The bridged stablecoin of Rand Protocol
One shielded dollar, backed by the USDT and USDC you already hold
Lock USDT or USDC on Ethereum, BNB Smart Chain, Tron or Solana and receive the same amount as zUSD on Rand: digital dollars only the sender and the recipient can see. Redeem to any of the four chains, one-to-one.
| Locked on | Coin | Amount |
|---|---|---|
| Ethereum | USDT | — |
| Ethereum | USDC | — |
| BNB Smart Chain | USDT | — |
| BNB Smart Chain | USDC | — |
| Tron | USDT | — |
| Solana | USDT | — |
| Solana | USDC | — |
| Total locked | — | |
| zUSD in circulation | — | |
Reading the bridge from the explorer… Open the explorer →
- Redemption
- 1 : 1
- one zUSD releases one USDT or USDC, less fees
- Backings
- 7
- USDT and USDC on three chains, USDT on Tron
- Source chains
- 4
- ETH · BSC · TRON · SOL
- New issuers
- 0
- every dollar is Tether's or Circle's, held in custody
What is zUSD?
zUSD is the dollar of Rand Protocol, a payments network built for businesses that need confidentiality without giving up verifiability. Rand keeps no accounts and no balances on its ledger, and it issues no currency of its own. zUSD fills that gap by importing the dollars firms already hold: every unit is minted when USDT or USDC is locked on its home chain, and retired when that collateral is released. Every zUSD in circulation corresponds to coin held in custody, and no new issuer stands between a company and its money.
Public blockchains disclose every balance and every transaction to anyone who looks. For most firms that is a disqualifying feature: payroll, supplier pricing and treasury activity are competitively sensitive, and no board would publish them. zUSD resolves this tension. A payment settles as a note in a shielded pool; the network verifies a cryptographic proof that the transaction balances and learns nothing else. Disclosure stays under the company's control. The holder keeps a viewing key and can extend it to an auditor or regulator, so confidentiality from the market does not mean opacity to those with a right to see.
The design introduces no new counterparty to underwrite. It does carry one dependency, which we state plainly: an independent guardian group confirms deposits and withdrawals on each chain. The risks below set out what that dependency means for a holder.
Lock, mint, transfer, redeem
Each coin is locked in a custody contract on its home chain and attested by a threshold guardian set. Rand mints zUSD against the aggregate, as a note the chain computes from the attested amount. Exit runs the same path backwards.
- 1 Lock
USDT or USDC is deposited into the custody contract on Ethereum, BNB Smart Chain, Tron or Solana, and immobilized there.
- 2 Mint
Guardians attest the lock, with more than two thirds of the set signing. Anyone may submit the attestation, and Rand appends one zUSD note for the recipient.
- 3 Transfer
zUSD moves inside the shielded pool as notes. The ledger records a proof that each payment balances, and its fee. Not the sender, the recipient or the amount.
- 4 Redeem
A burn spends the notes and names a coin, a chain and an address. Guardians attest the burn and custody releases on that leg, one-to-one.
The total USDT plus USDC locked on Ethereum, BNB Smart Chain, Tron and Solana equals the total zUSD on Rand. Transfers inside the pool conserve value, so only a mint or a burn can change the supply, and each one moves a backing's counter by the same amount.
Seven backings, one asset
The asset is shared; the custody is not. Each row below is a separately held balance behind its own contract, with its own counter on Rand's ledger.
| Chain | Coin | Standard | Custody | Trust assumption |
|---|---|---|---|---|
| Ethereum | USDT | ERC-20 | Lock contract | Program correctness ∧ guardian threshold |
| Ethereum | USDC | ERC-20 | Lock contract | Program correctness ∧ guardian threshold |
| BNB Smart Chain | USDT | BEP-20 | Lock contract | Program correctness ∧ guardian threshold |
| BNB Smart Chain | USDC | BEP-20 | Lock contract | Program correctness ∧ guardian threshold |
| Tron | USDT | TRC-20 | Lock contract | Program correctness ∧ guardian threshold |
| Solana | USDT | SPL | Custody program | Program correctness ∧ guardian threshold |
| Solana | USDC | SPL | Custody program | Program correctness ∧ guardian threshold |
One unit of account
Prices, invoices and contracts on Rand are written in one dollar. Nobody has to ask which dollar, or hold two balances to pay two suppliers.
One anonymity set
Every holder hides among every other holder. Separate per-coin pools would each be smaller, and would label every holder by the coin they came in with.
Any leg out
The entry leg does not bind the exit leg. USDT locked on Tron can leave as USDC on Ethereum, provided that backing holds enough to cover it.
What one pooled dollar costs
Issuing a single zUSD, rather than a separate asset for each source coin, is a deliberate design choice. Pooling delivers one dollar that any counterparty will accept, at the price of four risks a treasurer should understand before holding it. We set them out here rather than leave them to be discovered.
A pooled dollar is only as sound as its weakest reserve asset. Should one backing coin trade below par, a rational actor deposits it and redeems a sound coin at 1:1, and that arbitrage continues until the sound reserve is exhausted. Pooling therefore spreads one issuer's impairment across every zUSD holder, where separate assets would have confined the loss to holders of the impaired coin.
The same mint-and-redeem path doubles as a conversion facility: USDT into USDC, or a balance on one chain into another, for the cost of a proof and a fee. Because the rate is fixed at par, demand concentrates on whichever backing the market values most, and that reserve is drawn down first.
Supply always equals the sum of what is locked, so a holder can always redeem into some backing. What is not guaranteed is the coin and chain of their choice. Rand declines any redemption a specific reserve cannot cover, which means a refusal is reported on Rand at the point of request rather than surfacing later as a release that cannot settle.
A natively issued stablecoin is a direct liability of its issuer. zUSD is a claim on custody held by this protocol, which in turn holds the issuer's coin. Each link is a party whose performance the holder depends on, and this structure adds two: the custody contracts and the guardian set that attests to them.
At launch, the first two risks are bounded by speed rather than size. Pausers, per-transfer and daily caps, and the release fee slow a drain and make conversion less than free, but no standing limit governs how much of zUSD any one backing may represent. We accept that exposure knowingly. zUSD exists to serve the period before Rand issues a dollar natively, and the controls are sized for that period.
What holds the peg in place
Listed, never created
Only the seven listed backings can mint zUSD. Each is admitted by contract address and never on the strength of its name, so a token that merely calls itself USDC cannot acquire a bridged identity. The backing set is a closed list, and changing it is a governance decision rather than a user action.
A counter per backing
The ledger maintains a separate locked balance for each of the seven backings, and zUSD's supply is their sum. Every redemption names the backing it draws on and is checked against that balance alone, so no custody balance can be drawn down on the strength of another. Reconciliation is by backing, not by pool.
Burn before release
Redemption follows a fixed order of operations. The note's nullifier is published first, the guardians then attest the burn, and only then does custody release the coin. The claim is extinguished before the collateral moves, never after, so at no point can the same dollar exist on both sides of the bridge.
Caps and a pause
Each backing is subject to a daily mint cap on Rand, set at 100,000 zUSD on the current testnet. A pause key, held separately from the guardian keys, can halt minting immediately but cannot resume it, which separates the authority to stop from the authority to restart. Redemptions remain open throughout a pause. The source-chain contracts carry their own pauser and rate limits.
Public custody
The source chains are transparent, so every custody balance is publicly visible at all times. Any party can sum the seven and compare the total with zUSD's outstanding supply without opening a single note. Proof of reserves is therefore continuous and independently verifiable rather than periodic and attested.
Post-quantum guardians
Alongside the ordinary guardian signatures, a post-quantum guardian quorum authorizes governance actions such as resuming a paused mint. The bridge's controls are therefore designed to remain sound after today's signature schemes are retired, without a migration under pressure.
Asked often
Is zUSD a new stablecoin?
No. zUSD has no issuer of its own and holds no reserve of bills or bank deposits. Each unit is a claim on one USDT or USDC locked in a custody contract on its home chain. It is a bridged representation of dollars that already exist.
Why not wait for Tether and Circle to issue on Rand directly?
Native issuance is a commercial decision that a third party makes on its own timeline, and it is made against transaction volume a new chain has not yet built. Issuers deploy where settlement already happens, and settlement cannot begin without a dollar. That is a circular dependency, and bridging is how we break it. zUSD exists to serve the period before native issuance.
Why is there no USDC on Tron?
Circle stopped minting USDC on Tron in February 2024 and ended redemption there in February 2025. Tron therefore contributes USDT alone, which is why the backing set numbers seven rather than eight.
What stays private, and what does not?
Within Rand, a zUSD payment discloses no sender, recipient or amount. The boundary is a different matter: deposits and releases settle on transparent chains, so the fact and size of a lock or a release are visible there. Disclosure inside Rand remains at your discretion. You hold a viewing key and can extend it to an auditor or regulator of your choosing, who can then read your records in full.
What does it cost?
A transfer on Rand carries a small fee payable in RAND. Redemption carries a bridge fee on Rand, and the source-chain endpoint charges a release fee of 10 basis points. Deposits are minted at the full attested amount.
Can I use it today?
On testnet. The bridge is operating on Rand's current test network with all seven backings listed, and the figures at the top of this page are read directly from it. Testnet assets carry no monetary value, so the environment is suitable for integration and evaluation, not for holding funds.
The specification is public
zUSD is specified in the Cross-Chain Collateral section of the Rand Protocol whitepaper: the backing set, the supply theorem, the redemption guard and the pooled-backing remark this page summarizes.