Curve DAO appoints Resupply developers to risk role

fiverr
Ledger



Curve DAO approved yRisk as its new risk-management provider for crvUSD and Llamalend on Sept. 2, assigning the mandate to two contributors who are also primary developers of Resupply.

Summary

  • Curve DAO approved yRisk to monitor crvUSD and Llamalend through a twelve-month risk management mandate.
  • yRisk will receive 125,000 frxUSD and 568,181 CRV through two revocable one-year vesting streams separately.
  • Its two contributors disclosed being primary Resupply developers, whose protocol suffered a 2025 donation attack.
  • The proposal and Curve comparison did not mention Resupply’s approximately $9.6 million exploit explicitly anywhere.
  • yRisk’s binding funding vote passed with 621.2 million veCRV supporting and virtually none opposing it.

The binding onchain vote closed with approximately 621.2 million veCRV supporting the proposal and 5.33 veCRV opposing it. The proposal was executed about 87 minutes after voting ended.

bybit

yRisk will receive 125,000 frxUSD and 568,181 CRV through separate revocable vesting streams lasting one year. The package represents the team’s requested annual budget of approximately $250,000.

Curve DAO gives yRisk a twelve-month mandate

yRisk will provide risk assessment and monitoring across crvUSD mint markets and Llamalend isolated lending markets. Its responsibilities include reviewing collateral, liquidity, oracle design, concentration and governance risks.

The team will also recommend debt ceilings, market parameters, PegKeeper limits and other risk controls. Curve governance and its emergency DAO retain authority over final decisions and execution.

According to its original proposal, yRisk plans to build public monitoring systems, dashboards, alerts and automated code-analysis tools. Work funded by the mandate will generally be released under an open-source license.

The team consists of contributors known as Wavey and Dudesahn. The proposal identifies both as core developers at Yearn and Resupply and describes them as Resupply’s primary developers.

Resupply exploit was absent from reviewed materials

Resupply suffered a donation attack in June 2025 that caused approximately $9.6 million in losses. A QuillAudits analysis attributed the incident to exchange-rate manipulation affecting a lending market.

The attacker donated assets to a nearly empty vault, causing an exchange-rate calculation to round toward zero. That manipulation allowed the attacker to borrow against artificially inflated collateral.

yRisk’s Curve proposal disclosed its contributors’ Resupply roles but did not mention the exploit. Curve’s comparative assessment also discussed their Resupply experience without referring to the incident.

The omission does not establish that yRisk violated a disclosure requirement. Curve’s call for proposals requested relevant experience, methodology, capacity and pricing, but the published requirements did not expressly demand disclosure of every incident involving a contributor’s previous projects.

Curve reviewers identified a staffing concern

Swiss Stake reviewed nine competing applications before Curve conducted its preference votes. Its assessment credited yRisk with practical knowledge of Curve, Llamalend, Yearn and Resupply.

The review also identified capacity as its main concern. It questioned whether two contributors with other responsibilities could monitor a growing number of markets and provide adequate incident coverage.

“It is not yet clear whether they can sustain that workload and provide sufficient incident coverage as the number of markets expands,” Swiss Stake said.

The statement described uncertainty rather than a finding that yRisk lacked the necessary resources. Swiss Stake recommended an initial limited mandate and a public review checkpoint for whichever provider Curve selected.

During a nonbinding preference vote, yRisk received approximately 536.97 million veCRV votes in favor and none against from 47 voters. That represented about 68.78% of the voting supply at the snapshot block.

yRisk replaces LlamaRisk across Curve markets

Curve began seeking a replacement after LlamaRisk ended its engagement early. LlamaRisk had renewed its mandate in April 2026 with plans to continue through April 2027.

The provider announced its departure on May 29 and stopped active work on June 30. It returned approximately 270,247 crvUSD in unvested funding to Curve’s treasury.

LlamaRisk described the departure as a structural decision about how it allocated resources, rather than criticism of Curve. Curve opened its replacement process on July 7.

The new mandate arrives as Curve expands Llamalend. Crypto.news previously reported that Llamalend v2 introduced isolated lending markets on Optimism before a planned Ethereum deployment.

Risk management has remained a central concern for the ecosystem. In March, an improperly configured oracle enabled an attacker to extract approximately $240,000 from a Llamalend market, as crypto.news reported in its coverage of the sDOLA-crvUSD pool exploit.

Public reporting will test yRisk’s delivery

yRisk must now review LlamaRisk’s existing reports, models, dashboards and repositories. The team will determine which resources should be retained, rebuilt or retired.

Its proposal commits to monthly progress reports, continuous monitoring and incident support. The revocable funding structure gives Curve DAO the ability to stop the remaining vesting streams before the twelve-month term ends.

A future public review would allow governance participants to assess whether yRisk has met its monitoring, reporting and response commitments. Curve has not announced a specific date for that checkpoint.





Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*