BlockRadar News
Market quotes loading
Curve DAO

Curve DAO Risk Provider yRisk Wins Mandate

Curve DAO appoints yRisk as its risk provider for crvUSD and Llamalend, allocating 125k frxUSD and 568k CRV while the developers retain ties.

BlockRadar News desk Based on reporting by The Defiant

Immediate Outcome of the Vote

On September 2 Curve DAO approved yRisk as its designated risk provider for both crvUSD and Llamalend. The binding vote recorded 621,165,848 veCRV in favor and a negligible 5.33 against, representing roughly 69% of the total veCRV supply at the snapshot block. Within 87 minutes the transaction was finalised, releasing two revocable one-year streams: 125,000 frxUSD locked in sfrxUSD and 568,181 CRV. At Thursday’s market price the CRV tranche alone is worth about $209,000, while the frxUSD principal will generate yield that returns to the Curve treasury.

Governance Mechanics and Vote Concentration

The decision followed a two-stage voting process. From August 10-17 the DAO ran nine parallel non-binding preference votes, allowing holders to back multiple bidders. yRisk’s “temp check” attracted 536,968,660.7 veCRV from 47 voters and recorded zero votes against, representing 68.78% of the total veCRV supply. By contrast, CrossWorlds, the second-place bidder, amassed 401.4 million in favor but faced 236 million against. Other contenders—Blockworks Advisory, Xerberus and Pharos Watch—each drew fewer than 300 million favorable votes while encountering over 536 million opposed. The stark disparity suggests a highly concentrated voting bloc supporting yRisk, a pattern that may warrant closer scrutiny by Curve’s governance analysts.

Developer Background and the Resupply Exploit

yRisk is described in the proposal as “primary Resupply developers” and “core developers at Yearn and Resupply, through their respective limited companies.” Resupply, a stablecoin and lending protocol built atop crvUSD and CurveLend, suffered a $9.6 million loss in June 2025 due to a donation-attack exploit that forced a vault exchange rate to zero. The incident, detailed in a Quill Audits post, is absent from both the yRisk proposal and Curve’s comparative review of bidders. This omission raises governance-risk questions: did the DAO’s reviewers overlook the exploit, or was the information deemed immaterial for the risk-provider role? Swiss Stake, the entity that evaluated the bids, praised yRisk’s Curve experience but did not flag the Resupply breach, highlighting a potential gap in due-diligence frameworks.

Market Implications for crvUSD and Llamalend

crvUSD, Curve’s algorithmic stablecoin, relies on robust risk oversight to maintain peg stability. By shifting the risk mandate from LlamaRisk—who exited ten months into a one-year renewal—to yRisk, Curve signals confidence in the new provider’s technical competence. However, the Resupply hack underscores the systemic risk of cross-protocol developer involvement. If yRisk’s risk models inherit assumptions from Resupply’s architecture, hidden vulnerabilities could propagate to crvUSD’s collateralisation mechanisms. Institutional investors monitoring stablecoin exposure will likely reassess Curve’s risk-management posture, especially given the sizable veCRV voting power that backed the decision.

Capital Flow and Treasury Impact

The allocation of 125,000 frxUSD and 568,181 CRV represents a modest outlay relative to Curve’s treasury, yet the structure of the payment is noteworthy. The frxUSD is held as sfrxUSD, meaning the principal remains locked while any yield accrues to the treasury, effectively creating a zero-cost risk-service contract for the DAO. This design mirrors other DeFi risk-provider arrangements where incentives are aligned through token vesting rather than direct cash payments. For operators of Curve-based products, the arrangement reduces immediate cash pressure but introduces token-price exposure; a 78% rise in CRV over the past month amplified the cost of the grant, a factor that could influence future budgeting cycles.

Regulatory Lens and Compliance Considerations

While the DAO operates in a largely permissionless environment, the concentration of voting power and the opaque handling of a prior exploit may attract regulator attention. In jurisdictions where DeFi protocols are increasingly subject to AML/KYC and consumer-protection rules, governance decisions that affect stablecoin stability could be interpreted as “financial services” activities. The U.S. Securities and Exchange Commission has signaled interest in DeFi risk-management frameworks; a governance process that appears to overlook material security incidents might be viewed as insufficient risk disclosure. Curve’s internal audit teams and external reviewers such as Swiss Stake will need to document their due-diligence methodology to mitigate potential supervisory inquiries.

Operational Consequences for Protocol Users

For lenders and borrowers on Llamalend, the change in risk provider could alter collateral-liquidation thresholds if yRisk adopts more conservative parameters. Users should monitor upcoming risk-parameter updates on Curve’s governance portal. Additionally, the absence of a public post-mortem on the Resupply hack within the proposal may signal limited transparency, prompting users to demand clearer reporting from yRisk on how lessons from the exploit are being integrated into their risk models.

What to Watch Next

  1. Risk-Parameter Adjustments – Expect a governance proposal from yRisk outlining updated liquidation ratios for crvUSD and Llamalend within the next two weeks.
  2. Audit Follow-Up – Independent auditors may be engaged to review yRisk’s risk engine, especially given the Resupply background.
  3. Voting Power Distribution – Track veCRV delegation patterns to see whether the concentration that propelled yRisk’s win persists or diversifies in subsequent votes.
  4. Regulatory Signals – Monitor statements from the SEC and European regulators regarding DeFi risk-provider disclosures; any guidance could prompt Curve to revise its governance documentation.

Curve’s swift execution – finalising the proposal within 87 minutes – illustrates the efficiency of on-chain governance but also the fragility of consensus when a single entity commands a majority of voting power. The episode adds to a growing list of cases where protocol-level risk decisions are made by developers with overlapping interests across multiple projects. As DeFi matures, institutional participants are demanding more rigorous conflict-of-interest checks and transparent audit trails. The market’s reaction, reflected in a modest uptick in CRV price following the vote, suggests investors remain cautiously optimistic, but the underlying governance risk remains a focal point for analysts.

Real-Time Market View

The broader crypto market continues to exhibit volatility, with Bitcoin hovering near $78,000 and Ethereum maintaining a stable range. For a real-time view of asset movements, see a global market snapshot.


This analysis was compiled from the original reporting on thedefiant.io and supplemented with market data from reputable sources.

Key takeaways

  • Curve DAO voted overwhelmingly for yRisk, allocating 125k frxUSD and 568k CRV.
  • yRisk developers also contributed to Resupply, a protocol that suffered a $9.6M hack in June 2025.
  • Zero votes against yRisk raise questions about voter concentration and due-diligence processes.

Questions

What compensation did yRisk receive for its risk-provider role?

yRisk was granted two revocable one-year streams: 125,000 frxUSD held as sfrxUSD and 568,181 CRV, valued at roughly $209,000 at current prices.

How did the voting results compare to other bidders?

yRisk secured 621,165,848 veCRV in favor with only 5.33 against, while the runner-up CrossWorlds received 401.4 million for and 236 million against.

Provenance

Published
September 3, 2026
Source dated
Sep 3, 2026
Original report
The Defiant
How this was made
Written up by an automated desk from the reporting linked above and published under the desk's name. Some outbound links are paid and are marked as partner links. How this site works.

More on this topic