. However, USDe’s delta-neutral strategy depends on centralized exchanges to hold derivative positions, introducing significant counterparty and custody risks. With a TVL of roughly $4.5B and a relatively short operational history since a 2024 launch, Ethena remains higher-risk than fully decentralized stablecoin alternatives. Notably, on 11 October 2025 USDe briefly traded down to about $0.65 on Binance during a market-wide crash — a venue-specific dislocation caused by Binance's margin-collateral pricing, not an Ethena smart-contract failure; USDe held near parity elsewhere and remained fully backed. Use with caution and only after understanding the centralization vectors.

Audit history

Ethena’s smart contracts have been audited by three security firms:

All audits were completed before mainnet launch, and the protocol has not experienced any post-audit incidents. However, the rapid expansion to new chains (Ethereum, Solana, Arbitrum, Base, Bybit, Mantle) may introduce new attack surfaces that have not yet been audited on every deployment.

Incidents and exploits

Ethena has not suffered an on-chain smart-contract exploit as of 2026-07-15, despite holding roughly $4.5B in value, and there has been no loss of funds due to oracle manipulation or a governance attack. It has, however, weathered several stress events. In September 2024 Ethena Labs' domain registrar account was briefly compromised (a front-end/DNS incident that did not touch protocol funds). In February 2025 the Bybit hack — a key CEX venue for USDe hedging — sparked depeg fears, but Ethena confirmed backing assets were held off-exchange with a custodian. And on 11 October 2025, USDe momentarily depegged to ~$0.65 on Binance during a broad crypto crash; the drop was isolated to Binance and tied to how its unified-margin system priced collateral, not to under-collateralization of USDe, which stayed near $1 elsewhere. These episodes validated the design under duress but underline USDe's exposure to centralized-venue and market-structure risk.

Smart contract risks

Ethena’s contracts are relatively new (launched 2024), so they lack the multi-year battle testing of protocols like Aave or Lido. The protocol uses a proxy-based upgrade pattern, which allows the team to modify logic but requires trust in the multisig signers and the governance process. Oracle dependencies exist for pricing the USDe peg and the underlying hedging assets; any manipulation or failure in these oracles could lead to incorrect minting or liquidations. Additionally, the integration with multiple chains increases the complexity and potential for cross-chain vulnerabilities.

Operational and counterparty risks

The primary risk for Ethena is counterparty exposure. USDe’s stability is maintained by shorting perpetual futures on centralized exchanges, meaning a significant portion of the protocol’s collateral resides on CEXs like Bybit. Exchange hacks, insolvencies, or withdrawal halts could directly impact USDe’s backing and cause a depeg. Team transparency is moderate; Ethena Labs operates the protocol, but the governance token ENA is used for DAO decisions, though key decision-making remains concentrated. Regulatory risk is elevated—stablecoin issuers face uncertain legal frameworks, especially those involving centralized intermediaries. There is no known insurance fund or Nexus Mutual-style coverage for USDe holders, so losses from a counterparty failure would likely be socialized among users.

How to use it more safely

Verdict

Ethena sits at a 7.2 out of 10 on DeFi Intel’s safety scale. It has passed multiple audits and has no exploit history, but its reliance on centralized exchange infrastructure introduces unique risks not present in overcollateralized decentralized stablecoins. If you can tolerate the counterparty and regulatory uncertainties, USDe may offer attractive yields, but it should be approached as a conditional safe asset rather than a fully trust-minimized one.

DeFi Intel publishes editorial research, not financial advice. Smart contract risk is never zero. Do your own research and consider position sizing accordingly.

Frequently asked questions

Has Ethena ever been hacked?

No. As of 2026-05-28, Ethena has not suffered any smart contract exploits or loss of user funds.

Who audits Ethena?

Ethena’s code has been audited by Pashov, Quantstamp, and Spearbit. These audits cover the core USDe minting, staking, and oracle integrations.

What are the main risks of using Ethena?

The biggest risk is counterparty centralization: USDe relies on centralized exchanges to maintain its delta-neutral position. Exchange hacks, insolvencies, or regulatory actions could cause a depeg. Other risks include oracle manipulation, upgradeability via multisig, and limited insurance.

Is Ethena's code open source?

Yes, Ethena’s on-chain core contracts are open source and verifiable. However, the off-chain management components and CEX execution logic are not fully transparent.

Sources