ONDO
Ondo Finance tokenizes real-world assets: OUSG (US Treasuries), USDY (yield-bearing stablecoin), and Global Markets (tokenized equities). ONDO token has no control over these core products; team multisigs govern all ~$3.5B TVL.
Core Ondo products are controlled by team multisigs. ONDO governance controls Flux Finance, but Flux appears small relative to Ondo's other product TVL. The ONDO token contract has team-held admin and minting roles. Supply is 10B with active mint capability.
ONDO tokenholders have no governance control over Ondo's core products (OUSG, USDY, Global Markets). These products represent ~$3.5B TVL (98.8% of total) and are controlled by company multisigs.
OUSG/USDY/Global Markets Governance (Company-Controlled)
All core products are controlled by company multisigs with no tokenholder involvement:
-
OUSG: Management Multisig holds DEFAULT_ADMIN_ROLE and ProxyAdmin ownership.
-
USDY: Team Multisig holds ProxyAdmin ownership.
-
Global Markets: TimelockController with 2-hour delay, controlled by company multisigs.
No forum discussion required. No onchain tokenholder vote. Changes proposed and executed by multisig signers.
OUSG, USDY, and Global Markets are entirely controlled by company multisigs. The ONDO token itself has DEFAULT_ADMIN_ROLE and MINTER_ROLE held by team multisigs, not the DAO.
Team-Controlled Roles (ONDO Token)
DEFAULT_ADMIN_ROLE: Team Multisig (4-of-7).
MINTER_ROLE: Team Multisig (4-of-7).
The team can grant/revoke roles and mint new ONDO tokens without DAO approval.
Team-Controlled Roles (OUSG/USDY)
OUSG DEFAULT_ADMIN_ROLE: Management Multisig (4-of-7).
OUSG ProxyAdmin owner: Management Multisig (4-of-7).
rOUSG ProxyAdmin owner: Management Multisig (4-of-7).
USDY ProxyAdmin owner: Team Multisig (4-of-7).
rUSDY ProxyAdmin owner: Team Multisig (4-of-7).
Team-Controlled Roles (Global Markets)
GMTokenManager/USDon DEFAULT_ADMIN_ROLE: TimelockController (2-hour delay).
TimelockController PROPOSER_ROLE: Multisig (4-of-7).
TimelockController EXECUTOR_ROLE: Multisig (1-of-8) + EOA.
TimelockController DEFAULT_ADMIN_ROLE: Multisig (5-of-9).
OUSG, USDY, and Global Markets are upgradeable contracts controlled by team multisigs on all chains. ONDO tokenholders have no upgrade control over any core products.
OUSG/USDY (Team-Controlled)
Ethereum OUSG ProxyAdmin owner: Management Multisig (4-of-7).
Ethereum USDY ProxyAdmin owner: Team Multisig (4-of-7).
Polygon OUSG ProxyAdmin owner: 3-of-6 Multisig.
Mantle USDY ProxyAdmin owner: 4-of-7 Multisig.
Arbitrum USDY ProxyAdmin owner: 4-of-7 Multisig.
The DAO has no upgrade authority over OUSG or USDY on any chain.
Global Markets (Team-Controlled via TimelockController)
USDon is an upgradeable proxy. Upgrade authority resides with TimelockController (2-hour delay) which is controlled by company multisigs. ONDO tokenholders have no upgrade control.
The ONDO token is not upgradeable (no proxy pattern). It uses AccessControl with DEFAULT_ADMIN_ROLE and MINTER_ROLE held by a team multisig, not the DAO.
ONDO Token Roles
DEFAULT_ADMIN_ROLE holder: Team Multisig.
MINTER_ROLE holder: Team Multisig.
The team can grant/revoke roles and mint new tokens. The DAO has no control over these roles.
Contract Source Note
The deployed ONDO token uses AccessControl. The public ondo-v1 repository shows a simpler Ownable-based contract, indicating the deployed contract differs from the public repo.
ONDO has a total supply of 10B tokens. MINTER_ROLE exists and is held by a team multisig. The supply is not immutably fixed.
Current Supply
Total supply: 10,000,000,000 ONDO (verified onchain).
Team Multisig balance: ~5.9B ONDO (~59% of supply).
Documentation states "no scheduled or planned inflation" but this is a policy statement, not code enforcement.
Mint Function Exists
The deployed ONDO token includes a mint() function restricted to MINTER_ROLE holders. Team multisig holds MINTER_ROLE and can mint new tokens without DAO approval.
OUSG and USDY have extensive transfer restrictions (KYC requirements, blocklists, sanctions checks) enforced by Ondo Finance, not the DAO. The company controls who can hold these products.
OUSG Transfer Restrictions
KYC required via KYCRegistry. The _beforeTokenTransfer hook enforces three-way checks: sender, receiver, and msg.sender must all be KYC-approved. The DAO does not control the KYC registry.
USDY Transfer Restrictions
USDY has blocklist, allowlist, and sanctions list checks. Transfers require passing all three checks. These are controlled by the company, not the DAO.
The ONDO token has no blocklist, freeze, or seizure functions. Transfers are permissionless. Transfers were enabled in January 2024.
No Censorship Capability
transferAllowed = true (verified onchain, enabled January 2024).
No blacklist mapping.
No pause function for transfers.
No force transfer or seize functions.
The token contract has a whenTransferAllowed modifier but transfers are permanently enabled.
No active value accrual mechanism was identified for ONDO holders. Ondo has multiple products with documented product-level economics, including yield, fees, expenses, and spreads, but no identified flow from those economics to ONDO holders or an ONDO-controlled treasury. Flux is ONDO-governed but small relative to Ondo's other product TVL, so it does not materially change the assessment.
No active value accrual mechanism for ONDO tokenholders was identified. Ondo products have documented product-level economics, but Aragon did not identify a fee distributor, staking reward, buyback program, DAO treasury, or other mechanism routing product economics to ONDO holders.
Product Economics vs ONDO Holder Accrual
Ondo has products with documented product-level economics, including yield, fees, expenses, and spreads. Those mechanics do not identify an ONDO-holder accrual mechanism.
Aragon has not been able to identify a DAO treasury address for ONDO governance. No FeeDistributor or Treasury contract exists.
No Treasury Identified
No DAO treasury contract identified. No fee distribution mechanism was identified for Ondo product economics. No governance proposals for treasury creation were identified.
ONDO holders have no identified control over revenue routing for Ondo's core products. Core product parameters are controlled by company-held roles and multisigs. Flux is ONDO-governed but represents a small share of Ondo TVL.
OUSG/USDY Price Oracles (Company-Controlled)
The price oracles that determine OUSG/USDY NAV are controlled by SETTER_ROLE-restricted setPrice() functions. ONDO tokenholders cannot control these oracle price-update roles.
Global Markets (Company-Controlled via TimelockController)
GMTokenManager admin is TimelockController (2-hour delay). ONDO tokenholders have no control over Global Markets fee parameters.
Ondo product economics may accrue through product-holder yield, issuer/operator fees, spreads, expenses, or service revenue, but no documented offchain value-accrual flow to ONDO holders was identified.
Ondo Product Economics
Ondo products have documented product-level economics, including yield, fees, expenses, and spreads. These mechanics describe product economics, not ONDO-holder accrual. No onchain mechanism guarantees that residual issuer/operator economics flow to ONDO holders.
Global Markets Revenue
Global Markets documentation describes fees and quote spreads retained by Ondo Global Markets. Aragon did not identify a mechanism routing those fees or spreads to ONDO holders or an ONDO-controlled treasury.
ONDO token is verified on Etherscan. OUSG/USDY/Global Markets contracts are verified with public GitHub and audit code available. The deployed ONDO token uses AccessControl, which differs from the public ondo-v1 repository.
The ONDO token contract is verified on Etherscan. The deployed contract uses AccessControl, which differs from the simpler Ownable-based contract in the public ondo-v1 repository.
OUSG, USDY, and Global Markets contracts are verified on Etherscan. Public GitHub repositories and audit code available.
Global Markets
~59% of ONDO supply is held by a single team multisig, giving effective governance control. Vesting schedules exist per documentation but specific addresses are not publicly verifiable onchain.
~59% of ONDO supply is held by a single team multisig. This gives the team unilateral control over governance. The team can pass any proposal and block any proposal.
Team Holdings
Team Multisig balance: ~5.9B ONDO (~59% of supply).
Total supply: 10B ONDO.
Multisig config: 4-of-7.
This multisig also holds DEFAULT_ADMIN_ROLE and MINTER_ROLE on the ONDO token. "Decentralized governance" is effectively team governance.
Per documentation, unlock schedules exist for team and investors with unclear start dates, but the token being transferrable from Jan 2024 allows an educated guess of many unlocks yet to pan out. Aragon has not been able to verify specific vesting contract addresses from onchain data.
Documented Schedule
CoinList Tranche 1 (~0.3%): 1-year lock, then 18-month linear release.
CoinList Tranche 2 (~1.7%): 1-year lock, then 6-month linear release.
Seed Investors (<7%): 1-year cliff, then 48-month release.
Series A (<7%): 1-year cliff, then 48-month release.
Core Team: 5-year extended lock-up from the transfer unlock.
Aragon has not been able to verify specific vesting contract addresses or unlock schedules from onchain data.
Ondo Finance Inc. operates the primary website, documentation, APIs, dashboards, and technical interfaces under its Terms of Service. The Terms preserve Ondo-related trademark/IP rights and separate interface services from product issuance or economic terms. Certain product source files use BUSL-1.1 SPDX headers, but no tokenholder-controlled licensing right was identified.
Ondo's Terms of Service state that Ondo names, logos, and marks used on the site or services are owned by Ondo, its affiliates, Covered Entities, or applicable licensors.
Ondo Terms of Service - Proprietary Rights
The Terms reserve Ondo names, logos, and marks to Ondo, its affiliates, Covered Entities, or applicable licensors, and do not grant users rights in those trademarks.
Ondo Finance Inc. controls the primary website, documentation, APIs, dashboards, and technical interfaces. The Terms of Service identify Ondo Finance Inc. as the contracting party for those interface services, while product issuance and economic terms are governed separately by Covered Entity terms.
Ondo Terms of Service - Interface Services
Ondo Finance Inc. operates the site and interface services. The Terms also state that Covered Entities are separate legal entities providing their own services under their own terms.
Certain USDY/rOUSG source files use SPDX-License-Identifier: BUSL-1.1. BUSL-1.1 is not an open-source license and restricts production/commercial use until the applicable change date or open-source conversion.
BUSL-1.1 Source Headers
USDY and rOUSG source files include BUSL-1.1 SPDX headers. No repo-level license file or tokenholder-controlled license holder was identified.
Stay up-to-date on the latest token reports
Get an email when we publish a new token report or release major updates to the Framework.
