TL;DR
Ethereal is a USDe-native perpetuals DEX built as an EVM appchain: an offchain application-specific sequencer matches orders for CEX-like speed, and trades settle onchain via Arbitrum One with Celestia for data availability. It is non-custodial in the sense that matters day to day (you sign from your own wallet, funds sit in onchain contracts, settlement is onchain), and unlike the earlier read of this venue, the safety rails are now largely verifiable from primary sources. Ethereal's own contracts were audited: ChainSecurity assessed the exchange smart contracts (report dated June 11, 2025) and Guardian Audits reviewed the Exchange and Season Zero, both listed on Ethereal's docs audit page. The ChainSecurity result was clean on severity: zero critical, zero high, one medium (risk-accepted), seven low. So the deal-breaker is not "we cannot see the audit." It is what the audit plainly documents: the exchange admin is fully trusted and can upgrade the contracts through a proxy, and a single offchain sequencer is fully trusted and, in the auditor's own words, its accounts are "theoretically able to steal funds" because their keys run on live machines. This is where the 2TOP $10k HYPE short lives. The design is centralized-by-trust by construction, and getting out is a deposit-and-bridge flow with an onchain withdraw lockout and a LayerZero hop. That is enough to hold the verdict at caution on an owned position.
Checklist
Audits and contracts. Confirmed, correcting the prior read. Ethereal's docs list a dedicated audits page naming ChainSecurity (Exchange smart contracts, report dated June 11, 2025, hosted on ChainSecurity's own domain) and Guardian Audits (Exchange and Season Zero). ChainSecurity found 0 critical, 0 high, 1 medium (risk-accepted), and 7 low (4 corrected, 3 risk-accepted). Real audits, clean severity. The caveat is not coverage; it is that the same report documents a centralized trust model (below).
Admin control. Confirmed from the ChainSecurity trust model. The Exchange Owner/Admin can update system parameters, register and remove tokens and sequencers, and upgrade contract implementations via an ERC1967 proxy, and is "fully trusted." The report does not evidence a timelock or a named multisig, so admin key custody and rate-of-change are the residual unknown. Separately, a single offchain sequencer is "fully trusted," has exclusive access to the settlement entry point, and per the auditor its accounts are "theoretically able to steal funds" since their private keys run on live machines. Emergency pausers (set by the owner) can halt deposits. This is documented centralization on the fund path, not an unverified gap.
Oracle. Single provider, confirmed by docs and audit. Pyth Lazer feeds mark price into an offchain matching engine; those marks drive liquidations and funding and are verified onchain at settlement. The auditor flags the oracle as a "critical dependency for system solvency" and "fully trusted." One source is a concentration.
Liquidity and exit. Exit is not a same-chain unilateral redeem. Withdrawals carry an onchain withdrawLockout delay before they can be finalized, then route out over LayerZero with processing time that varies by destination chain. TVL is thin at about $23M; note pre-launch pre-deposits exceeded $1B, so current TVL reflects post-launch decay, not depth.
Yield: real vs emission. Our economics here are funding captured on the delta-neutral short (real) plus USDe balance rewards and a points program (incentive, and points are not yet a token). Treat the points as speculative until an airdrop lands.
Holder concentration. No live Ethereal token yet; rewards are wired to Ethena and ENA. Not applicable today. Re-check at token launch.
Track record. Mainnet Alpha, live since October 20, 2025. No Ethereal hack appears in 2026 DefiLlama or news hack scans, which is reassuring but is roughly eight months of history on a still-alpha venue.
Worst case
A compromise or misuse of the single sequencer keys, or a malicious or compromised admin upgrade to the settlement contracts, drains or freezes deposited USDe. This is not hypothetical hand-waving: the ChainSecurity report states the sequencer accounts are theoretically able to steal funds because the contracts omit some checks for gas reasons and the keys live on hot machines, and that the proxy admin can upgrade contract logic. A softer and more likely case: during stress the sequencer censors or delays, or the withdraw lockout plus LayerZero leg slows your exit, so you cannot unwind the hedge exactly when you want to. Mitigation is position sizing and not treating deposited margin as instantly retrievable.
Bottom line
Caution. The audits are real and clean on severity, and the record is clean so far, which is better than the venue's youth would suggest. But on an owned position the gate is the trust model the audit itself lays out: a fully trusted, upgradeable admin proxy and a single fully trusted offchain sequencer whose keys could, per the auditor, move user funds. That is centralization by design, not an average of green and red. Keep the HYPE short sized so an Ethereal-side freeze, censorship, or loss is survivable, and lift the verdict only if the admin setup hardens (timelock plus a disclosed multisig) and the sequencer decentralizes or gains an enforced escape hatch.
Data appendix
- TVL: ~$23M (DefiLlama API, slug
ethereal-dex, $22.97M). Pre-launch pre-deposits reportedly exceeded $1B; current TVL is post-launch. Daily volume: refresh (the ~$1.5B figure could not be confirmed; DefiLlama DEX/perps summary endpoints do not track this venue and one ranking puts it ~#37 by 30d perp volume). 90d / ATH: refresh. - Custody / settlement: Non-custodial by design (user-signed, funds in onchain contracts); offchain application-specific sequencer matches orders, settlement onchain via Arbitrum One, Celestia DA; USDe is collateral and unit of account (Ethereal docs, corroborated by the ChainSecurity audit).
- Deposit / withdraw: Multi-chain deposit swaps assets to USDe and bridges in; withdrawals carry an onchain
withdrawLockoutdelay then route out via LayerZero, processing time varies by chain (Ethereal docs; lockout per ChainSecurity report). - Audits: ChainSecurity, Exchange smart contracts, report dated 2025-06-11 (0 critical / 0 high / 1 medium risk-accepted / 7 low, 4 corrected). Guardian Audits, Exchange and Season Zero. Both listed on the Ethereal docs audit page.
- Admin / governance: Exchange Owner/Admin is fully trusted: updates parameters, registers/removes tokens and sequencers, upgrades contracts via ERC1967 proxy. No timelock or named multisig evidenced. Single offchain sequencer is fully trusted; per the auditor its accounts are theoretically able to steal funds (keys on live machines). Emergency pausers can halt deposits. Ecosystem and rewards tied to Ethena / ENA. Admin key custody (multisig/timelock): refresh.
- Oracle: Pyth Lazer, single provider, fully trusted, critical solvency dependency (Ethereal docs + ChainSecurity).
- Insurance: Insurance fund plus liquidator subaccount and a first-bankruptcy-price cap to prevent socialized losses (Ethereal docs). Fund size: refresh.
- Holder concentration: No live token; airdrop pending, tied to Ethena / ENA. refresh at token launch.
- Recent news / incidents: No Ethereal hack found in 2026 DefiLlama hacks or news scan; Mainnet Alpha since 2025-10-20. Maintained monthly. Methodology: DeFi Research Instruction v2.