What is Zoth?
Zoth is a real-world-asset protocol built around ZeUSD, a stablecoin backed by tokenised fixed-income notes it calls ZTLN. It describes itself as the first restaking layer for RWA finance. It is also a protocol that was exploited twice in one month in March 2025, for $285,000 and then for $8.4 million, and kept operating afterwards. Both halves belong on the same page.
What Zoth actually does
Zoth tokenises fixed-income assets — treasury bills and sovereign debt are the examples it gives — and issues claims against them on-chain. The pitch is the one most RWA protocols make: bring the yield and relative stability of government paper into DeFi, where it can be used as collateral and moved between chains.
What Zoth added on top is restaking. Rather than a tokenised note sitting idle in a wallet, Zoth’s design lets the same underlying asset back a second instrument that circulates. The company calls this the first restaking layer for RWA finance, and points at the tokenised fixed-income market as the pool it wants to reach.
That layering is the interesting part and the risky part at once. Every extra claim on the same collateral is another place a logic error can be expressed, which is not a theoretical concern here.
ZeUSD and ZTLN: two instruments, one collateral
ZTLN — Zoth Tokenized Liquid Notes — is the note representing the underlying fixed-income position. It is the layer nearest the actual asset.
ZeUSD is the stablecoin. It is not backed by dollars in a bank; it is backed by ZTLN, which is backed by the fixed-income assets. Zoth describes it as omni-chain and fully backed by high-quality fixed-income paper.
Read that chain of backing carefully before treating ZeUSD as interchangeable with a fiat-reserved stablecoin. It is a claim on a claim on a bond. That is a legitimate structure and it is also two steps further from the asset than USDC is, which matters most precisely when you would want it not to.
The product did find demand: ZeUSD reached more than $27 million in total value locked within six weeks of its beta.
March 2025: two hacks, three weeks apart
Most write-ups about Zoth mention one hack. There were two, and they failed in different ways, which is why both are worth naming.
March 1, 2025 — roughly $285,000. A loan-to-value logic flaw in the mintWithStable path. This is a code-level bug: the contract did what it was written to do, and what it was written to do was wrong.
Later in March 2025 — roughly $8.4 million. A different class of failure entirely. The private key controlling the deployer address for the protocol’s proxy contract was compromised. No clever contract exploit was needed; whoever held that key could upgrade the proxy. Reports at the time noted the attacker converted the proceeds to DAI.
The second one is the one to weigh. A logic flaw is a bug you can audit for. A compromised deployer key on an upgradeable proxy is a governance and operational-security failure, and it means the contract’s published code was never the whole of the trust assumption.
Where the databases disagree
Zoth’s funding history does not reconcile cleanly across sources, and anyone sizing the company should know that before quoting a number.
Tracxn puts total funding at $6.5 million across six rounds from twenty investors. Separately, Zoth was reported to have received $15 million from Bolts Capital in August 2025 — on its own larger than the cumulative total the first source gives. A further round was reported in February 2026.
These are not necessarily contradictory: a database may exclude a facility, a commitment, or a non-equity arrangement that a press release counts. But they cannot both be a complete picture, and we have not seen a reconciliation from the company. Treat any single headline figure for Zoth as one source’s definition, not as settled fact.
The same caution applies to the $200 million-plus that Zoth said was committed to RWA and stablecoin opportunities alongside its FAAST launch in July 2025. Committed is not deployed.
The risk section nobody prints
The proxy is upgradeable, and a key already leaked once. This is the single most important line on the page. The March 2025 incident was not a subtle reentrancy; it was key custody. Whatever the protocol’s code says today, ask who can change it and how those keys are held now.
Backing is layered. ZeUSD is backed by ZTLN, not by dollars. In calm conditions the distinction is academic. In a redemption rush it is the whole question.
Off-chain assets need off-chain trust. Tokenised treasuries depend on a custodian, an issuer and a legal wrapper that no block explorer can verify for you.
Recovery narratives are not recovery. Zoth published a “next chapter” message about advancing secure, scalable RWA infrastructure after the hacks. That is a statement of intent. It is not the same as a public post-mortem with restitution figures, and we have not seen one.
Where Unitypad stands
Zoth is one of the 64 positions on the public portfolio. The club’s own entry records it as a $350 position dated April 17, 2024, entered via WM Capital, with the TGE-return and P&L columns still empty — the canonical record is in the Unitypad docs.
That is a small ticket, and printing it is the point. A portfolio page that shows only the size of the wins is a brochure. The empty P&L column is equally honest: no token generation event has been recorded against this position, so there is no return to claim either way.
We are publishing the hacks in the first screen of this page rather than the last paragraph, because a portfolio page that omits an $8.4 million exploit is marketing, not a record. Members were not shielded from this and neither is the page.
Nothing here is advice, a price forecast, or a claim about what Zoth is worth today. It is what the public record says, dated, with the places the record contradicts itself marked as such.
Zoth questions, answered
What is Zoth in crypto?
Zoth is a real-world-asset protocol that tokenises fixed-income assets such as treasury bills and issues ZeUSD, a stablecoin backed by its ZTLN notes rather than by fiat reserves. It describes itself as the first restaking layer for RWA finance.
Was Zoth hacked?
Yes, twice in March 2025. The first exploit took roughly $285,000 through a loan-to-value logic flaw in the mintWithStable path. The second took roughly $8.4 million after the private key controlling the deployer address of the protocol’s proxy contract was compromised. The protocol continued operating afterwards.
What is ZeUSD backed by?
ZeUSD is backed by ZTLN, Zoth’s tokenised liquid notes, which in turn represent fixed-income assets. It is not a fiat-reserved stablecoin, so the backing runs through two layers rather than one.
How much funding has Zoth raised?
Sources disagree. Tracxn lists $6.5 million across six rounds from twenty investors, while a separate report describes $15 million from Bolts Capital in August 2025, and a further round was reported in February 2026. We have not seen a reconciliation, so no single figure should be quoted as settled.
Logged when it wins.
Logged when it doesn’t.
Unitypad publishes every position by name, including the ones that were exploited. That record is the product: 64 investments, one page, verifiable line by line.