Market Prices

BTC Bitcoin
$75,894.5 -2.02%
ETH Ethereum
$2,405.17 -3.31%
SOL Solana
$97.2 -3.67%
BNB BNB Chain
$715.3 -0.63%
XRP XRP Ledger
$1.3 -7.60%
DOGE Dogecoin
$0.0803 -3.17%
ADA Cardano
$0.1957 -4.12%
AVAX Avalanche
$7.33 -2.11%
DOT Polkadot
$0.9530 -3.56%
LINK Chainlink
$10.88 -4.64%

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xd0c5...bd56
Experienced On-chain Trader
+$0.5M
70%
0x623c...4a44
Early Investor
-$4.4M
91%
0x1f8a...cae3
Early Investor
+$4.2M
70%

🧮 Tools

All →

The Two-Person Risk Mandate: Curve DAO Outsources Its Watchtower to the Team Behind a $9.6M Exploit

CryptoCred Interviews
On September 2, Curve DAO funded yRisk to become the sole risk-assessment and monitoring provider for crvUSD mint markets and Llamalend isolated markets. The mandate pays 125,000 frxUSD and 568,181 CRV through revocable one-year vesting streams—roughly $250,000 annually [[6]][[16]]. The winning team consists of two principal contributors. Both were the primary developers of Resupply, a stablecoin and lending protocol exploited for $9.6 million in June 2025 through a donation attack that rounded a vault exchange rate to zero [[1]][[15]]. The exploit is not mentioned anywhere in the proposal [[1]]. The DAO ran nine parallel non-binding preference votes from August 10 to August 17, one per bidder, and holders could back more than one. yRisk's temp check drew 536,968,660.7 veCRV in favor, none against, from 47 voters—68.78% of the veCRV supply at the snapshot block [[1]][[5]]. That is not a mandate. That is a coronation. Trace every byte back to the genesis block. When I audit a governance decision of this magnitude, I do not read the marketing copy. I read the chain of custody: who built the tooling, who profited from its failure, and who is now paid to monitor the very same risk surface where the failure occurred. Context matters here. This is not a routine vendor swap inside a quiet protocol. Curve sits at the center of DeFi's stablecoin infrastructure. It holds $1.33 billion across its protocols [[5]]. crvUSD circulating supply stood at $285.5 million on Wednesday—down from $302.5 million a week earlier but up from $226.3 million a month prior [[1]]. Llamalend v1 held $76 million in deposits against $44.1 million borrowed, while the v2 iteration, live on Optimism since June 2026 with a 250,000 OP grant, holds $1.75 million against $740,920 borrowed [[1]][[5]]. The previous provider, LlamaRisk, ended its engagement early. It returned unvested crvUSD to the Curve treasury and shifted its focus exclusively to Aave [[2]]. The DAO opened a public call on July 7 with two scopes: crvUSD peg and mint market risk, and isolated Llamalend markets. Nine proposals arrived within two weeks: Curvature, Pharos Watch, Xerberus, BA Labs, Tulipa Capital, Manifold, CrossWorlds, yRisk, and Blockworks Advisory [[9]][[19]]. Nine bidders. Two-person shop wins. The ledger remembers what the marketing forgets. Here is the core problem. Curve is not merely selecting a vendor. It is delegating a critical supervisory function—collateral evaluations, parameter monitoring, stress alerts, and biannual public health updates on the lending markets [[2]]. This is not a one-time audit engagement. It is continuous, operational control over the risk parameters that determine whether crvUSD stays pegged and whether Llamalend borrowers can be liquidated safely. Consider the recent history of this exact surface. In March of this year, an improperly configured oracle enabled an attacker to extract approximately $240,000 from a Llamalend market—the sDOLA-crvUSD pool [[4]][[13]]. That is not ancient history. That is five months ago, on the identical codebase yRisk is now paid to monitor. And consider the Resupply exploit, which is the elephant in this governance room. Resupply was built on top of crvUSD and CurveLend. In June 2025, a donation attack rounded a vault exchange rate to zero, draining $9.6 million [[1]][[15]]. The attack vector was a rounding vulnerability—precisely the class of flaw that a risk provider's parameter monitoring and collateral evaluation framework is supposed to catch before it becomes a headline. The proposal does not mention the exploit. The comparative review does not mention it. Swiss Stake, the entity that reviewed the bids, praised yRisk's Curve experience and open deliverables, then flagged its main concern as capacity—not track record. “Two contributors with other responsibilities would need to cover both scopes, support a fast pace of new Llamalend markets, and monitor a growing risk surface,” Swiss Stake wrote in its August 3 assessment [[1]][[5]]. Capacity, not credibility, was the stated risk. Let me be precise about what this means in operational terms. The mandate covers crvUSD mint markets, PegKeepers, and Llamalend isolated markets [[16]]. Llamalend v2, launched on Optimism, now allows more flexible combinations of collateral and borrowing assets, expanding pairings beyond crvUSD [[2]]. More markets mean more oracles, more collateral types, more parameter surfaces to monitor. Two people—with other responsibilities—are now the sole line of defense between Curve's stablecoin infrastructure and a repeat of the Resupply-style rounding attack. Based on my audit experience, the failure mode here is not malicious intent. It is structural. The risk provider's own assessment model is software. It has bugs. It processes data from oracles that can be manipulated. And it is now operated by a team whose defining production incident—a $9.6 million drain on a protocol they built—is absent from the very document that appointed them. Metadata is not ownership; it is merely a pointer. And in this case, the pointer leads to a governance process that appears to have optimised for alignment over evidence. Now let me address what the bulls got right, because the contrarian angle matters. The absence of the Resupply incident from the proposal does not, by itself, establish that yRisk is unsuitable for the role [[3]]. There is a legitimate argument that the developers who survived a $9.6 million exploit understand the attack surface better than anyone who has never been breached. Post-mortem experience is not worthless; in adversarial engineering, it is often the only teacher that sticks. There is a second defensible point. yRisk's automation-first approach, with open deliverables, is a genuine improvement over the opaque black-box models that most risk providers operate. The DAO's brief required that tooling, models, and documentation remain with the DAO after any mandate ends [[9]]. That is a meaningful accountability mechanism—one that prevents vendor lock-in and preserves institutional knowledge. If yRisk publishes its models and dashboards, the community can audit the auditor. And the overwhelming governance support is itself a data point. 68.78% of the veCRV supply at the snapshot block. That is not a handful of whales pushing a backdoor deal. It is broad consensus, which suggests the DAO's sophisticated holders weighed the trade-offs and still preferred yRisk's specificity and Curve-native experience over nine alternatives. Greed optimizes for yield, not for survival—but in this case, the voters may have optimised for something closer to survival than the market gives them credit for. Yet the counter-arguments only go so far. The structural risks are real and they are not mitigated by good intentions. The first risk is single-point dependency. Curve now relies entirely on a two-person team for risk monitoring across its most systemically important assets. If yRisk misses an incident—delayed alert, false negative, tooling failure—there is no redundant provider, no secondary opinion, no fallback. The DAO fired its safety net and replaced it with a single thread. The second risk is information asymmetry. The veCRV holders who voted overwhelmingly for yRisk cannot independently verify the quality of the team's monitoring. They cannot audit the audit. They cannot stress-test the model. They are taking yRisk's claim—and Swiss Stake's assessment—on faith. Code does not lie, but developers do. And in a governance context, the absence of a disclosed prior exploit in the proposal is a lie of omission that the ledger will eventually expose. The third risk is the one nobody in the governance thread is talking about: the precedent. If a protocol the size of Curve, with $1.33 billion under management, can appoint a risk provider whose defining production incident is omitted from the proposal, then every other DeFi protocol looking for risk management services now has a template. Competence becomes optional. Alignment becomes everything. A mirror reflects the face, not the value. The mirror here reflects a DAO that values loyalty over evidence, and that is a dangerous standard to set for an industry that survives on verifiable trust. Risk is a number until it becomes a breach. Right now, the risk number is $250,000—the annual cost of the mandate. The breach number is whatever the next exploit costs, and it will not be paid in frxUSD. It will be paid by crvUSD minters who trusted a peg, and by Llamalend depositors who trusted a liquidation engine. What should the community track going forward? Three signals, in order of priority. First, yRisk's permission boundaries: if the mandate grants them unilateral parameter adjustment capability, that is a centralisation risk that must be flagged immediately. Second, the quality of their biannual public health updates: if they are formulaic or defensive, treat that as a red flag. Third, Llamalend's bad-debt rate over the next two quarters: if it diverges from historical baselines, the monitoring framework is not working. And one broader signal deserves attention. If other top-tier protocols—Aave, Compound, Uniswap—start appointing similar two-person risk shops with omitted exploits in their proposals, then this is not an anomaly. It is a trend. And trends in governance, like trends in code, always end the same way: with a transaction hash that nobody predicted and everybody should have. The ledger remembers what the marketing forgets. The question is whether Curve's ledger will remember this decision as the moment it professionalised its risk management—or the moment it outsourced its watchtower to the architects of its own recent failure. The next Llamalend exploit, whenever it comes, will answer that question with a timestamp.

Fear & Greed

51

Neutral

Market Sentiment

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,894.5
1
Ethereum ETH
$2,405.17
1
Solana SOL
$97.2
1
BNB Chain BNB
$715.3
1
XRP Ledger XRP
$1.3
1
Dogecoin DOGE
$0.0803
1
Cardano ADA
$0.1957
1
Avalanche AVAX
$7.33
1
Polkadot DOT
$0.9530
1
Chainlink LINK
$10.88

🐋 Whale Tracker

🔴
0x596a...bb23
12h ago
Out
38,586 SOL
🟢
0xcdcc...d86a
5m ago
In
2,949,977 USDC
🟢
0xaee3...a158
30m ago
In
29,856 BNB