ENA
ENA is the governance token of Ethena, a synthetic dollar protocol. Governance is advisory via Snapshot signaling; the Dev Multisig executes all decisions. Fee switch received positive forum signals but awaits Snapshot vote and onchain execution.
ENA governance is advisory only. Tokenholders vote via Snapshot, but the Dev Multisig executes all decisions. There is no onchain governance workflow, no timelock, and ENA holders cannot elect or remove multisig signers. The ENA token itself is non-upgradeable, but sENA and rsENA are upgradeable proxies controlled by separate multisigs. Staking contracts include blacklist capabilities with seizure powers.
ENA governance is offchain Snapshot signaling only. Votes do not trigger onchain transactions. The Dev Multisig decides whether to execute proposals, making tokenholder votes advisory rather than binding. There is no timelock on multisig actions.
Snapshot Governance
ENA holders vote via Snapshot at ethenagovernance.eth. All passed votes require manual multisig execution. Per docs: "fully on-chain governance is not a practical or viable option at present."
Multisig Execution
The Dev Multisig owns all core contracts. Verified onchain: getThreshold() returns 5, getOwners() returns 11 addresses. Documentation claims 4/8, but onchain reality is 5/11.
All privileged roles are controlled by Ethena Labs multisigs or EOAs, NOT by ENA tokenholders. The Risk Committee is elected via Snapshot but has no onchain authority. No mechanism exists for ENA holders to remove or replace multisig signers.
Multisig Control Matrix
Dev Multisig: All contract ownership, upgrades, minting, parameter changes. Signers NOT elected by ENA holders.
Hot Swap: Protocol revenue flow, USDe conversion. Signers NOT elected.
sUSDe Payout: Staker reward distribution. Signers NOT elected.
Trading Operations: Onchain operational activities. Signers NOT elected.
Reserve Fund: Emergency reserve deployment. Signers NOT elected.
EOA Control Points
StakingRewardsDistributor Operator (EOA): Can trigger transferInRewards() to distribute USDe to sUSDe stakers.
Minters (20 EOAs): Can mint USDe via EthenaMinting.
Redeemers (20 EOAs): Can redeem USDe.
Gatekeepers (3+ EOAs): Can disable USDe mint/redeem globally.
sENA is upgradeable via proxy controlled by Dev Multisig. rsENA is also upgradeable but controlled by a different multisig. Neither upgrade path involves tokenholder approval. ENA, USDe, sUSDe, and EthenaMinting are non-upgradeable.
Non-Upgradeable Contracts
ENA, USDe, sUSDe, and EthenaMinting V2 are not proxy contracts.
Upgradeable Contracts (sENA and rsENA)
sENA: Uses EIP-1967 proxy. Dev Multisig can upgrade without tokenholder approval. No timelock.
rsENA: Uses EIP-1967 proxy with a different upgrade controller. Controlled by a separate multisig with signers not publicly identified. No timelock.
The ENA token itself is NOT upgradeable. It uses Ownable2Step, not a proxy pattern. Token behavior is immutable. However, the owner (Dev Multisig) retains mint authority subject to rate limits.
ENA Non-Upgradeability Verification
The ENA token inherits Ownable2Step, ERC20Burnable, ERC20Permit. No upgrade mechanism exists in the contract.
ENA has rate-limited but discretionary minting controlled by the Dev Multisig. Maximum 10% of total supply per mint, with 365-day cooldown between mints. No tokenholder approval required. Total supply is 15 billion ENA.
Mint Function
The mint() function allows the owner to create new tokens subject to two constraints:
MAX_INFLATION = 10 (10% of total supply per mint)
MINT_WAIT_PERIOD = 365 days (minimum time between mints)
Owner (Dev Multisig) can invoke without tokenholder approval.
Gatekeepers can disable USDe minting/redemption globally. Only the Owner can re-enable. The StakingRewardsDistributor operator (a single EOA) controls when rewards are distributed to sUSDe stakers.
Privileged Roles (per Multisig Matrix)
Owner (EthenaMinting): Can set max mint/redeem limits for USDe, add/remove collateral assets and custodians.
Admin (EthenaMinting): Can grant/revoke Minter, Redeemer, Gatekeeper roles.
Gatekeeper: Can call disableMintRedeem() to halt USDe operations globally.
Operator (StakingRewardsDistributor): Single EOA that controls transferInRewards() to distribute USDe to sUSDe stakers.
Gatekeeper Powers
Gatekeepers can halt but only the Owner can re-enable. This creates asymmetric power.
The ENA base token has no blacklist capability. However, sENA and sUSDe staking contracts include BLACKLIST_MANAGER_ROLE with freeze and seizure powers. FULL_RESTRICTED addresses cannot transfer tokens, and redistributeLockedAmount() allows admin to seize frozen assets.
sENA/sUSDe Blacklist Capabilities
StakedUSDe.sol defines three restriction roles:
SOFT_RESTRICTED_STAKER_ROLE: Cannot stake/unstake
FULL_RESTRICTED_STAKER_ROLE: Cannot transfer at all (frozen)
BLACKLIST_MANAGER_ROLE: Can assign restrictions
The redistributeLockedAmount() function allows admin to seize and redistribute frozen assets.
No active programmatic value accrual to ENA holders. sUSDe holders receive USDe yield from protocol operations; sENA holders do NOT receive this yield, only ecosystem airdrops. rsENA holders receive Symbiotic restaking rewards. Treasury flows through multisig-controlled wallets. All accrual mechanisms are controlled by multisigs or EOAs, not tokenholders.
sUSDe holders receive USDe yield; sENA/ENA holders do NOT. sENA holders receive only ecosystem airdrops from Ethena Network protocols. rsENA (~5.2M supply) earns Symbiotic restaking rewards via Mellow Finance. Fee switch (which would share protocol revenue with sENA) received positive forum signals but awaits Snapshot vote and execution.
Fee Switch Status
Forum posts received positive signals in November 2024. USDe supply ~5.98B (the $6B threshold has not been met). Cumulative revenue $500M+ as of Sept 2025. Activation requires Risk Committee sign-off + Snapshot vote + multisig execution.
Ethena Network Airdrops
Protocols in the Ethena Network commit portions of their token supply to sENA holders. Example: Ethereal committed 15% of tokens to sENA holders.
rsENA (Restaked ENA via Symbiotic)
rsENA (~5.2M supply) provides economic security for USDe cross-chain transfers using LayerZero DVN messaging via Symbiotic partnership. rsENA holders receive rewards in ENA and USDe per docs. Available via Mellow Finance vault.
Protocol revenue flows through multisig-controlled wallets. Treasury is NOT tokenholder-controlled. Revenue flows: Hot Swap → sUSDe Payout → StakingRewardsDistributor → sUSDe stakers. ENA tokenholders do NOT control treasury flows.
Revenue Flow
Protocol Operations (delta-neutral strategies)
→ Hot Swap Multisig (receives revenue, converts to USDe)
→ sUSDe Payout Multisig
→ StakingRewardsDistributor
→ sUSDe Stakers
ENA/sENA holders are NOT in this flow unless fee switch activates.
Reserve Fund (Negative Funding Backup)
Separate from revenue treasury. Used only for negative funding emergencies. NOT tokenholder-controlled.
All ENA value accrual mechanisms are controlled by multisigs or EOAs, NOT by ENA tokenholders. Fee switch requires discretionary multisig execution. Ecosystem airdrops are Foundation-negotiated. sENA/rsENA can be upgraded without tokenholder vote.
ENA Value Accrual Controls
Fee Switch Activation: Dev Multisig + Risk Committee. Snapshot votes are advisory only.
Ethena Network Airdrops: Ethena Foundation negotiates allocations.
sENA Upgrade: Dev Multisig via ProxyAdmin. Unilateral, no timelock.
rsENA Upgrade: Separate multisig. Unilateral, no timelock.
rsENA Restaking Rewards: Symbiotic integration.
Upgrade Risk: Contract upgrades could modify or eliminate value accrual mechanisms without tokenholder approval.
Tokenholder Cannot Force Activation
Even with majority sENA/ENA support, tokenholders cannot force fee switch activation or change airdrop terms. Snapshot votes signal preference but the Dev Multisig decides execution. No onchain mechanism exists for binding governance over value accrual.
USDe yield comes from three sources: CEX funding rates (unverifiable), ETH staking (~3-4%), and Treasury/BUIDL (~4-5%). This yield flows to sUSDe stakers only; ENA/sENA holders receive none of it. Revenue is controlled by multisigs, not programmatic.
USDe Yield Sources
CEX Funding Rates: Delta-neutral hedging (long spot, short perps). Variable 5-20%+ yield. Not verifiable onchain (CEX positions).
ETH Staking: stETH/wBETH collateral earns validator rewards (~3-4%). Partially verifiable (collateral visible).
Treasury/BUIDL: USDtb backed by BlackRock BUIDL fund (~4-5%). Partially verifiable (USDtb holdings).
Yield Distribution Flow
- Yield generated offchain (CEX funding) and onchain (staking, treasury)
- Revenue settles through Copper ClearLoop custody (offchain)
- Hot Swap multisig receives and converts to USDe
- sUSDe Payout multisig transfers to StakingRewardsDistributor
- Operator EOA calls
transferInRewards()to distribute to sUSDe stakers only
ENA/sENA holders do NOT receive USDe yield.
All core contracts are verified on Etherscan and open source on GitHub. Multiple security audits completed.
The ENA token contract is verified on Etherscan and matches the source code on GitHub. Solidity version 0.8.20, GPL-3.0 license.
All core protocol contracts are verified on Etherscan. Most have open source GitHub repos. sENA is verified on Etherscan but no public GitHub repo has been identified. Multiple audits completed.
Verified Contracts
GitHub Repository
70% insider allocation. Vesting unlocks continue through April 2028 for all categories. Circulating supply is approximately 55% of total.
Initial allocation heavily favors insiders: Core Contributors (30%), Investors (25%), Foundation (15%), Ecosystem Development (28%), Binance Launchpool (2%). The combined insider bloc (Contributors + Investors + Foundation) controls 70% of total supply.
Token Allocation
Total supply: 15 billion ENA.
Circulating: ~8.2 billion (55%).
Locked: ~6.8 billion (45%).
Insider bloc: Contributors (30%) + Investors (25%) + Foundation (15%) = 70%
Monthly unlocks continue for all vesting categories through April 2028. Contributors, Investors, and Ecosystem receive linear monthly unlocks. Foundation allocation has no disclosed vesting.
Vesting Schedules
Core Contributors (30%): 1-year cliff (25%), then 3-year linear monthly. Full unlock ~April 2028.
Investors (25%): 1-year cliff (25%), then 3-year linear monthly. Full unlock ~April 2028.
Ecosystem Development (28%): Linear over 4 years. Full unlock ~April 2028.
Foundation (15%): Discretionary, no vesting disclosed.
Next unlock: March 2, 2026 (~40.6M ENA to Contributors).
Trademarks and IP owned by Ethena (BVI) Limited, not controlled by ENA tokenholders. Primary interfaces operate under BVI law. Code is open source but copyright belongs to Ethena Labs.
Trademarks and brand assets are owned by Ethena (BVI) Limited (Registration number 2127704), a British Virgin Islands entity. Per Terms of Service: "The Company's name, trademarks and logos... are trademarks of the Company or its affiliates." This entity is NOT controlled by ENA tokenholders.
The primary interface domain (ethena.fi) and Terms of Service identify Ethena (BVI) Limited as the contracting party, governed by British Virgin Islands law. ENA holders have no legal claim or control over the primary interface.
Smart contract code is licensed under GPL-3.0, making it open source. However, per Terms of Service: "the Company and/or its licensors own all right, title and interest in and to the Services." Copyright belongs to Ethena Labs. ENA holders do NOT control IP or licensing rights.
Stay up-to-date on the latest token reports
Get an email when we publish a new token report or release major updates to the Framework.
