Curve DAO names yRisk to manage crvUSD and Llamalend risk for 12 months

Daily Feed
Curve DAO names yRisk to manage crvUSD and Llamalend risk for 12 months

Curve DAO has approved yRisk to handle risk management for crvUSD and Llamalend for the next twelve months, handing the job to two DeFi builders whose Resupply background brings both expertise and baggage.

  • Approved: yRisk will oversee crvUSD and Llamalend.
  • Funding: 125, 000 frxUSD and 568, 181 CRV.
  • Tension: Strong technical fit, but capacity and disclosure questions linger.

On Sept. 2, Curve DAO approved yRisk as the new risk-management provider for its crvUSD system and Llamalend lending markets. The mandate lasts twelve months and is funded through two revocable one-year vesting streams worth 125, 000 frxUSD and 568, 181 CRV, a package that matches the team’s requested annual budget of about $250, 000 at the proposal’s assumed token value.

The binding vote was lopsided. Roughly 621.2 million veCRV supported the appointment, while 5.33 veCRV opposed it. The proposal was executed about 87 minutes after voting ended, which tells you governance moved with all the urgency of a trader spotting free lunch and none of the hesitation usually reserved for “maybe we should think about this a little longer.”

veCRV, for the uninitiated, is Curve’s vote-escrowed CRV model. Users lock CRV to gain governance power. The setup is meant to align incentives over time, but it also means the people steering protocol risk are often the same ones with the most skin in the game.

yRisk’s job is the unglamorous part of DeFi that keeps expensive mistakes from becoming protocol lore. The team will monitor crvUSD mint markets and Llamalend’s isolated lending markets, review collateral, liquidity, oracle design, concentration risk, and governance risk, and recommend debt ceilings, market parameters, PegKeeper limits, and other controls.

Those terms matter. Oracles are the price feeds DeFi uses to decide what assets are worth. If those feeds are broken or manipulated, a lending market can be stripped before anyone realizes the math is rotten. Debt ceilings cap how much can be borrowed. PegKeeper limits help govern Curve’s peg-support mechanisms. Revocable vesting streams mean the funds are released over time, but Curve DAO can stop the remaining stream if the work goes sideways. In DeFi, boring risk management is usually cheaper than a flashy post-mortem.

The appointment gets more interesting once you look at who yRisk is. The team consists of Wavey and Dudesahn, both described as core developers at Yearn and Resupply and as Resupply’s primary developers. That’s the upside: they know this corner of DeFi from the inside. The downside is that Resupply suffered a donation attack in June 2025 that caused roughly $9.5 million to $9.6 million in losses, depending on the source.

QuillAudits described the exploit as Hack Analysis and Its Impact. In plain English, the attacker donated assets into a nearly empty vault, which distorted the protocol’s accounting. Because the exchange-rate calculation rounded toward zero, the attacker was able to borrow against artificially inflated collateral. That is a classic DeFi failure mode: if your accounting can be gamed, someone will eventually turn your elegant formula into a money printer for themselves.

What stands out here is not just the Resupply history, but how it was handled. According to crypto.news, yRisk’s proposal disclosed the contributors’ roles at Resupply, but did not explicitly mention the June exploit. Curve’s comparison materials also discussed their Resupply experience without calling out the incident. That does not automatically prove bad faith or a rule breach, but it does leave a fair question hanging in the air: if prior security failures are relevant to a risk role, why tiptoe around them?

Swiss Stake, which reviewed nine competing applications before Curve’s preference votes, basically raised the same issue in more restrained language. It credited yRisk with practical knowledge of Curve, Llamalend, Yearn, and Resupply, but said capacity was the real concern.

“It is not yet clear whether they can sustain that workload and provide sufficient incident coverage as the number of markets expands, ”

That’s the heart of it. Two experienced people can cover a lot, but Curve’s surface area is growing, and DeFi does not send polite calendar invites before an exploit lands.

Swiss Stake recommended an initial limited mandate and a public review checkpoint. Curve has not announced a specific date for that checkpoint, so the revocable funding structure is the main accountability lever for now. If performance slips, the DAO can stop the remaining vesting streams. Whether governance actually does that when the time comes is another matter entirely.

The timing matters too. Curve is expanding Llamalend, and its lending stack has already shown weak spots. Crypto.news previously reported that Llamalend v2 introduced isolated lending markets on Optimism before a planned Ethereum deployment. Isolated markets are meant to contain damage so one bad pool does not contaminate the whole system. Helpful? Absolutely. Magical? Not even close.

Curve has also already had to deal with a lending-market exploit. In March, an improperly configured oracle enabled an attacker to extract about $240, 000 from a Llamalend market in the sDOLA-crvUSD pool exploit. That sort of failure is exactly why risk oversight matters: one bad price feed can turn into a tidy little theft if nobody catches it fast enough.

Curve’s search for a replacement began after LlamaRisk ended its engagement early. LlamaRisk had renewed in April 2026 with plans to continue through April 2027, then announced its departure on May 29 and stopped active work on June 30. It returned about 270, 247 crvUSD in unvested funding to Curve’s treasury before Curve opened the replacement process on July 7.

LlamaRisk said its exit was a structural decision about how it allocated resources, not criticism of Curve. Fair enough. Protocol teams move around, priorities change, and sometimes the polite version of “we’re breaking up” is genuinely accurate. But the practical result was the same: Curve needed a new risk seat filled, and it needed someone who could get up to speed without wasting months.

That is where yRisk’s pitch appears to have landed. Swiss Stake liked the team’s familiarity with the protocols involved, and the nonbinding preference vote was also strong: yRisk received about 536.97 million veCRV in favor, none against, from 47 voters, representing about 68.78% of the voting supply at the snapshot block. The binding vote then followed with overwhelming support.

The broader message is hard to miss. Curve is not just running stable-swap pools anymore. It is building lending infrastructure with real moving parts, real attack surfaces, and real loss potential. That means the protocol needs more than optimism and branding. It needs people who can spot the weak link before the chain snaps.

The good news is that Curve is funding risk work, formalizing it, and keeping that funding revocable. The uncomfortable truth is that strong governance support does not erase the possibility of understaffing, blind spots, or convenient omissions. In DeFi, reputation helps. Memory helps more.

For readers who want the underlying protocol docs, the Curve Knowledge Hub is where the technical framework lives. And for a market-side snapshot of how traders are pricing the token narrative, Investment Analysis September 2026 offers a useful contrast to the governance and security realities on the ground.

Key questions and takeaways

  • Why did Curve choose yRisk?
    Because the team already knows Curve’s systems, and governance clearly preferred continuity and hands-on experience over a longer search. That does not make the choice perfect, but it does make it understandable. For additional context, see Curve DAO selects yRisk as new risk provider for crvUSD and the governance recap on Curve DAO Appoints yRisk for Risk Management Despite.

  • What will yRisk actually do?
    It will monitor crvUSD mint markets and Llamalend isolated lending markets, review collateral, liquidity, oracle design, concentration risk, and governance risk, and recommend safeguards like debt ceilings and PegKeeper limits.

  • Why does the Resupply background matter?
    Because Resupply suffered a June 2025 donation attack that caused roughly $9.5 million to $9.6 million in losses. That history does not disqualify the team, but it does make disclosure and scrutiny matter more. A deeper post-mortem is available in sDOLA Market Exploit: Attack Overview and Lessons Learned.

  • Is team size a real concern?
    Yes. Swiss Stake’s main warning was about capacity, saying it was not yet clear whether two contributors could sustain the workload and provide enough incident coverage as the number of markets expands.

  • What is the biggest risk for Curve now?
    The biggest risk is operational: whether yRisk can keep pace with Curve’s expanding lending markets and catch problems before they become losses. DeFi is very bad at forgiving “we’ll review that later.”

Further reading

For a closer look at Curve’s risk staffing move and the baggage that comes with it:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog