Curve DAO's binding vote to appoint a new risk provider for crvUSD and Llamalend attracted 5.33 veCRV of opposition against roughly 621.2 million in favour, and executed 87 minutes after the polls closed. The team it hired is run by the two primary developers of Resupply, a protocol that lost about $9.6 million to a donation attack in June 2025. The proposal named their Resupply roles. It did not mention the exploit.

That is the shape of the week. Across two of DeFi's largest lending venues, token holders approved the delegation of risk authority to very small groups at very high speed, and in both cases the information needed to judge the delegation arrived after the vote rather than before it. Nothing here is a scandal. It is something duller and more durable: a governance process that is now faster than its own due diligence.

1. Curve's yRisk vote passed with functionally zero opposition

Proposal 1492 closed on 2 September 2026 at 15:04 UTC. The Defiant reports a final tally of 621,165,847.95 veCRV in favour and 5.33 against, with execution following 87 minutes later. The mandate covers collateral evaluations, parameter monitoring, alerts during stress periods and biannual public health updates on the lending markets.

Compensation runs through two separate, revocable one-year vesting streams: 125,000 frxUSD, held in yield-bearing sfrxUSD with the yield returning to the Curve treasury, and 568,181 CRV, worth roughly $209,000 at the time of announcement. That matches yRisk's requested annual budget of about $250,000, which is not a large number for oversight of a stablecoin and an expanding lending market.

The non-binding temp check, Proposal 1478, ran 10 to 17 August and drew 47 voters representing 68.78% of veCRV supply. yRisk took 536,968,660.7 veCRV for and none against. Runner-up CrossWorlds took 401.4 million for and 236 million against. Reporting on the tallies is not fully consistent; some outlets attribute the 536.9 million figure to the binding vote.

621.2M
veCRV in favour
Binding vote, Proposal 1492, 2 September 2026
5.33
veCRV against
Total recorded opposition
87 min
Vote close to execution
Time elapsed before the proposal executed
$250k
Annual mandate
125,000 frxUSD plus 568,181 CRV, revocable

2. The line the proposal left out

yRisk's two contributors, known by the handles Wavey and Dudesahn, describe themselves as core developers at Yearn and as Resupply's primary developers. Both facts appear in the proposal. What does not appear, according to crypto.news, is that Resupply lost roughly $9.6 million in June 2025 when an attacker manipulated an exchange-rate calculation through an asset donation and rounding behaviour on a newly deployed, low-liquidity market.

The omission extends to Curve's own comparative review, the document governance participants were meant to use to weigh candidates. Curve's call for proposals asked for relevant experience, methodology, capacity and pricing. It did not explicitly require disclosure of security incidents at a contributor's other projects, which means yRisk broke no stated rule.

That is precisely the problem. A vetting process for a risk provider that does not ask about prior losses is not a vetting process with a loophole; it is a vetting process missing its central question. The failure sits with the framework, not the applicants.

3. The objection worth taking seriously, and why it holds only halfway

The strongest defence of the appointment is a good one. Having shipped a protocol that was exploited is not disqualifying for a risk role; it is arguably the most expensive education available in DeFi, and a team that has watched a donation attack drain its own market has a sharper instinct for the failure mode than one that has only modelled it. The compensation is modest and both streams are revocable. crvUSD held its peg between $0.997 and $1.000 through recent volatility. The developers disclosed their Resupply affiliation openly.

All of that is true and none of it settles the matter, because the question was never whether yRisk is competent. The question is whether 68.78% of veCRV supply got to decide that with the relevant facts in hand. A third-party reviewer, Swiss Stake, did raise a flag, though a different one: capacity. Two contributors covering an expanding Llamalend surface prompted a recommendation of an initial limited mandate with a public review checkpoint. The DAO approved the full twelve months instead. Reading a proposal for what it omits is one of the harder habits to build, and it is a large part of how large holders analyse proposals before committing weight.

The main concern is capacity

Swiss Stake
Third-party reviewer on yRisk's two-person team

4. Aave handed out freeze power with no unfreeze attached

The ARFC to activate Risk Stewards on Aave V4 went up on 20 August and escalated to Snapshot on 2 September. CryptoSlate reports the vote opened 3 September at 3:46 p.m. and closed three days later at the same hour, covering the Ethereum and Avalanche instances.

It replaces a single domain admin role with five granular ones: Spoke Active/Pause, Spoke Halted/Freeze, Listing, Emergency and Risk Management. Routine changes are boxed in tightly. Hub interest-rate parameters carry a 36-hour cooldown and a 3% absolute cap per action, 20% for rateGrowthAfterOptimal. Collateral factor changes sit behind 72 hours and a 0.5% or 5% absolute limit. Oracle price caps, 72 hours and 5% relative.

The emergency roles carry no execution delay at all, and they are one-directional. Stewards can deactivate, halt or pause. They cannot reverse any of it. Unfreezing a market requires a separate governance action, which is the slow path precisely when speed matters most.

5. Powers that are dormant today are still powers

Two caveats sit under the Aave grant. The current Risk Steward release does not call any emergency selector functions, so the emergency authority is dormant until a future release activates it. And a passed Snapshot still requires execution by the V4 Security Council before any steward holds anything. The Certora audit of the steward contracts was described as reaching finalization, not finished, at proposal time; Grafa reported on 7 September that the contracts had undergone the audit, with AAVE trading at $133.35 that day.

The objection raised in the forum is not that stewards will misbehave. It is that the DAO is pre-authorising a capability whose activation needs no fresh vote, with no mandatory reporting on when or why it gets used. Community members asked for post-action reports and usage frequency disclosures. Neither is written into the proposal. This is the same Aave Labs versus DAO centralisation argument that has surfaced repeatedly, restated in narrower and more technical terms, which is how these arguments usually return.

Community discussion should remain meaningful and not only a formal approval process.

Aave governance forum participant

What the two votes have in common

LlamaRisk, which had served Curve since 2021, exited on 29 May citing a "structural decision" about resource allocation, returned roughly 270,247 unvested crvUSD to the treasury and now focuses exclusively on Aave. So the same week that Curve replaced a large incumbent with a two-person outfit, Aave moved toward delegating constrained emergency authority to a small operator group of its own. Both DAOs are concentrating operational risk power in fewer hands, for defensible reasons, on votes that produced almost no dissent.

Holders who want a say in how this settles should watch one thing above all: whether the Aave Security Council's execution attaches the reporting requirements the forum asked for, because that is the last moment at which conditions can be put on the grant without a full governance cycle. On Curve, the equivalent lever is the revocability of the two vesting streams, which is a real check only if somebody is watching closely enough to pull it. The mechanics of both are covered in more depth in our primer on DAO decision-making.