This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

    • Learn more about this provideropens in a new window
      CookieConsentStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • Learn more about this provideropens in a new window
      bcookieUsed in order to detect spam and improve the website's security.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      li_gcStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 180 daysType: HTTP Cookie
    • Learn more about this provideropens in a new window
      datadomeUsed in context with the website's BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • _pk_testcookie_domainThis cookie determines whether the browser accepts cookies.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • __cf_bm [x3]This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • Learn more about this provideropens in a new window
      lidcRegisters which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • Learn more about this provideropens in a new window
      guestRegisters data on visitors' website-behaviour. This is used for internal analysis and website optimization.
      Maximum Storage Duration: 1 monthType: HTTP Cookie
    • Learn more about this provideropens in a new window
      personalization_idThis cookie is set by Twitter - The cookie allows the visitor to share content from the website onto their Twitter profile.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
    • _pk_uidUsed by Piwik Analytics Platform to identify the visitor on repeat visits to the website.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      _pk_id#Collects statistics on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      _pk_ses#Used by Piwik Analytics Platform to track page requests from the visitor during the session.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • FPGSIDRegisters statistical data on users' behaviour on the website. Used for internal analytics by the website operator.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      FPIDRegisters statistical data on users' behaviour on the website. Used for internal analytics by the website operator.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      FPLCRegisters a unique ID that is used to generate statistical data on how the visitor uses the website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • _gaRegisters a unique ID that is used to generate statistical data on how the visitor uses the website.
      Maximum Storage Duration: 2 yearsType: HTTP Cookie
      _ga_#Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.
      Maximum Storage Duration: 2 yearsType: HTTP Cookie
  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • Learn more about this provideropens in a new window

      Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness. The provider may use the IP Addresses for ads measurement and ads personalization.

      ads/ga-audiencesUsed by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor's online behaviour across websites.
      Maximum Storage Duration: SessionType: Pixel Tracker
    • Learn more about this provideropens in a new window
      userRefererDetermines how the user accessed the website. This information is used by the website operator in order to measure the efficiency of their marketing.
      Maximum Storage Duration: 1 monthType: HTTP Cookie
    • Learn more about this provideropens in a new window
      #:session-dataTracks the individual sessions on the website, allowing the website to compile statistical data from multiple visits. This data can also be used to create leads for marketing purposes.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      eng_mtTracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      t_gidThis cookie assigns a specific visitor ID, when the visitor interacts with ads or content from the website - this allows the website to target the visitor with similar ads or content.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      t_pt_gidCollects information on user preferences and/or interaction with web-campaign content - This is used on CRM-campaign-platform used by website owners for promoting events or products.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      taboola global:user-idSets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      taboola_session_idThis cookie is used to collect information on a visitor. This information will become an ID string with information on a specific visitor – ID information strings can be used to target groups with similar preferences, or can be used by third-party domains or ad-exchanges.
      Maximum Storage Duration: SessionType: HTTP Cookie
    • Learn more about this provideropens in a new window
      1/i/adsct [x2]Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
      Maximum Storage Duration: SessionType: Pixel Tracker
      muc_adsCollects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      guest_idCollects data related to the user's visits to the website, such as the number of visits, average time spent on the website and which pages have been loaded, with the purpose of personalising and improving the Twitter service.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      guest_id_adsCollects information on user behaviour on multiple websites. This information is used in order to optimize the relevance of advertisement on the website.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      guest_id_marketingCollects information on user behaviour on multiple websites. This information is used in order to optimize the relevance of advertisement on the website.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
    • _gcl_auUsed by Google AdSense for experimenting with advertisement efficiency across websites using their services.
      Maximum Storage Duration: 3 monthsType: HTTP Cookie
      _gcl_lsTracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.
      Maximum Storage Duration: PersistentType: HTML Local Storage
    • pardot [x2]Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.
      Maximum Storage Duration: SessionType: HTTP Cookie
  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • cs_analytics_ip_blockedPending
      Maximum Storage Duration: SessionType: HTTP Cookie
      user_tokenPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • _twpidPending
      Maximum Storage Duration: SessionType: HTTP Cookie
Cookie declaration last updated on 8/20/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
Image The xUSD collapse: leverage eating itself

The xUSD collapse: leverage eating itself

Timer4 min read

  • Finance

Stream Finance just gave us a $280 million lesson in why DeFi still hasn't learned from its own mistakes. A $93 million loss by an external fund manager turned into a full-blown systemic crisis, and if you're surprised, you haven't been paying attention.

What actually happened

The facts are straightforward. Stream Finance ran what it called "market neutral strategies" promising 18% yields on $382 million in assets. An external fund manager lost $93 million over the weekend. By Monday morning, xUSD,  their stablecoin that was supposed to hold $1, was trading at $0.26. Withdrawals froze. $160 million in user funds locked. Another DeFi implosion.

But the $93 million hole wasn't the real problem. The real problem was what Stream had built around it.

The loop

Stream's core strategy was recursive leverage, which they dressed up as "yield arbitrage." Here's how it worked: deposit xUSD as collateral, borrow stablecoins like USDT0, use those stablecoins to mint more xUSD, deposit that xUSD as collateral, borrow more, repeat. One dollar could become several dollars of xUSD through enough loops.

Days before the collapse, on-chain analyst under the pseudonym Cbb0fe flagged that Stream's supporting assets totaled around $170 million while borrowing hit $530 million. That's over 4x leverage through their looping strategy. Stream became the largest holder of its own token, not because of organic demand, but because they'd engineered a circular dependency where the collateral backing the asset was the asset itself.

This is the kind of structure that looks genius in a bull market and catastrophic the moment anything breaks. And something broke.

The leverage loop was bad enough. The oracle design made it exponentially worse.

On Euler markets running on Plasma, $107 million of xUSD sat as collateral with the oracle hardcoded at $1.27. Not reflecting market prices. Not responding to reality. Just a number in the code that said "this is worth $1.27" while the market was screaming that it wasn't.

When xUSD started depegging, positions couldn't liquidate. The oracle refused to acknowledge what was happening. Lenders have been stuck with bad debt because the system was designed to ignore price discovery. Meanwhile, borrowers faced 75% APY that only deepens the hole, and liquidations sat frozen waiting for bankruptcy proceedings to resolve what functioning risk systems should have handled automatically.

This might end up being the largest single loss for DeFi lenders from a non-exploit event. And it was entirely by design. Someone chose to hardcode those oracles. Someone decided that pretending volatility doesn't exist was safer than dealing with it. That person was wrong, and now thousands of users are paying for it.

There's a detail here that matters: Stream's "missing transparency report." When you're managing $382 million and promising 18% yields, your users aren't customers but creditors taking your counterparty risk. They deserve to know what backs their deposits.

The uncomfortable question: did Stream's team actually understand their own risk? When you're running recursive loops across multiple chains with bespoke agreements and external managers, can you even map your dependencies? Or had the structure become too complex for anyone to fully comprehend? 

DeFi is excessively,, and paradoxically, concentrated and thus, systemic. One protocol's excessive leverage becomes everyone's problem. Borrow rates spike. Liquidations trigger elsewhere. Liquidity evaporates. Each unwind forces another. The timing didn't help: coming right after the $100 million Balancer exploit and broader market weakness, confidence was already fragile.

Patterns we keep ignoring

This script is familiar: Terra/Luna, Celsius, Three Arrows Capital. Unsustainable yields, recursive leverage, opacity about risk, catastrophic unwind. We've seen this movie before, and yet here we are again, watching the same plot unfold with different characters.

DeFi has sophisticated primitives but immature risk management. We can build complex financial instruments on-chain, but we haven't built the culture of prudence that prevents disasters like this.

This isn’t bad luck. This is a disaster engineered through negligence and growth-at-all-costs mentality.

Every bull market follows this pattern: leverage builds, yields compress, someone reaches for more risk, something breaks, contagion spreads, deleveraging cascades. We shouldn't be surprised. The question is whether we'll learn from it.

Based on history, it’s fair to show scepticism. But there are reasons for cautious optimism. The pain from events like this changes behavior, slowly but surely. More importantly, the arrival of mature institutional players with actual risk frameworks and regulatory oversight should eventually force these practices out. Traditional finance learned these lessons through centuries of crises. DeFi is compressing that education into years, and institutional capital won't tolerate the kind of opacity and reckless leverage that just imploded Stream.

The cowboys running recursive loops with hardcoded oracles will either adapt or get crowded out. Not because they suddenly develop prudence, but because capital flows toward sustainable risk-adjusted returns, not 18% yields backed by circular dependencies. That process takes time, and we'll see more failures along the way. But each xUSD makes it harder for the next one to raise funds.

The question is whether retail gets wiped out first, or whether the industry matures fast enough to protect them. Right now, it's a race.

Published onNov 7th, 2025

Writer
Former journalist for Le Monde, Le Figaro, and Capital's Cryptocurrency section. Bitcoin node runner.

Welcome to CoinShares

Personal Data

0102

When you visit CoinShares website, cookies enhance your experience. They help us to show you more relevant content. Some cookies are necessary for the site to work and will always be active. Blocking some types of cookies may impact your experience of the website and the services which we offer on our website.

We use cookies on our site to optimize our services. Learn more about our EU cookie policy or US cookie policy.

  • Necessary
    Question circle icon
  • Preferences
    Question circle icon
  • Statistical
    Question circle icon
  • Marketing
    Question circle icon
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.