What happened
The Curve Finance community has approved a pivotal governance proposal, delegating the risk management mandate for its core products, crvUSD and LlamaLend, to a new provider called yRisk. The vote was overwhelmingly positive, securing 536.9 million votes in favor and zero against. Consequently, the mandate was funded on September 2nd with 125,000 frxUSD and 568,181 CRV tokens.
Controversy emerged shortly after, when it was revealed that the two primary contributors to yRisk are the same developers behind Resupply, a DeFi protocol that lost $9.6 million to an exploit in June 2025. This critical piece of information regarding the team's track record was notably absent from the official proposal submitted to the DAO.
Technology context
In the Decentralized Finance (DeFi) ecosystem, risk management is a critical function. Protocols like Curve utilize liquidity algorithms and lending mechanisms (LlamaLend) that require constant monitoring of market parameters to prevent insolvency or massive capital losses.
Curve operates through a governance model based on veCRV (vote-escrowed CRV), where users lock their tokens to gain voting power. Strategic decisions, including who manages risk parameters, are made through this on-chain direct democracy mechanism. However, this incident highlights a vulnerability in the system: voters often rely on information presented in proposals without always performing rigorous background checks or due diligence on the entities involved.
Why it matters
This event is significant for several reasons:
1. Governance Transparency: Omitting a major exploit from the resume of a team seeking to manage risk raises serious questions about the integrity of the voting process within DAOs.
2. Fund Security: Curve is one of the largest liquidity pillars in the crypto ecosystem. Any error in crvUSD risk management could have contagion effects across the entire market.
3. Developer Accountability: The reappearance of developers under new brand identities (yRisk) following major failures (Resupply) puts pressure on the community to develop better reputation auditing mechanisms.
Key terms explained
- DAO (Decentralized Autonomous Organization): An organization governed by rules encoded on a blockchain, where decisions are made through member voting.
- veCRV: The "locked" version of the CRV token that grants governance rights and a share of Curve protocol revenues.
- Exploit: A vulnerability in a smart contract's code used by attackers to unauthorizedly extract funds.
- crvUSD: The native stablecoin of the Curve protocol, backed by over-collateralization.
Impact
In the short term, trust in the Curve DAO's due diligence process may decline, leading to stricter monitoring of future proposals. Although the mandate is already funded, the community might demand its revocation if yRisk's performance falls below expectations or if further red flags emerge.
In the medium term, this case could serve as a precedent for implementing more rigorous transparency standards for service providers in DeFi, similar to financial audits in the traditional world.
What's next
yRisk is expected to be under intense scrutiny from the Curve community. If the team succeeds in stabilizing and optimizing crvUSD parameters, they might rehabilitate their reputation. Conversely, we may see a reform in how DAOs select external experts, potentially introducing trial periods or financial guarantees (slashing) in case of negligence.
Sources
- The Defiant
- Curve DAO Governance Proposals
- Resupply Protocol Post-Mortem (June 2025)
*
Educational analysis generated with AI and editorially reviewed.