Tulipa Capital - Curve Risk Assessment and Market Monitoring Response

1. Summary

Curve does not need another dashboard or periodic risk report. It needs an operating risk function: continuous monitoring, human validation, clear recommendations, and direct involvement until an issue is resolved or the DAO knowingly accepts the remaining risk.

Tulipa will apply the discipline that governs our proprietary and managed capital: deciding where capital belongs, when exposure should be reduced, and when an opportunity should be rejected. Every policy and execution decision remains with the Curve DAO and eDAO. Tulipa Capital will build tools for Curve that Curve will keep. Anything that is created in the scope of the project, the Curve team and DAO will own in perpetuity.

The mandate must answer two related questions.

First, is Curve taking the right risk-adjusted approach? Tulipa will maintain a recurring risk-economics assessment for every in-scope market. It will compare the value earned by the DAO with the risk carried through collateral, liquidity, borrower concentration, oracle design, liquidation capacity, and market-specific failure modes. The output will be a clear recommendation: maintain, reprice, reduce, pause, or exit. We will also maintain a portfolio-level view across crvUSD mint markets, PegKeepers, and DAO credit lines so that governance can evaluate both individual markets and the aggregate balance sheet.

Second, are those risks being monitored properly? Tulipa will operate continuous coverage across crvUSD, PegKeepers, LlamaLend, oracle dependencies, bad debt, YieldBasis flows, and material configuration changes. Every active in-scope market will be covered, including smaller markets with nonzero debt. Critical conditions will be validated and routed within 30 minutes of alert generation; warnings will be reviewed and communicated within two hours. A public, timestamped KPI ledger will record coverage, interruptions, alerts, response times, recommendations, unresolved issues, and disclosed gaps.

Tulipa will also make the evidence usable. Raw data without clear presentation is difficult to interpret, compare, or convert into timely decisions. We will therefore serve Curve’s risk data through accessible visualizations, decision-focused summaries, user tools, and public interfaces that help governance and the wider community find the signal, understand its significance, and act on it.

Tulipa proposes a full-service model covering both core RFP areas and the optional responsibilities described below.

Proposal MVP and Detailed Approach

Tulipa has built a working MVP to establish the operating approach described in this proposal and make the proposed monitoring model concrete. The site includes an interactive market map, supporting tools, and a more detailed explanation of our approach: Explore the Tulipa Curve Risk MVP and detailed proposal.

2. Who We Are and Why We Are Aligned

Tulipa Capital is a DeFi-native asset manager whose risk process exists because our own capital depends on it. The proprietary fund that became Tulipa began operating in 2020; Tulipa launched publicly in 2024. As of July 2026, Tulipa manages approximately $100-110 million in proprietary capital and $43 million across managed vaults. A six-person team works across portfolio management, risk research, monitoring engineering, onchain data, quantitative analysis, and governance communication, with capacity expected to expand.

Our process covers pre-deployment review, live monitoring, exposure management, and incident response. We assess protocols, contracts, counterparties, liquidity, market structure, and exit capacity; automated systems then monitor transactions, rates, utilization, oracles, governance, and abnormal activity. Human operators evaluate material signals and decide whether exposure or escalation is required.

That principal-risk perspective matters. A technically correct report can still miss the operational question: what can be sold, repaid, paused, or changed before deterioration becomes an irreversible loss? Tulipa approaches risk as an operator responsible for capital.

Our alignment with Curve is already economic. Tulipa has capital deployed across the Curve ecosystem and is one of YieldBasis’s largest LPs. Our exposure means that the health of YieldBasis, crvUSD, and the surrounding liquidity system affects our own balance sheet.

We will disclose that position plainly as evidence of alignment, not as a reason to conceal or soften risk. YieldBasis recommendations will use the same documented evidence, thresholds, and public methodology applied elsewhere, while the DAO and eDAO retain the final decision.

That alignment has already produced action. On April 23, while monitoring our exposure, Tulipa identified unusual onchain activity involving YieldBasis contracts and alerted the team within minutes. Our review determined that an attacker had used a custom contract to claim fees and drain approximately $1.25 million of wrapped BTC from three individual vaults while the core protocol contracts remained unaffected. Tulipa had no paid monitoring mandate and no commercial arrangement requiring us to investigate or publish. Our own capital was exposed, so we acted.

This proposal formalizes and extends an operating capability Tulipa already uses when its own capital is at risk.

3. Scope: What Curve Gets

Tulipa will cover both core RFP areas: crvUSD mint-market risk, and LlamaLend isolated-market risk, through one connected system organized around the decisions Curve must make.

Tulipa is creating refined monitoring to produce refined results and public tooling. Detailed data and validated signals will be translated into accessible visualizations, position-level tools, and public interfaces so that better monitoring improves both DAO decisions and the community’s ability to understand and use the underlying evidence.

3.1 crvUSD, mint markets, PegKeepers, and credit lines

For every proposed mint market and PegKeeper pool, Tulipa will publish a pre-vote review covering collateral quality, executable liquidity, oracle design, concentration, LLAMMA behavior, and failure modes. Each review will conclude with recommended launch parameters, approval conditions, remediation, and whether the market can plausibly earn enough value for the risk it adds.

For active markets, monitoring will cover debt, ceiling utilization, collateral deterioration, liquidity, oracle behavior, soft-liquidation conditions, borrower concentration, bad debt, and abnormal activity. PegKeeper coverage will include pool composition, available defense capacity, caps, inventory, utilization, and evidence of whether each keeper is contributing to peg defense under actual market conditions.

DAO credit lines, including YieldBasis, will enter the same portfolio view, covering authorized and drawn exposure, collateral coverage, material flows, concentration, unwind paths, emergency controls, and potential transmission into crvUSD liquidity or peg performance.

The crvUSD view will show where pressure is building, which mechanism is absorbing it, what capacity remains, and what intervention is available. Thresholds will be published as recommendation triggers. They will inform human decisions and will not execute parameter changes automatically.

3.2 LlamaLend isolated markets

Tulipa will cover every active LlamaLend market and its critical LLAMMA infrastructure across v1 and v2. Mint markets and isolated lending markets will remain separate in calculations and reporting because their economics, loss paths, and responsible parties differ.

Pre-vote reviews will assess collateral structure, liquidity, oracle construction, borrower behavior, liquidation assumptions, LLAMMA parameters, and failure modes, concluding with recommended parameters and launch conditions.

Active-market monitoring will cover debt and utilization, borrower and collateral concentration, oracle health, executable exit liquidity, time and depth in soft liquidation, solvency, bad-debt formation, recoverability, and abnormal activity. A position-level explorer will allow material risk to be traced from a system-level signal to the affected market and borrowers.

This will be genuine public infrastructure, not a private analyst terminal repackaged as a report. Tulipa will build clear market and position visualizations, tools for users to monitor their own LlamaLend positions, and documented public APIs for community developers. The same operating evidence should be useful to borrowers, suppliers, delegates, researchers, and independent builders.

The v1-to-v2 transition will be a named workstream. Tulipa will maintain parallel coverage while both versions are active, track migration and deprecation risks, assess v2 readiness, develop borrow-cap and exposure-limit recommendations, and validate the resulting state after migrations or governance changes.

3.3 Contagion mapping

Curve’s risk perimeter extends beyond its contracts. Tulipa will maintain a living contagion map connecting markets to underlying assets, issuers, protocol teams, major holders, liquidity venues, oracle paths, treasury and team wallets, and material external positions. It will flag unusual wallet movements, concentration changes, large position adjustments, suspicious fund flows, and activity that may indicate stress or conflicts.

Tulipa has a licensed private investigator who specializes in crypto-fraud investigations and DeFi due diligence. The work combines wallet and transaction-flow analysis, Chainalysis tooling, source-of-funds and conflict review, and OSINT background checks. The investigator identified multiple projects as high risk before they proved fraudulent; in one rapid-response case, the work contributed to recovering more than $2 million for creditors.

The map will combine that capability with direct contact channels Tulipa maintains with all teams represented across the Curve ecosystem. Onchain signals can then be checked against asset conditions, protocol operations, and team context before escalation. Wallet movement will not itself be treated as wrongdoing; claims will be separated from hypotheses and documented with evidence and confidence.

3.4 Shared monitoring layers

The monitoring stack will connect the following surfaces across both core scopes:

  1. crvUSD and PegKeepers: peg conditions, market debt, defense capacity, collateral, reserves, ceilings, credit lines, and monetary-policy state.

  2. LlamaLend health: utilization, concentration, soft liquidation, executable liquidity, solvency, bad debt, and v1/v2 status.

  3. Oracle divergence: comparison of the feeds used by covered markets with independent sources, including deviation, latency, stale updates, and stressed-liquidity or manipulation patterns.

  4. Bad-debt tracking: position-, market-, and system-level insolvency, accrual, affected collateral, recoverability, and recovery events.

  5. Credit-Line monitoring: YieldBasis credit-line exposure, flows, LP position health, concentration, unwind capacity, and stress transmission into crvUSD.

  6. Alerts and escalation: validated critical, warning, and informational alerts routed through agreed private channels, with appropriate public follow-up.

Supporting watches will maintain a versioned history of material contract and parameter changes, and will monitor relevant issuer and protocol treasury wallets for any movements that could affect collateral quality, liquidity, or peg risk.

3.5 Risk-adjusted market economics

Tulipa will maintain a recurring risk-economics assessment for each market, comparing realized or attributable DAO revenue with loss exposure. Inputs will include market size, concentration, collateral behavior, oracle dependencies, liquidation performance, executable liquidity, historical stress, and market-specific failure modes.

Thin historical data cannot produce one exact probability of default. Where evidence supports a bounded estimate, we will publish a range and assumptions; otherwise, we will classify the uncertainty and identify what would change the recommendation.

Each assessment will produce one of five governance-relevant outcomes:

  • Maintain: economics and controls remain proportionate to the measured risk.

  • Reprice: fees, rates, discounts, or other terms do not adequately compensate for risk.

  • Reduce: the market remains useful, but its ceiling, cap, or concentration should be smaller.

  • Pause: new exposure should stop while an identified condition is investigated or remediated.

  • Exit: the DAO is not adequately compensated or the risk cannot be controlled within defensible parameters.

The first methodology and market table will be delivered in Months 2–3. Every active assessment will be refreshed at least every 90 days and published quarterly. The portfolio view will aggregate exposure across crvUSD issuance channels without hiding the different mechanics underneath them.

3.6 Governance, optional responsibilities, and boundaries

Every in-scope proposal will enter a tracked queue. Approved recommendations will become governance-ready posts and, after an agreed ramp-up, simulated executable payloads for independent review. Tulipa will verify the resulting onchain state.

Where a material risk turns on off-chain facts, such as issuer counterparties, team conduct, treasury movements, or an incident’s origin, Tulipa will incorporate targeted investigation into the relevant assessment or escalation at no additional charge.

All optional RFP areas are included behind core coverage: gauge reviews and efficiency analysis; pool-parameter recommendations; risk-focused asset pre-screening; and public dashboards, frontend indicators, yield-source breakdowns, and user disclosures. Business-development support is limited to two asset pre-screens per month unless scope expands.

Tulipa’s role is advisory. We will hold no protocol keys and perform no automated or discretionary onchain execution. Legal opinions are outside scope; reviews will flag legal-dimension issues for counsel selected by the DAO. When optional work competes with monitoring, incident response, or required assessments, core service levels take priority.

4. Operating Model

The operating loop is straightforward: monitor, validate, recommend, escalate, support the response, and verify the result.

Automated systems will handle continuous detection, enrichment, and prioritization. A human operator will validate material alerts before escalation. When a signal may cross markets or depend on off-chain facts, the workflow will add contagion-map context: connected wallets and positions, underlying-asset dependencies, relevant flows, and direct checks with ecosystem teams. Tulipa’s investigator will support validation where fraud indicators, source-of-funds questions, or counterparties are material. Primary and backup coverage will prevent the response process from depending on one individual. As the mandate and operating load grow, Tulipa will expand capacity rather than dilute the agreed service levels.

In Month 1, Tulipa and relevant Curve contributors will agree on the severity taxonomy, alert recipients, private escalation channels, and an incident response manual. Critical alerts will be validated and routed under 30 minutes of Tulipa’s monitoring system generating the alert. Warnings will be reviewed and communicated under two hours. Each escalation will include the affected market, timestamp, evidence, severity, exposed positions or mechanisms, contagion-map context where relevant, recommended next action, and the responsible DAO or eDAO decision-maker.

Tulipa will remain engaged through the response, update the recommendation as evidence changes, and verify the resulting onchain state. A significant incident will receive an initial report under two hours of confirmation and a full report under 72 hours, covering the timeline, detection, response, impact, known causes, and follow-up work.

Daily coordination will run through a Telegram group with relevant Curve contributors. A weekly working session with Swiss Stake and other designated contributors will review open recommendations, upcoming votes, new markets, incidents, launches, and migrations. Public questions in the proposal thread will receive a substantive response within two business days, with regular office hours for community review.

Curve first-party data and contributor infrastructure will be used where reliable. Critical values will be cross-checked through public RPCs and third-party sources. Backend access will accelerate implementation but is not a prerequisite. Gaps affecting coverage or confidence will be disclosed with their cause, impact, and remediation plan.

5. Deliverables, KPIs, and Reporting

Tulipa will publish a biweekly risk bulletin, a monthly deep dive by the fifth business day, quarterly risk-economics tables, biannual crvUSD market-health updates, and the incident reports described above. Recommendations arising from a threshold breach will be issued when action is required rather than held for a scheduled report.

The public KPI ledger will make the mandate auditable. It will record:

KPI Commitment
Pre-vote coverage 99% of in-scope proposals reviewed before vote close where timing and complete inputs allow
Active-market coverage 99% of active in-scope markets, including small markets with nonzero debt
Critical response Validated and routed under 30 minutes of alert generation
Warning response Reviewed and communicated under two hours of alert generation
Initial incident report Issued under two hours of confirming a significant incident
Full incident report Issued under 72 hours of confirming a significant incident
Reporting Biweekly, monthly, quarterly, biannual, and incident commitments tracked publicly
Reusable assets Dashboards, monitors, schemas, methods, documentation, and runbooks tracked as delivery milestones

Every recommendation will remain open until implemented, rejected, superseded, or accepted as residual risk. Significant incidents will review monitoring performance. Numeric detection benchmarks will be set after the Month-3 operating baseline; setting them before observing production data would create marketing guarantees rather than accountable KPIs.

By approximately Month 3, Tulipa will also publish a draft DAO risk-appetite framework and facilitate community review. Ratification remains the DAO’s decision, but the framework will give later parameter recommendations a consistent policy reference.

6. Commercial Terms

Tulipa requests $1,000,000 for a 12-month mandate, structured as two cancellable six-month terms with two months’ notice.

A $150,000 upfront mobilization payment, paid in crvUSD, is due upon approval and is credited toward the $1,000,000 annual fee. The remaining $850,000 will be paid in four quarterly installments of $212,500: $137,500 in crvUSD and $75,000 in CRV tokens per quarter. Across those quarterly payments, this is $550,000 in crvUSD and $300,000 in CRV tokens; including mobilization, the annual mix is $700,000 in crvUSD and $300,000 in CRV.

The fee is all-inclusive for the defined scope. It covers monitoring and on-call operations, reviews and parameter work, risk-economics assessments, incident response, governance and reporting, the Month-2 handoff assessment, Curve-specific tooling and documentation, data infrastructure, and the phased optional responsibilities. Material additions beyond the defined scope will be discussed at a six-month term boundary rather than absorbed through ambiguous commitments. All products built for Curve while Tulipa Capital is under contract will remain under the control of the DAO.

7. Roadmap and Continuity

Month 1: Handoff review and operational setup

Tulipa will begin with the task required by the RFP: review inherited LlamaRisk materials, reports, simulations, models, dashboards, and repositories. Each item will receive a reuse, deprecate, or rebuild classification, with its dependencies, access requirements, and operating condition documented. Month 1 will also establish the monitored-market inventory, critical dependency map, data access, severity taxonomy, escalation runbook, alert recipients, coordination channels, and implementation order. The goal is to understand and organize the full inherited environment before representing new infrastructure as delivered.

Months 2-3: Core monitoring and operating baseline

By early Month 2, Tulipa will have integrated the reusable inherited infrastructure into the active operating environment and begun building the Tulipa monitoring stack on top of it.

During Months 2-3, selected inherited services will continue operating while Tulipa assumes full ownership of the governance workflow including proposal reviews, recommendations, execution follow-through, and state verification. Alert thresholds will be calibrated against live data, and the first wave of public dashboards and tools will be released. These will prioritize system dependency and contagion maps, market-health views, position-level LlamaLend coverage, and initial public data access.

At the same time, the standardized pre-vote template, risk-economics table, public KPI baseline, recommendation register, monthly deep-dive reports, and full weekly cadence will be in operation. Scenario analysis work will begin once the core monitoring pipeline is stable.

Months 4-6: Migration and proactive risk work

The v1-to-v2 workstream will move into focus: parallel monitoring, migration-risk tracking, v2 readiness, exposure-limit methodology, and post-migration validation. Tulipa will deliver the first historical-replay scenarios, move recurring parameter optimization into operation, and publish a bad-debt policy framework addressing recognition, reserving, recoverability, and socialization-versus-treasury questions. By the end of this phase, the first measurable evidence of the mandate’s value should be visible in public: completed recommendations, improved parameters, investigated risk signals, governance outcomes, operating service levels, and adoption of the community-facing tools.

At six months, a live handoff drill will show that Curve contributors can access and understand the operating assets, data paths, alerts, documentation, and runbooks. The DAO can evaluate term 2 against recorded performance.

Term 2: Public goods and model development

Subject to continuation and maintenance of core service levels, term 2 will develop the operating base into an integrated public risk platform: multiple community tools, position monitoring, public APIs, accessible visualizations, contagion mapping, gauge and emissions analysis, frontend risk indicators, and model-based scenarios. The result should be a system that contributors and users can interrogate directly, built on the evidence and workflows proven during the first term.

Tulipa will maintain a written succession procedure. Curve should be able to review what was built, test the handoff, and replace the provider without losing the risk record or operating context.

Conclusion

Curve’s central challenge is clear: Can the DAO accurately see the risks it is taking, properly assess whether those risks are sufficiently rewarded, detect deterioration while options still remain, and ensure high-quality recommendations translate into timely, documented decisions?

Tulipa is prepared to operate this full process across both core scope areas. With our own capital directly exposed to the same risks and decisions, we will bring rigorous discipline, transparency, and accountability to Curve. We will make the work professional, measurable, and fully visible to the community, all while leaving every policy and execution decision exactly where it belongs: with the Curve DAO and eDAO.

@strky Replying here for consistency,

As a part of Tulipa’s prospective mandate to the DAO, we will continue to monitor and evaluate the legacy bad debt in the ecosystem. Tulipa is unable to take direct action on the debt but will make recommendations and simulations for the DAO, looking to resolve the situation and find the best path forward.

1 Like

For our follow up to the Swiss Stake analysis, Tulipa would like to make public the questions and answers that we were asked by Swiss Stake and provide our answers.

1. Can Tulipa offer a leaner version focused on core risk work?

We can separate the mandate into a $700,000 core package and five optional modules. The lean package uses the same scope and internal allocation presented in the original proposal.

Internal allocation of the original $1 million fee

Service line Total Core risk work Optional work
Monitoring and 24/7 on-call $275,000 $245,000 $30,000 for community bots and indicator feeds
Reviews, parameters, economics, and scenarios $250,000 $185,000 $45,000 for gauges and pool parameters; $20,000 for investigative diligence
Incident response $100,000 $70,000 $30,000 for incident forensics
Reporting and governance $100,000 $55,000 $45,000 for BD support
DAO tooling, documentation, and KPI ledger $125,000 $45,000 $80,000 for public dashboards, APIs, and builder tools
Infrastructure, data, and integration $150,000 $100,000 $50,000 for public data serving, APIs, and bots
Total $1,000,000 $700,000 $300,000

Optional modules

Each optional module runs on the core data and monitoring foundation.

Module Included work Annual price
Dashboards Six products: Contagion Graph, Oracle Observatory, Position Explorer, Market Economics, Gauge and Emissions, and LlamaLend/earn/APR $90,000
User tools DAO-branded alert bots, frontend risk indicators, position disclosures, a public read API, and a community dashboard builder $70,000
Investigations Counterparty and issuer diligence plus incident forensics, engaged when triggered $50,000
Gauges and pool parameters Gauge proposal reviews, identification of stale or extractive gauges, CRV emissions analysis, and pool parameter recommendations $45,000
BD support Up to two asset pre-screens per month, risk-screened opportunities, and contact with relevant asset and protocol teams $45,000

Available configurations

We view this engagement as the start of a long-term partnership with Curve. To reflect that, Tulipa will discount both configurations by 10% for the initial term.

Configuration Included work Initial-term fee Payment mix
Core Core risk mandate $630,000, discounted from $700,000 $472,500 crvUSD and $157,500 CRV
Core plus Risk Tooling and Investigations Core package, six public dashboards, and triggered investigations $750,000, discounted from $840,000 $562,000 crvUSD and $187,500 CRV

Our Recommendation

We recommend the Core plus Risk Tooling and Investigations package at the discounted initial-term fee of $750,000. Its public tools, including the Contagion Graph, will be vital to how Curve monitors interconnected risk as the protocol grows. We believe this package gives Curve the strongest foundation for a durable, long-term risk function.

2. Who would work on Curve, what would each person do, and how much time would they commit?

Contributor Responsibilities Commitment
Mandate Lead Leads the mandate end to end: monitoring stack, assessment methodology, review and escalation sign-off, weekly Swiss Stake session. VP of Engineering at Tulipa; previously high-frequency trading infrastructure in Rust; cybersecurity professor and Web3 security educator with 1,500+ alumni. 1.0 FTE
Senior Engineer, planned addition Second engineer on the monitoring stack and alert pipeline, joining at award from one of DeFi’s largest protocols; five years of systems engineering at Intel, crypto-native since 2018. Identity disclosed privately via Swiss Stake before any payment flows. Planned: 1.0 FTE
Quantitative Analyst, planned addition Supports risk modeling and market analytics. Planned: 1.0 FTE
Vault Strategy Leads per-market fee and yield analysis, revenue-sustainability scoring, risk-economics assessment inputs, and LlamaLend, earn, and APR coverage. DeFi Vault Strategist at Tulipa. 0.8 FTE
Vault Strategy Risk market management and mint/redeem functions of crvUSD and LlamaLend; eight years of prior experience in banking focused primarily on business performance and analysis. 0.5 FTE
Founder Partner and ecosystem relations, mandate oversight. Tulipa founder; co-founder and former CFO of ARK Ecosystem; led Protokol as CEO for six years. Extra weight during the first months. 0.2 FTE
Chief Investment Officer Advises on asset and issuer quality and ecosystem relations. Four years of DeFi BD, formerly at Gearbox; now CEO of Syntetika, where Tulipa is a strategic partner. Advisor
Private Investigator Supports protocol dependency mapping, issuer diligence, AML review, onchain tracing, and incident forensics using Chainalysis and OSINT. 0.5 FTE

At start, core staffing would total 4 FTE and increase to 5 FTE after the quantitative analyst joins.

Automation handles alert triage, governance-proposal intake, investigation legwork, and report drafting. It runs on Tulipa’s own in-house LLM infrastructure rather than third-party APIs. This means every alert and proposal gets processed, not sampled; coverage is never limited by outside rate limits or per-query costs; and sensitive material never leaves Tulipa’s systems. Every validation, recommendation, and escalation remains a human decision.

Coverage is 24/7. Automated detection and prioritization run around the clock, and the validation rotation provides primary and backup on-call coverage at all hours, so no escalation depends on one person. Named alert recipients, escalation contacts, and severity owners will be agreed with the eDAO and Swiss Stake in Month 1.

3. What comparable risk-provider work has the proposed team completed?

Our record is primarily operational. We have managed risk for our own capital and third-party capital for six years.

Tulipa’s proprietary record

The strategies that became Tulipa have operated across BTC, ETH, stablecoins, and major DeFi protocols since 2020. Across that period, the portfolio has realized two losses, both disclosed: Euler v1 and Maple v1. The combined loss was under 0.01% of portfolio capital, which equated to ~2 weeks of yield allowing the quarter to still end positive.

This does not mean the process prevents every loss. It shows a six-year operating record through multiple DeFi market cycles, with losses identified rather than omitted.

Managed vaults

Since the public launch in 2024, Tulipa vaults have reached peak AUM of approximately $500 million. Current AUM is $43 million across vaults on Lagoon and Ember.

RockSolid

Tulipa is the main curator for RockSolid, supporting the protocol across strategy, risk, and market coverage on an ongoing basis. This work requires continuing risk review rather than a one-time report.

  • Official Mandate: RockSolid’s rETH Vault maximizes rETH-based returns by allocating it across DeFi protocols like AAVE and Morpho. Our asset manager constantly monitors funding rates and DeFi opportunities to ensure maximum performance. Additionally, rETH deposits are used to negotiate new deals for depositors. The vault may deploy assets across mainnet and L2s. An allocation towards to rETH looping is kept whenever funding rates are positive.

Kelp Gain

Tulipa ran Kelp Gain from August 2024 through August 2025. The strategy reached peak AUM of $250 million and recorded no losses.

Giddy YieldBasis Vault Incident

On April 23, 2026, Tulipa detected an incident involving a vault from Giddy DeFi that had YieldBasis as a part of its strategy. It was not an attack on YieldBasis contracts. Tulipa alerted the YieldBasis team, identified a custom contract draining approximately $1.25 million of wrapped BTC from three individual vaults, confirmed that YieldBasis core contracts were unaffected, and published a public notice.

4. How often does the system check the data, and how long could an onchain event take to reach a human?

All risk-relevant data is tracked block by block. When a transaction lands onchain, it is processed by our system at max within two minutes. Critical alerts are answered by a human within a maximum of 30 minutes after the notification, the reference point is transaction confirmation plus two minutes, so the worst case from onchain inclusion to a validated human response is 32 minutes. The 30 minutes is a ceiling, not a target.

The public KPI ledger will record the trigger time, page time, and escalation time for each critical alert, so the DAO can verify actual response times, including the median, against these bounds.

5. How would Tulipa handle conflicts involving its Curve and YieldBasis positions?

Tulipa does not believe its Curve or YieldBasis positions create a conflict of interest. Tulipa, its LPs, Curve, and YieldBasis all benefit from the same long-term outcome: healthy markets, sustainable liquidity, and continued protocol growth.

Where returns conflict with the health or growth of a position or pool, Tulipa will prioritize long-term safety and sustainable growth. Recommendations will favor sound parameters over yield that creates avoidable risk and drives growth.

Tulipa will make recommendations using the same data, methodology, and risk standards applied across the mandate. We will state when Tulipa has relevant economic exposure but will not disclose specific positions or position sizes. Each recommendation will explain the expected impact on Curve DAO, the protocol, and LPs.