> For the complete documentation index, see [llms.txt](https://docs.tapir.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tapir.money/security/vault-risk-reports/zircuit-finance-usdc.md).

# Zircuit Finance — USDC Vault

USD Coin (USDC) vault on Base. Share token: zvUSDC.

Prepared by Tapir Protocol. Tapir has a commercial relationship with Zircuit concerning a product that uses zvUSDC and an interest in its adoption. Zircuit provided factual comments on an earlier draft. The assessments below are Tapir's; factual review does not imply Zircuit's endorsement. The report covers the underlying vault, excluding products that use its shares.

## 1. Summary

Zircuit Finance combines institutional investment strategies with on-chain lending in a single vault. At the research snapshot, the vault reported 1,354,524.93 USDC of accounting assets. Monarq represented 84.44%, Morpho strategies on Base and Ethereum together represented 13.59%, and the WisdomTree-labelled strategy represented 1.87%. The remainder was 0.09% of accounting value. Monarq is therefore the principal driver of credit, valuation, and repayment exposure. [Vault](https://basescan.org/address/0x03067bbD0d41E3Fe4A0bb6ca67c99e7352Da4CAE#code), [Base strategy accounting](https://basescan.org/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code), [Ethereum strategy accounting](https://etherscan.io/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code).

There is positive operating evidence. The public performance series records a 2.91% increase in share value over approximately 130 days. All 72 requests in the reviewed Base withdrawal queue were either fulfilled or cancelled by the requester, with none pending. A public transaction records a 392,800 USDC institutional repayment. These observations establish an operating history; they do not establish how the vault would perform during borrower distress. [Performance series](https://yields.llama.fi/chart/437a4c66-b5a7-416b-853a-565433679627), [withdrawal queue](https://basescan.org/address/0xBb801ED781dF31F660cC743bEf7Bb9D04B030923#code), [repayment transaction](https://basescan.org/tx/0xb803f439f130f9483d741ccce877381c6af995949322fef3477dd56ccfbc993f).

The vault has verified contract source, a 3-of-5 multisignature Safe for core control, strategy allowlisting, and separate steps for institutional valuation and vault reporting. Five security reports are publicly available. These controls address contract and operational risks. Institutional repayment and the accuracy of off-chain valuations remain dependencies that cannot be verified from vault balances alone. [Contracts](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/zircuit-finance-addresses), [Safe](https://basescan.org/address/0xC0a7c631f50ABaaAb9942839720803E16A24172d#readProxyContract), [institutional strategy](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code), [audit reports](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/security).

The assessment distinguishes a decline in asset value from a delay in obtaining USDC. It gives no composite protocol score, investment recommendation, or judgment on whether the yield compensates for the risks.

## 2. Scope and evidence

The reviewed vault is `0x03067bbD0d41E3Fe4A0bb6ca67c99e7352Da4CAE` on Base. The snapshot uses Base block **50,990,192**, timestamp **2026-09-07 08:28:51 Coordinated Universal Time (UTC)**, and Ethereum block **25,924,286**, timestamp **08:28:47 UTC**. Public documentation and reports were checked on 2026-09-07. Historical series have their own stated observation periods. [Base block](https://basescan.org/block/50990192), [Ethereum block](https://etherscan.io/block/25924286), [official addresses](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/zircuit-finance-addresses).

The report covers investment exposure, accounting, withdrawals, contract control, infrastructure, and the holder's claim. Its factual findings rely on the public sources cited below. The work is a review of that evidence, not a new security audit, a fund audit, or a legal opinion.

Three distinctions apply throughout:

* On-chain observations establish what a contract stored or executed at the specified block. They do not independently establish the value of assets held off chain.
* Provider statements describe Zircuit's or a counterparty's published position. A published service target or product description is not automatically an enforceable holder right.
* Analytical scenarios describe consequences under stated assumptions. They are not forecasts or evidence that an impairment has occurred.

The risk register separates an observed exposure from the likelihood of a future event. **Unknown** means the evidence does not support an estimate. **Conditional** means the outcome requires the stated trigger. Neither means that an event is likely. Impact is assessed before uncertain recoveries: **low** is limited at the current allocation; **medium** is a meaningful cost or interruption; **high** is material loss or prolonged restricted access; **severe** can affect most of the vault. These are qualitative judgments, not statistical probabilities.

## 3. How the vault works

Users deposit USDC and receive zvUSDC shares. The deployed vault follows Ethereum Request for Comments 4626 (ERC-4626), a standard for tokenized vaults. Its accounting asset is the internal zUSDC token at `0xd7aBC360dfcF1B6dD0a03138235e12A2bc1c1C8B`. A zvUSDC accounting conversion is consequently distinct from cash immediately available for withdrawal. [Vault](https://basescan.org/address/0x03067bbD0d41E3Fe4A0bb6ca67c99e7352Da4CAE#code), [architecture](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults).

The StrategyManager allocates capital among approved strategies. Institutional lender contracts transfer capital to designated receivers. A designated reporting address proposes the institutional value, a keeper accepts it, and strategy and vault reports carry changes into the share price. The contracts expose these steps, but do not independently observe a fund's custody accounts, leverage, or liabilities. [StrategyManager](https://basescan.org/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code), [InstitutionLender](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code).

At the snapshot, total supply was **1,295,249.896002 zvUSDC**. Dividing 1,354,524.928746 accounting assets by that supply gives **1.045763 USDC-denominated accounting assets per share**. [Vault](https://basescan.org/address/0x03067bbD0d41E3Fe4A0bb6ca67c99e7352Da4CAE#code).

| Allocation                                       | Accounting value, USDC | Share of vault |
| ------------------------------------------------ | ---------------------: | -------------: |
| Monarq institutional strategy, Base              |           1,143,772.93 |         84.44% |
| WisdomTree-labelled institutional strategy, Base |              25,353.88 |          1.87% |
| Morpho strategy, Base                            |              55,237.97 |          4.08% |
| Morpho strategy, Ethereum                        |             128,895.52 |          9.52% |
| Residual accounting value                        |               1,264.63 |          0.09% |
| Total                                            |           1,354,524.93 |        100.00% |

Strategy values are the StrategyManagers' stored `getUnderlyingByStrategy` amounts, rather than the total value of each strategy contract, which can include shares belonging to other accounts. The residual is total vault assets minus those four amounts. It includes value not assigned by this calculation and is not assumed to be immediately liquid. Cross-chain reports need not be synchronized with underlying strategy accrual. Displayed percentages may differ from a dashboard refreshed at another time. [Base strategy accounting](https://basescan.org/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code), [Ethereum strategy accounting](https://etherscan.io/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code).

Zircuit's current overview identifies WisdomTree as a money-market strategy with next-day liquidity. The live strategy is labelled WisdomTree. This supports that identification at the product level; the label alone does not verify the complete underlying legal or custody arrangement. Prospective managers listed in product materials are not counted as funded allocations. [Product overview](https://docs.zircuit.com/zircuit-finance/overview), [WisdomTree lender](https://basescan.org/address/0x7C19aADD063487676b9Dc58968Ed0761d99cE80B#code).

## 4. Performance and operating history

DefiLlama's public series contains 193 observations from 2026-02-27 through 2026-09-07. The arithmetic mean of reported base annual percentage yield (APY) was **8.25%**, with **8.30%** over the last 90 observations and **7.81%** over the last 30. The latest observation was **7.84%**. Zircuit's own endpoint reported a 30-day APY of **7.82%** when checked. These are provider-reported annualized rates, not audited fund returns or a return available to every entrant. [Historical data](https://yields.llama.fi/chart/437a4c66-b5a7-416b-853a-565433679627), [Zircuit APY endpoint](https://finance.zircuit.com/api/apy).

The available share-price series runs from 2026-04-29 23:03:10 UTC to 2026-09-07 08:01:29 UTC. Its relative increase was **2.91% over 130.37 days**, calculated as ending share price divided by starting share price, minus one. Using actual elapsed time, that is **8.15% simple annualized** or **8.36% compounded annualized**. The raw series uses a scaled share-price field; the growth calculation uses the ratio, so the common scale cancels. Annualization describes this period and is not a forecast. [Historical data](https://yields.llama.fi/chart/437a4c66-b5a7-416b-853a-565433679627).

The Base VaultComposer queue contained **72 requests: 64 fulfilled, eight cancelled, and zero pending**. This is a complete count of that contract's entries at the snapshot, not an end-to-end timing study of every cross-chain withdrawal. [Withdrawal queue](https://basescan.org/address/0xBb801ED781dF31F660cC743bEf7Bb9D04B030923#code).

On **2026-06-19**, the Monarq lender received **392,800 USDC** in a successful `returnFunds` transaction. Its `RepaymentReceived` event applied the full amount to pending institutional withdrawals. Vault accounting assets at the transaction block were 1,507,962.70 USDC, making the repayment approximately **26.05%** of that value. This is evidence that a material institutional repayment occurred. It is not evidence of repayment capacity during a loss event, nor proof that a single end-user withdrawal of the same size settled at that moment. [Transaction and logs](https://basescan.org/tx/0xb803f439f130f9483d741ccce877381c6af995949322fef3477dd56ccfbc993f).

## 5. Risk register

The register is a navigation aid to the detailed assessment in section 6. Observed conditions and missing evidence are identified separately from event likelihood. No loss probability can be responsibly calibrated from this short operating record alone.

| ID  | Risk event or condition                                            | Likelihood basis                                             | Potential impact                                           | Assessment |
| --- | ------------------------------------------------------------------ | ------------------------------------------------------------ | ---------------------------------------------------------- | ---------- |
| R1  | Monarq credit, trading, or custody impairment                      | Unknown                                                      | Severe at the current weight                               | 6.1        |
| R2  | Single-manager concentration amplifies R1                          | Exposure observed                                            | Severe if the manager allocation is substantially impaired | 6.1        |
| R3  | Connected counterparties transmit a common shock                   | Ownership link observed; loss likelihood unknown             | High, depending on actual shared exposure                  | 6.1        |
| R4  | Withdrawal demand exceeds accessible liquidity                     | Conditional on request size and available assets             | High for access; delay alone is not a principal loss       | 6.2        |
| R5  | A pause prevents processing or cancellation                        | Conditional on a pause                                       | Medium to high for access                                  | 6.2        |
| R6  | Institutional valuation is stale or materially incorrect           | Permissioned input observed; misstatement likelihood unknown | High                                                       | 6.3        |
| R7  | Loss recognition is delayed by the reporting sequence              | Conditional on a loss or disputed valuation                  | High for timely valuation and exits                        | 6.3        |
| R8  | Withdrawal ordering redistributes an unreported loss               | Conditional on a loss and withdrawals preceding its report   | High for remaining holders                                 | 6.3        |
| R9  | Recovery is delayed or reduced by the legal claim structure        | Conditional on an impairment or dispute                      | High                                                       | 6.4        |
| R10 | Core administrative authority is compromised or misused            | Authority observed; event likelihood unknown                 | Severe                                                     | 6.5        |
| R11 | The operating account is compromised                               | Permissions observed; event likelihood unknown               | High within the account's permitted functions              | 6.5        |
| R12 | Reporting or withdrawal operations become unavailable              | Operational dependency observed; event likelihood unknown    | High if prolonged                                          | 6.5        |
| R13 | A contract defect causes loss or blocks use                        | Unknown                                                      | High, potentially severe for a core defect                 | 6.6        |
| R14 | Deployed changes fall outside evidenced audit coverage             | Mapping limitation observed; defect likelihood unknown       | Indirect; a missed defect could have high impact           | 6.6        |
| R15 | Bridge or cross-chain message failure affects assets or accounting | Conditional on the affected route                            | High; scope depends on the path                            | 6.7        |
| R16 | Base becomes unavailable                                           | Unknown                                                      | Medium to high for access and reporting                    | 6.7        |
| R17 | USDC depegs or relevant addresses are frozen                       | Unknown                                                      | High to severe; common asset exposure                      | 6.7        |
| R18 | Recovery after a reported loss incurs another performance fee      | Conditional on loss and later positive reports               | Low to medium, depending on the recovery                   | 6.8        |
| R19 | WisdomTree strategy impairment or repayment delay                  | Unknown                                                      | Low direct loss at the current 1.87% weight; can grow      | 6.1        |
| R20 | Morpho strategy or lending-market impairment                       | Unknown                                                      | High if both allocations are substantially impaired        | 6.1        |
| R21 | Allocation or strategy changes alter holder exposure               | Change authority observed; future use unknown                | High, depending on the change                              | 6.5        |
| R22 | Expected smart-contract cover does not respond                     | Coverage terms not established in this review                | High if a material loss was assumed to be covered          | 6.6        |
| R23 | Service or legal restrictions interrupt access or wind-down        | Rights and dependencies observed; event likelihood unknown   | Medium to high for access and recovery                     | 6.4        |

These impacts are not additive. For example, concentration, valuation, delayed recognition, and legal recovery can describe different consequences of the same institutional impairment.

## 6. Detailed assessment

### 6.1 Investment exposure and concentration

Monarq accounts for most of the vault's investment exposure. Its lender contract can record a claim on institutional capital and request its return, but cannot force an off-chain repayment. The public overview describes the allocation as a quantitative delta-neutral fund. That description does not establish current leverage, venue concentration, or available collateral. The on-chain cap and reporting checks constrain transfers and accounting. Repayment also depends on the institution's financial position. The completed repayment in section 4 demonstrates that the return mechanism has handled a material amount. [Product overview](https://docs.zircuit.com/zircuit-finance/overview), [lender mechanics](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code), [repayment](https://basescan.org/tx/0xb803f439f130f9483d741ccce877381c6af995949322fef3477dd56ccfbc993f).

FalconX publicly announced an investment in Monarq. A United States Securities and Exchange Commission filing describes majority ownership of MNNC Capital GP LLC through FalconX's subsidiary Monarch Digital. This establishes a corporate connection. It does not quantify the vault's exposure to FalconX custody, financing, or execution services. The analysis therefore recognizes possible correlated dependencies without treating every FalconX-group activity as a vault exposure. [FalconX announcement](https://www.falconx.io/newsroom/monarq-asset-management-announces-strategic-investment-from-falconx), [ownership filing](https://www.sec.gov/Archives/edgar/data/1737995/000119312526051654/xslSCHEDULE_13D_X01/primary_doc.xml).

MNNC Capital Digital Asset Opportunities Master Fund LP is named in a creditor-matrix service list attached to a June 10, 2026 filing in the BlockFills proceedings. A service-list entry does not establish the amount, validity, recovery value, or present status of a claim. It also does not establish a loss to capital backing zvUSDC. No specific impairment is attributed to this record in the calculations. [Court filing, exhibit U](https://www.veritaglobal.net/blockfills/document/2610371260610000000000005).

The smaller strategies introduce their own exposures. WisdomTree uses a separate institutional lender, so contract accounting alone does not verify the value and accessibility of its off-chain holdings. Morpho positions are on chain, but remain exposed to the specific lending markets, collateral, contract behavior, and available withdrawal liquidity. Two Morpho strategies on different networks do not constitute two independent protocol dependencies. Their combined weight is 13.59%; a common impairment would affect both. [WisdomTree contract](https://basescan.org/address/0x7C19aADD063487676b9Dc58968Ed0761d99cE80B#code), [Base strategy](https://basescan.org/address/0x049e8aab2D3CA187e47D74Cf8171Ad266f18643E#code), [Ethereum strategy](https://etherscan.io/address/0x59aEF8fEED17B8220778Aaed37c4b7218a6f6978#code).

### 6.2 Liquidity, withdrawal timing, and pauses

Zircuit publishes **14 to 21 days** for vault withdrawals, **T+14** for Monarq and **T+1** for WisdomTree. The public materials thus distinguish institutional liquidity horizons. A Base-local withdrawal does not require moving the user's proceeds to Ethereum. Where the standard Base-to-Ethereum withdrawal route is used, Base documents an additional seven-day challenge period. That delay belongs to the route; it does not apply to every bridge or to every Base-local exit. These are published operating periods, subject to liquidity, processing, and network conditions. [Zircuit overview](https://docs.zircuit.com/zircuit-finance/overview), [Base withdrawal mechanics](https://docs.base.org/specifications/base-protocol/bridging/withdrawals), [withdrawal terms](https://static.zircuit.com/docs/zf-tos.pdf).

The Monarq contract's `withdrawalMaxTime` was **30 days**. The source uses that value to emit a deadline when an institutional withdrawal is signalled. It contains no automatic penalty, collateral seizure, or permissionless repayment mechanism at expiry. The event parameter and the published customer-facing periods serve different purposes; neither should be read as proof of a universally enforceable maximum exit time. [Monarq contract](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code).

At the snapshot, the Base Morpho strategy's `maxWithdraw` for the StrategyManager was approximately **55,240.88 USDC**. The Base underlying-token contract held **201.19 USDC**, and the Monarq lender's immediately withdrawable amount was less than one cent. These identified Base-local sources totalled approximately **55,442.07 USDC**, or **4.09%** of vault accounting assets. This is a snapshot of identified capacity, subject to permissions and execution, not a committed buffer policy or a service promise. Ethereum Morpho assets are excluded from that local total because moving their proceeds to Base introduces additional processing. [Base Morpho](https://basescan.org/address/0x049e8aab2D3CA187e47D74Cf8171Ad266f18643E#code), [underlying-token contract](https://basescan.org/address/0xd7aBC360dfcF1B6dD0a03138235e12A2bc1c1C8B#code), [Monarq lender](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code).

Requests larger than accessible liquidity require institutional repayment or other available funding. A large holder's exit can therefore lengthen the queue even without a credit loss. Only the withdrawal-manager role can process requests. A requester can cancel an unprocessed request while the factory is unpaused, but a factory pause also blocks cancellation. This supports incident containment while temporarily restricting holder access. [Withdrawal implementation](https://basescan.org/address/0xFea5cE0499C255B41D531520B64657C7f8b3b65c#code).

### 6.3 Valuation and loss recognition

Institutional valuation uses a proposal and acceptance process. The Monarq valuation proposer was `0x10A0DF6A863797eD061c8eB4007FFb115067c311`; its keeper was `0x38591f549c9E5Aa998d53ca77730759d8F20cc80`. WisdomTree used that operating address as proposer and `0x15872178C53951197f0AD2Ce5CAEd8cCdCe20d0A` as keeper. Different addresses separate execution steps, but do not by themselves establish independent organizations or independent valuation assurance. [Monarq](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code), [WisdomTree](https://basescan.org/address/0x7C19aADD063487676b9Dc58968Ed0761d99cE80B#code).

Both institutional strategies had health checks enabled with a zero-loss limit. A report that would recognize a loss therefore requires management to adjust or temporarily disable the check. This can prevent an erroneous write-down. A genuine loss also needs deliberate intervention before it enters strategy accounting. Vault reporting is a further step, so the displayed share value can lag recoverable value. [InstitutionLender and BaseHealthCheck source](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code), [vault reporting](https://basescan.org/address/0x2F17b8f1Cf58dD02CB09905efabF3eb6d5fa6e68#code).

Withdrawal ordering matters during that interval. Zenith's public report identifies an acknowledged finding, L-7, under which a withdrawal processed before a loss report exits at the earlier price, leaving more of the loss with remaining holders. The current implementation still separates accounting reports from permissioned withdrawal processing. This is a conditional mechanism, not evidence that losses have been shifted in practice. [Zenith report, section L-7](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/security), [accounting implementation](https://basescan.org/address/0xbFaebf5eAEAaC737E6D274D70e5C6AFA76410302#code), [withdrawal implementation](https://basescan.org/address/0xFea5cE0499C255B41D531520B64657C7f8b3b65c#code).

### 6.4 Holder claim and service continuity

Pantheon ZK Labs' Terms of Service describe vault shares as a programmatic claim against the vault contracts, rather than a claim against a particular entity. Sections 5(a) and 5(b) make the holder's outcome dependent on strategy results and available withdrawal liquidity. The terms do not, on their own, establish that zvUSDC holders are direct secured creditors of an institutional borrower. No priority or recovery percentage is assumed here. [Terms of Service](https://static.zircuit.com/docs/zf-tos.pdf).

The terms permit strategy changes without advance notice and state a **US$100 cap on the Company's total contractual liability**, to the extent permitted by applicable law. That provision concerns liability of the Company; it is not a US$100 limit on assets redeemable from the vault. The terms provide for Panama law and individual arbitration, with applicable-law qualifications. Institutional default or interrupted processing can complicate a wind-down. The public sources do not establish the full legal route by which borrower recoveries reach holders. [Terms, sections 2, 5, 15–17](https://static.zircuit.com/docs/zf-tos.pdf).

### 6.5 Governance and operational control

The core Safe at `0xC0a7c631f50ABaaAb9942839720803E16A24172d` required three approvals from five owners. No enabled Safe modules were returned, and its guard slot was zero at the snapshot. The Safe held the StrategyManager's strategy-admission and upgrade roles. The reviewed upgrade authorization has no mandatory on-chain waiting period. This allows prompt changes while placing trust in the approving signers; their custody practices and organizational independence are not established by the threshold alone. [Safe](https://basescan.org/address/0xC0a7c631f50ABaaAb9942839720803E16A24172d#readProxyContract), [StrategyManager](https://basescan.org/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code), [upgrade authorization](https://basescan.org/address/0x2F17b8f1Cf58dD02CB09905efabF3eb6d5fa6e68#code).

The operating address `0x38591f549c9E5Aa998d53ca77730759d8F20cc80` held allocation, reporting, and bridge-operation roles in the StrategyManager and the withdrawal-manager role in the VaultComposer. It did not hold the StrategyManager's strategy-admission or upgrade role. Its compromise is consequently bounded by those permissions; its availability still matters to several routine functions. The institutional management authority can change designated institutional receivers, making that authority relevant to custody as well as administration. [StrategyManager](https://basescan.org/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code), [VaultComposer](https://basescan.org/address/0xBb801ED781dF31F660cC743bEf7Bb9D04B030923#code), [institutional management setters](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code).

Strategy allowlisting limits the operating address to approved destinations. It does not fix portfolio weights permanently. A new approved strategy or a material rebalance can change credit and liquidity exposure, so this assessment applies to the stated snapshot rather than every future use of the architecture. [StrategyManager source](https://basescan.org/address/0x2F17b8f1Cf58dD02CB09905efabF3eb6d5fa6e68#code).

### 6.6 Smart contracts, audits, and cover

Zircuit's public security page makes five reports available:

| Reviewer and report                                             | Review period         | Public report result relevant to this assessment                             |
| --------------------------------------------------------------- | --------------------- | ---------------------------------------------------------------------------- |
| Quantstamp, Bridges & Vaults                                    | October 2025          | Findings table marks all ten findings fixed                                  |
| Quantstamp, Bridges & Vaults #2                                 | November 2025         | Both findings marked fixed                                                   |
| Quantstamp, Strategies                                          | November 2025         | All three findings marked fixed                                              |
| Zenith, smart-contract assessment                               | October–November 2025 | High and medium findings resolved; some lower-severity findings acknowledged |
| Quantstamp, Circle Cross-Chain Transfer Protocol (CCTP) adapter | April 2026            | Three informational findings fixed and one acknowledged                      |

These are substantive public review records. Their scope is the identified code and commits, rather than every later deployment. The five Base core proxy implementations matched the addresses listed in appendix A at the snapshot. The reports reviewed do not provide a complete, explicit mapping of all those deployed implementations to audited commits. The April report reviews the CCTP adapter and cannot alone establish full-system coverage. [Public reports](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/security), [deployed contracts](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/zircuit-finance-addresses).

Audit-source relationships should also be understood accurately. Zircuit's own account describes its founders' Quantstamp background, and Quantstamp authored four of the five listed reports, including the adapter review. Zenith supplies a separate review. The historical connection does not invalidate an audit or establish a defect; report scope and the evidence for each finding remain the basis for assessment. [Zircuit's account](https://www.zircuit.com/en/blog/built-to-thrive), [reports](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/security).

No recovery value is assigned to smart-contract cover. The sources reviewed do not establish a complete current policy identifying the holder beneficiary, covered deployments, limit, exclusions, and term. Any eventual payment would depend on the actual policy and claim, so it is excluded from the stress calculations.

### 6.7 Networks, cross-chain dependencies, and USDC

Base hosts the reviewed canonical vault, with strategy activity also present on Ethereum. Bridge transfers and cross-chain accounting depend on the relevant contracts, messages, and processing. A Base-local user can avoid a user-level Ethereum withdrawal, but that does not remove the vault's Ethereum strategy exposure. A failed bridge or report can produce delayed liquidity or stale accounting; a loss of bridged assets can have a financial effect. [Architecture](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults), [addresses](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/zircuit-finance-addresses), [Ethereum strategy accounting](https://etherscan.io/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code).

Base unavailability can interrupt transfers and processing independently of institutional solvency. USDC is a shared asset dependency across the reviewed allocations. Circle's public terms reserve blocking and freezing powers and place conditions on direct redemption. A USDC depeg or a freeze of relevant assets can affect multiple strategies together; manager diversification does not remove that exposure. [Base withdrawal dependencies](https://docs.base.org/specifications/base-protocol/bridging/withdrawals), [Circle terms](https://www.circle.com/legal/usdc-terms).

### 6.8 Performance fees

The AccountingReceiver's performance-fee setting was **2,000 basis points, or 20%**, at the snapshot, matching the published fee. Its current code charges on positive report deltas and does not maintain a portfolio high-water mark. A positive report during recovery from an earlier loss can therefore incur a fee before holders return to their previous share value. This is a fee-accounting consequence, separate from the cause of the original loss. The current implementation caps the setting at 20%; an upgrade could change the implementation. [AccountingReceiver](https://basescan.org/address/0x7fCeB53b2959861D29057361158a2B41cAAffD68#code), [fee logic](https://basescan.org/address/0xbFaebf5eAEAaC737E6D274D70e5C6AFA76410302#code), [published fee](https://docs.zircuit.com/zircuit-finance/overview).

## 7. Stress scenarios

### Monarq impairment

These scenarios apply a haircut to the **1,143,772.926827 USDC** Monarq allocation and divide the loss by **1,354,524.928746 USDC** of vault accounting assets. All other positions are held constant. No recovery, external support, fee effect, or change in withdrawal order is assumed.

| Impairment of the Monarq allocation | Vault loss, USDC | Vault loss as a percentage |
| ----------------------------------- | ---------------: | -------------------------: |
| 5%                                  |        57,188.65 |                      4.22% |
| 10%                                 |       114,377.29 |                      8.44% |
| 25%                                 |       285,943.23 |                     21.11% |
| 50%                                 |       571,886.46 |                     42.22% |
| 100%                                |     1,143,772.93 |                     84.44% |

The calculation is sensitivity analysis, not an estimate of default likelihood. It shows how concentration transmits an impairment to the vault. Recoveries would reduce ultimate losses; correlated losses in other positions could increase them. Inputs come from the snapshot in section 3.

### Withdrawal demand without a credit loss

Using the identified **55,442.07 USDC Base-local capacity** from section 6.2, with no new deposits or capital movements:

| Request size       | Request value, USDC | Amount beyond identified Base-local capacity, USDC |
| ------------------ | ------------------: | -------------------------------------------------: |
| 5% of vault assets |           67,726.25 |                                          12,284.17 |
| 10%                |          135,452.49 |                                          80,010.42 |
| 25%                |          338,631.23 |                                         283,189.16 |
| 50%                |          677,262.46 |                                         621,820.39 |

The final column is a funding requirement, not a loss. The Ethereum Morpho position and institutional repayments may supply funds, subject to availability and processing. The table does not predict completion time or assume that all residual accounting value is spendable cash.

### Combined operational stress

| Scenario                                       | Consequence derived from the reviewed mechanism                                                                  |
| ---------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
| Institutional impairment before a vault report | Share accounting can remain above recoverable value until the accepted loss reaches the vault                    |
| Withdrawals processed during that gap          | Loss allocation can differ between exiting and remaining holders                                                 |
| Operating-account outage                       | Reporting, reallocation, or queue processing may wait for restored operation or role replacement                 |
| Adverse administrative change                  | Upgrades or changed permissions can alter the contract protections described in this report                      |
| Bridge or destination-chain interruption       | Cross-chain proceeds or accounting may be delayed even when a local transaction succeeds                         |
| USDC depeg or freeze                           | Multiple strategy allocations can be affected by the same asset-level event                                      |
| Orderly wind-down                              | Liquid positions can be realized and institutions recalled through normal processing, subject to available funds |
| Wind-down during borrower distress             | Timing and proceeds depend on off-chain repayment, loss recognition, and legal recovery                          |

These scenarios follow sections 6.2–6.7. They should not be added to the impairment table as independent losses.

## 8. Monitoring and reassessment

These are suggested review signals, not a claim that Tapir or Zircuit operates a particular monitoring service.

| Cadence                      | Public signal                                                                  | Reason to reassess                                                                                 |
| ---------------------------- | ------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------- |
| Event-driven                 | Proxy upgrades, role grants, Safe ownership or threshold, pauses               | Authority or behavior differs from the reviewed configuration                                      |
| Daily and during incidents   | Institutional proposals, accepted values, strategy reports, vault share value  | A negative delta, missing update relative to the established cadence, or an unexplained divergence |
| Daily and during withdrawals | Queue entries, outstanding shares, request age, available strategy withdrawals | Requests exceed accessible liquidity or outlast the applicable published operating period          |
| Daily                        | Monarq weight, both Morpho weights, WisdomTree weight, Base-local USDC         | Concentration or accessible liquidity changes materially                                           |
| Event-driven                 | Institutional receiver changes and actual USDC repayments                      | An unfamiliar destination or a pending recall without the expected return                          |
| Event-driven                 | USDC notices, network status, bridge incidents                                 | A restriction, depeg, or interrupted route affects the vault                                       |
| On new publication           | Audit reports, legal filings, product terms, coverage documents                | New evidence changes an exposure, control, or recovery assumption                                  |

## 9. Limitations and disclosures

Public on-chain accounting does not establish off-chain custody balances or independently audited fund value. This review did not establish the complete executed institutional loan terms, creditor ranking, current fund leverage and venue exposures, or a complete current cover policy. It did not reconstruct every historical withdrawal's end-to-end settlement time or perform a separate assessment of every collateral market underlying the Morpho positions. The small residual accounting amount in section 3 was not fully attributed. Those limits remain part of the assessment, without implying that missing public information is evidence of wrongdoing or loss.

This report is general research, not investment, financial, legal, tax, or accounting advice, and does not take account of a reader's circumstances. It is not an offer or recommendation to buy, sell, hold, or use an asset. Digital assets and decentralized finance (DeFi) can involve partial or total loss and restricted access. Observed yield and completed repayments do not predict future outcomes. Findings are bounded by the stated snapshots and sources; no continuing update service is promised. The publisher's relationship and Zircuit's factual-review participation are disclosed at the beginning.

## Appendix A. Contract identity and reproducibility

The five Base proxy implementations below were read from the Ethereum Improvement Proposal 1967 (EIP-1967) implementation slot at block 50,990,192.

| Component          | Base proxy                                   | Implementation at the snapshot               |
| ------------------ | -------------------------------------------- | -------------------------------------------- |
| Vault              | `0x03067bbD0d41E3Fe4A0bb6ca67c99e7352Da4CAE` | `0xfEFA9a81A0c662385172A249b321974199994A69` |
| StrategyManager    | `0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374` | `0x2F17b8f1Cf58dD02CB09905efabF3eb6d5fa6E68` |
| AccountingReceiver | `0x7fCeB53b2959861D29057361158a2B41cAAffD68` | `0xbFaebf5eAEAaC737E6D274D70e5C6AFA76410302` |
| UnderlyingOFT      | `0xd7aBC360dfcF1B6dD0a03138235e12A2bc1c1C8B` | `0xB2E30c33075510274ffbec2811Da66d102152bc7` |
| VaultComposer      | `0xBb801ED781dF31F660cC743bEf7Bb9D04B030923` | `0xFea5cE0499C255B41D531520B64657C7f8b3b65c` |

For allocation, read `totalAssets()` and `totalSupply()` from the Base vault, then `getStrategies()` and `getUnderlyingByStrategy(address)` from the StrategyManager on each chain at the specified blocks. USDC-denominated quantities and zvUSDC supply use six decimal places. Sum the funded strategies and subtract from vault accounting assets to reproduce the residual.

For queue status, read `getWithdrawalQueueLength()` and every `getWithdrawalQueueEntry(index)` from index 0 through 71 on the Base VaultComposer. Count `fulfilled`, `canceled`, and entries with neither flag. Institutional repayment evidence is the actual USDC transfer and `RepaymentReceived` event in the cited transaction, not an unrelated token transfer sharing a similar label.

For the performance fee, the verified AccountingReceiver layout puts `performanceFeeBps` three slots after storage location `0x0a59346b4263bf167da6b54c661b0c1738408553996dca1ef40c4dab71da0a00`. The snapshot value is 2,000. Source verification and deployment identity make these checks reproducible; they are not substitutes for a security audit.

## Public sources

* [Zircuit Finance product overview](https://docs.zircuit.com/zircuit-finance/overview): published strategy descriptions, withdrawal periods, and fees.
* [Vault architecture](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults) and [official address registry](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/zircuit-finance-addresses).
* [Base snapshot block](https://basescan.org/block/50990192) and [Ethereum snapshot block](https://etherscan.io/block/25924286).
* [Base vault](https://basescan.org/address/0x03067bbD0d41E3Fe4A0bb6ca67c99e7352Da4CAE#code), [Base StrategyManager](https://basescan.org/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code), and [Ethereum StrategyManager](https://etherscan.io/address/0xf7E745658fa6f1fe8f2CAb47861a273991Cd3374#code).
* [Monarq lender](https://basescan.org/address/0xe83ef4375d806c02387069f1b753b2ab76ab1dc5#code) and [WisdomTree lender](https://basescan.org/address/0x7C19aADD063487676b9Dc58968Ed0761d99cE80B#code).
* [Base Morpho strategy](https://basescan.org/address/0x049e8aab2D3CA187e47D74Cf8171Ad266f18643E#code) and [Ethereum Morpho strategy](https://etherscan.io/address/0x59aEF8fEED17B8220778Aaed37c4b7218a6f6978#code).
* [Base underlying-token contract](https://basescan.org/address/0xd7aBC360dfcF1B6dD0a03138235e12A2bc1c1C8B#code), [VaultComposer queue](https://basescan.org/address/0xBb801ED781dF31F660cC743bEf7Bb9D04B030923#code), and [administrative Safe](https://basescan.org/address/0xC0a7c631f50ABaaAb9942839720803E16A24172d#readProxyContract).
* [Current StrategyManager implementation](https://basescan.org/address/0x2F17b8f1Cf58dD02CB09905efabF3eb6d5fa6e68#code), [VaultComposer implementation](https://basescan.org/address/0xFea5cE0499C255B41D531520B64657C7f8b3b65c#code), and [AccountingReceiver implementation](https://basescan.org/address/0xbFaebf5eAEAaC737E6D274D70e5C6AFA76410302#code).
* [AccountingReceiver proxy and state](https://basescan.org/address/0x7fCeB53b2959861D29057361158a2B41cAAffD68#code).
* [Institutional repayment transaction, 2026-06-19](https://basescan.org/tx/0xb803f439f130f9483d741ccce877381c6af995949322fef3477dd56ccfbc993f).
* [Zircuit APY endpoint](https://finance.zircuit.com/api/apy) and [DefiLlama historical vault series](https://yields.llama.fi/chart/437a4c66-b5a7-416b-853a-565433679627).
* [Zircuit public security reports](https://docs.zircuit.com/zircuit-finance/zircuit-finance-vaults/security): links to all five reports summarized above.
* [Zircuit's published account of its founders](https://www.zircuit.com/en/blog/built-to-thrive).
* [FalconX announcement concerning Monarq](https://www.falconx.io/newsroom/monarq-asset-management-announces-strategic-investment-from-falconx) and [SEC ownership filing](https://www.sec.gov/Archives/edgar/data/1737995/000119312526051654/xslSCHEDULE_13D_X01/primary_doc.xml).
* [BlockFills court filing, docket 417, June 10, 2026](https://www.veritaglobal.net/blockfills/document/2610371260610000000000005): exhibit U creditor-matrix service list.
* [Zircuit Terms of Service, April 15, 2026](https://static.zircuit.com/docs/zf-tos.pdf).
* [Base withdrawal documentation](https://docs.base.org/specifications/base-protocol/bridging/withdrawals) and [Circle USDC terms](https://www.circle.com/legal/usdc-terms).
