How It Works
USD.estate is a two-sided credit protocol. It connects issuers of institutionally structured real-estate bonds with depositors who want yield from real-estate credit. The protocol takes onchain dollar deposits, keeps a liquid Treasury bill reserve, allocates the remainder to permissioned real-estate bonds, and distributes the yield through a tokenized instrument stack. Legal title to every bond position sits offchain with a dedicated holding subsidiary.
The system has three layers:
- Reserve layer, where capital enters as USDest.
- Allocation layer, where the sUSDest vault holds reserve and bond positions.
- Governance layer, where the USD.estate Foundation, a strategy multisig and a public timelock set and enforce protocol parameters.
Capital In: USDest and sUSDest
Capital enters the protocol when an approved institution deposits USDC and receives USDest, a synthetic dollar pegged 1:1 and fully backed by USDC reserves. Part of the reserve is held in tokenized short-dated US Treasury bill funds. USDest itself does not generate yield. It is a stable, composable asset for holding, transferring or using across DeFi.
To earn yield, holders stake USDest and receive sUSDest, the protocol's yield-bearing token. sUSDest earns from two sources:
- USDC coupons from real-estate bonds held by the vault.
- Treasury bill yield on the USDest reserve, harvested into the vault.
Yield is reflected in a rising exchange rate between USDest and sUSDest. Holders do not need to claim anything.
Direct minting and redemption of USDest at the smart contract level is restricted to allowlisted, KYC-verified market makers and institutions. USDest and sUSDest are always permissionless to hold, transfer, stake and trade on secondary markets.
Capital Out: Real-Estate Bonds and T-bills
On the allocation side, the protocol does not lend. It subscribes to permissioned real-estate bonds: ERC-3643 security tokens issued by regulated vehicles and secured on, or backed by, real estate. The initial eligible universe includes:
- Luxembourg securitisation notes, for example Tortuga T-Evergreen notes issued from segregated compartments.
- Swiss-ISIN real-estate bonds, for example bonds issued through Estating.
No bond is eligible until it is added to the bond allowlist, and every addition waits out a public timelock. Once a bond is allowlisted, the strategy multisig may allocate to it within the guardrails:
Each position follows four phases: eligibility review, allowlisting, subscription and settlement, then holding through coupons to maturity. See Issuers & Bonds.
The Hybrid Structure: Onchain Meets Offchain
USD.estate runs on two record systems at once.
Offchain, the bond documentation gives each position real-world enforceability: securitisation compartments, trustees and noteholder representatives, paying agents, security over property, and a Cayman holding subsidiary as the legal holder of every position.
Onchain, the protocol gives transparency and programmability. The BondPositionManager is an allowlisted ONCHAINID identity that holds the ERC-3643 bond tokens. Vault accounting records every position, accrued coupon and reserve balance. The guardrails are checked on every allocation.
The two layers are reconciled at every material event: subscription, coupon, principal repayment, credit event and recovery. See Onchain / Offchain Structure.
Risk Mitigation and Collateral Protection
Credit protection comes from the structure of the assets themselves:
- Real-estate collateral with loan-to-value limits set in the eligibility criteria.
- Issuer structures that ring-fence assets from the sponsor's balance sheet.
- Diversification enforced by the per-issuer cap.
- Hold-to-maturity: the protocol never sells a bond early to meet withdrawals.
- Reserve floor: a minimum share of vault NAV kept as unallocated USDest, so redemptions are funded without selling bonds.
There is no insurance policy and no token backstop. See Risks & Mitigants.
Readers can check live reserve balances and bond positions in Proof of Reserves.
Redemptions and Liquidity
Bonds are long-dated and illiquid, so sUSDest redemptions run on a fixed epoch cycle with a FIFO queue. At each epoch close, available USDest is paid out to queued requests. If demand is high and the reserve is fully used, the queue can carry over into later epochs. The protocol does not sell bonds early to satisfy withdrawals. Holders who need to exit immediately can sell sUSDest on secondary markets at the market price.
Deposits and redemptions use two different share prices. The deposit price includes coupon accrued but not yet received; the redemption price excludes it. This stops depositors from buying in just before a coupon lands and leaving right after. See Deposit and Redemption Prices.
Governance: Foundation, Strategy Multisig and Timelock
The USD.estate Foundation operates the protocol. A strategy multisig makes allocation decisions and services redemptions, bounded by guardrails enforced in the smart contracts. Changes to the guardrails, the bond allowlist and fee parameters are queued through a timelock controller, so depositors can see them before they take effect. No governance token has been issued.
The Sections That Follow
- Issuers & Bonds: bond allocation lifecycle, eligibility, legal structure, onchain/offchain mechanics and service providers.
- Depositor: USDest, sUSDest, yield mechanics, deposit and redemption prices, and redemptions.
- Governance: every protocol parameter, who can change it, and the protocol's economics.
- App Guide: step-by-step use of the App for depositors and approved institutions.
- Technical Overview: smart contract architecture, audits and deployed contract addresses.
Ready to enter the protocol? Get USDest.