Curve DAO has appointed yRisk as its new full-scope risk-management provider for crvUSD and Llamalend, selecting a two-person team whose contributors are also the primary developers of Resupply, a DeFi lending protocol exploited for approximately $9.6 million last year.

The binding governance vote approving yRisk’s funding concluded on September 2 with approximately 621.2 million veCRV supporting the proposal and only 5.33 veCRV voting against it.

Under the 12-month mandate, yRisk will receive 125,000 frxUSD and 568,181 CRV through separate revocable one-year vesting streams, representing an annual budget of approximately $250,000. Curve began searching for a new risk provider after LlamaRisk ended its engagement early. The DAO’s July request sought a team capable of monitoring collateral, liquidity, oracle dependencies, bad debt and other risks across crvUSD mint markets and Llamalend isolated lending markets.

Resupply Developers Take Over Curve Risk Mandate

yRisk is led by developers known as Wavey and Dudesahn. Its Curve proposal openly identifies both as core developers at Yearn and Resupply and states that they are Resupply’s primary developers. That background gives the team direct experience with Curve infrastructure.

Resupply is built around Curve’s crvUSD and CurveLend ecosystem, while yRisk’s contributors have worked on Curve-related vaults, Llamalend integrations and other open-source tooling. Their appointment is nevertheless notable because Resupply experienced one of DeFi’s significant lending exploits of 2025.

In June 2025, an attacker exploited a newly deployed Resupply market through an exchange-rate manipulation commonly described as a donation attack. The attacker targeted a market with extremely low liquidity, manipulating the exchange-rate calculation by donating assets and exploiting rounding behavior. That enabled collateral to receive an artificially inflated valuation and allowed approximately $9.6 million to be borrowed from the protocol.

The yRisk proposal discloses the developers’ Resupply roles but does not explicitly discuss that exploit. Curve’s published assessment of competing risk providers similarly cited their experience with Resupply without specifically referencing the incident.

That omission does not establish that yRisk breached a disclosure obligation. Curve’s call for proposals requested information covering experience, methodology, capacity, tooling and pricing but did not explicitly require applicants to list every previous security incident involving protocols they had developed.

Two-Person Team Faces Capacity Questions

Curve considered nine applications before selecting yRisk. Swiss Stake, which conducted a standardized comparison for the DAO, credited yRisk’s practical experience with Curve, Llamalend, Yearn and Resupply but identified the team’s size as a potential operational concern.

With only two principal contributors who also maintain responsibilities elsewhere, reviewers questioned whether yRisk could sustain continuous monitoring and adequate incident coverage as Curve’s number of markets expands. The concern did not prevent yRisk from receiving overwhelming governance support.

Its mandate covers risk assessment and ongoing monitoring across crvUSD mint markets, PegKeepers and Llamalend isolated markets. The team will evaluate collateral quality, market liquidity, oracle design, concentration and governance risks while recommending debt ceilings and other market parameters.

yRisk also plans to build automated monitoring, alerts, dashboards and reproducible risk-analysis tools, with most work funded by the mandate intended to remain open source. Final authority remains with Curve governance and its emergency DAO.

The funding structure provides another safeguard: both payment streams are revocable, allowing the DAO to terminate remaining compensation before the 12-month mandate expires. The appointment therefore presents an unusual juxtaposition.

Curve has entrusted risk oversight to developers whose technical experience includes operating a protocol that suffered a major exploit, while simultaneously selecting them through an overwhelmingly supportive governance process.

Whether that experience becomes an advantage or a liability will now be tested publicly. yRisk has committed to continuous monitoring, monthly reporting and incident support, giving Curve governance measurable benchmarks against which to evaluate whether its new risk provider can translate firsthand experience with DeFi failure modes into stronger protections for crvUSD and Llamalend.