1. Summary
Curve does not need another dashboard or periodic risk report. It needs an operating risk function: continuous monitoring, human validation, clear recommendations, and direct involvement until an issue is resolved or the DAO knowingly accepts the remaining risk.
Tulipa will apply the discipline that governs our proprietary and managed capital: deciding where capital belongs, when exposure should be reduced, and when an opportunity should be rejected. Every policy and execution decision remains with the Curve DAO and eDAO. Tulipa Capital will build tools for Curve that Curve will keep. Anything that is created in the scope of the project, the Curve team and DAO will own in perpetuity.
The mandate must answer two related questions.
First, is Curve taking the right risk-adjusted approach? Tulipa will maintain a recurring risk-economics assessment for every in-scope market. It will compare the value earned by the DAO with the risk carried through collateral, liquidity, borrower concentration, oracle design, liquidation capacity, and market-specific failure modes. The output will be a clear recommendation: maintain, reprice, reduce, pause, or exit. We will also maintain a portfolio-level view across crvUSD mint markets, PegKeepers, and DAO credit lines so that governance can evaluate both individual markets and the aggregate balance sheet.
Second, are those risks being monitored properly? Tulipa will operate continuous coverage across crvUSD, PegKeepers, LlamaLend, oracle dependencies, bad debt, YieldBasis flows, and material configuration changes. Every active in-scope market will be covered, including smaller markets with nonzero debt. Critical conditions will be validated and routed within 30 minutes of alert generation; warnings will be reviewed and communicated within two hours. A public, timestamped KPI ledger will record coverage, interruptions, alerts, response times, recommendations, unresolved issues, and disclosed gaps.
Tulipa will also make the evidence usable. Raw data without clear presentation is difficult to interpret, compare, or convert into timely decisions. We will therefore serve Curve’s risk data through accessible visualizations, decision-focused summaries, user tools, and public interfaces that help governance and the wider community find the signal, understand its significance, and act on it.
Tulipa proposes a full-service model covering both core RFP areas and the optional responsibilities described below.
Proposal MVP and Detailed Approach
Tulipa has built a working MVP to establish the operating approach described in this proposal and make the proposed monitoring model concrete. The site includes an interactive market map, supporting tools, and a more detailed explanation of our approach: Explore the Tulipa Curve Risk MVP and detailed proposal.
2. Who We Are and Why We Are Aligned
Tulipa Capital is a DeFi-native asset manager whose risk process exists because our own capital depends on it. The proprietary fund that became Tulipa began operating in 2020; Tulipa launched publicly in 2024. As of July 2026, Tulipa manages approximately $100-110 million in proprietary capital and $43 million across managed vaults. A six-person team works across portfolio management, risk research, monitoring engineering, onchain data, quantitative analysis, and governance communication, with capacity expected to expand.
Our process covers pre-deployment review, live monitoring, exposure management, and incident response. We assess protocols, contracts, counterparties, liquidity, market structure, and exit capacity; automated systems then monitor transactions, rates, utilization, oracles, governance, and abnormal activity. Human operators evaluate material signals and decide whether exposure or escalation is required.
That principal-risk perspective matters. A technically correct report can still miss the operational question: what can be sold, repaid, paused, or changed before deterioration becomes an irreversible loss? Tulipa approaches risk as an operator responsible for capital.
Our alignment with Curve is already economic. Tulipa has capital deployed across the Curve ecosystem and is one of YieldBasis’s largest LPs. Our exposure means that the health of YieldBasis, crvUSD, and the surrounding liquidity system affects our own balance sheet.
We will disclose that position plainly as evidence of alignment, not as a reason to conceal or soften risk. YieldBasis recommendations will use the same documented evidence, thresholds, and public methodology applied elsewhere, while the DAO and eDAO retain the final decision.
That alignment has already produced action. On April 23, while monitoring our exposure, Tulipa identified unusual onchain activity involving YieldBasis contracts and alerted the team within minutes. Our review determined that an attacker had used a custom contract to claim fees and drain approximately $1.25 million of wrapped BTC from three individual vaults while the core protocol contracts remained unaffected. Tulipa had no paid monitoring mandate and no commercial arrangement requiring us to investigate or publish. Our own capital was exposed, so we acted.
This proposal formalizes and extends an operating capability Tulipa already uses when its own capital is at risk.
3. Scope: What Curve Gets
Tulipa will cover both core RFP areas: crvUSD mint-market risk, and LlamaLend isolated-market risk, through one connected system organized around the decisions Curve must make.
Tulipa is creating refined monitoring to produce refined results and public tooling. Detailed data and validated signals will be translated into accessible visualizations, position-level tools, and public interfaces so that better monitoring improves both DAO decisions and the community’s ability to understand and use the underlying evidence.
3.1 crvUSD, mint markets, PegKeepers, and credit lines
For every proposed mint market and PegKeeper pool, Tulipa will publish a pre-vote review covering collateral quality, executable liquidity, oracle design, concentration, LLAMMA behavior, and failure modes. Each review will conclude with recommended launch parameters, approval conditions, remediation, and whether the market can plausibly earn enough value for the risk it adds.
For active markets, monitoring will cover debt, ceiling utilization, collateral deterioration, liquidity, oracle behavior, soft-liquidation conditions, borrower concentration, bad debt, and abnormal activity. PegKeeper coverage will include pool composition, available defense capacity, caps, inventory, utilization, and evidence of whether each keeper is contributing to peg defense under actual market conditions.
DAO credit lines, including YieldBasis, will enter the same portfolio view, covering authorized and drawn exposure, collateral coverage, material flows, concentration, unwind paths, emergency controls, and potential transmission into crvUSD liquidity or peg performance.
The crvUSD view will show where pressure is building, which mechanism is absorbing it, what capacity remains, and what intervention is available. Thresholds will be published as recommendation triggers. They will inform human decisions and will not execute parameter changes automatically.
3.2 LlamaLend isolated markets
Tulipa will cover every active LlamaLend market and its critical LLAMMA infrastructure across v1 and v2. Mint markets and isolated lending markets will remain separate in calculations and reporting because their economics, loss paths, and responsible parties differ.
Pre-vote reviews will assess collateral structure, liquidity, oracle construction, borrower behavior, liquidation assumptions, LLAMMA parameters, and failure modes, concluding with recommended parameters and launch conditions.
Active-market monitoring will cover debt and utilization, borrower and collateral concentration, oracle health, executable exit liquidity, time and depth in soft liquidation, solvency, bad-debt formation, recoverability, and abnormal activity. A position-level explorer will allow material risk to be traced from a system-level signal to the affected market and borrowers.
This will be genuine public infrastructure, not a private analyst terminal repackaged as a report. Tulipa will build clear market and position visualizations, tools for users to monitor their own LlamaLend positions, and documented public APIs for community developers. The same operating evidence should be useful to borrowers, suppliers, delegates, researchers, and independent builders.
The v1-to-v2 transition will be a named workstream. Tulipa will maintain parallel coverage while both versions are active, track migration and deprecation risks, assess v2 readiness, develop borrow-cap and exposure-limit recommendations, and validate the resulting state after migrations or governance changes.
3.3 Contagion mapping
Curve’s risk perimeter extends beyond its contracts. Tulipa will maintain a living contagion map connecting markets to underlying assets, issuers, protocol teams, major holders, liquidity venues, oracle paths, treasury and team wallets, and material external positions. It will flag unusual wallet movements, concentration changes, large position adjustments, suspicious fund flows, and activity that may indicate stress or conflicts.
Tulipa has a licensed private investigator who specializes in crypto-fraud investigations and DeFi due diligence. The work combines wallet and transaction-flow analysis, Chainalysis tooling, source-of-funds and conflict review, and OSINT background checks. The investigator identified multiple projects as high risk before they proved fraudulent; in one rapid-response case, the work contributed to recovering more than $2 million for creditors.
The map will combine that capability with direct contact channels Tulipa maintains with all teams represented across the Curve ecosystem. Onchain signals can then be checked against asset conditions, protocol operations, and team context before escalation. Wallet movement will not itself be treated as wrongdoing; claims will be separated from hypotheses and documented with evidence and confidence.
3.4 Shared monitoring layers
The monitoring stack will connect the following surfaces across both core scopes:
-
crvUSD and PegKeepers: peg conditions, market debt, defense capacity, collateral, reserves, ceilings, credit lines, and monetary-policy state.
-
LlamaLend health: utilization, concentration, soft liquidation, executable liquidity, solvency, bad debt, and v1/v2 status.
-
Oracle divergence: comparison of the feeds used by covered markets with independent sources, including deviation, latency, stale updates, and stressed-liquidity or manipulation patterns.
-
Bad-debt tracking: position-, market-, and system-level insolvency, accrual, affected collateral, recoverability, and recovery events.
-
Credit-Line monitoring: YieldBasis credit-line exposure, flows, LP position health, concentration, unwind capacity, and stress transmission into crvUSD.
-
Alerts and escalation: validated critical, warning, and informational alerts routed through agreed private channels, with appropriate public follow-up.
Supporting watches will maintain a versioned history of material contract and parameter changes, and will monitor relevant issuer and protocol treasury wallets for any movements that could affect collateral quality, liquidity, or peg risk.
3.5 Risk-adjusted market economics
Tulipa will maintain a recurring risk-economics assessment for each market, comparing realized or attributable DAO revenue with loss exposure. Inputs will include market size, concentration, collateral behavior, oracle dependencies, liquidation performance, executable liquidity, historical stress, and market-specific failure modes.
Thin historical data cannot produce one exact probability of default. Where evidence supports a bounded estimate, we will publish a range and assumptions; otherwise, we will classify the uncertainty and identify what would change the recommendation.
Each assessment will produce one of five governance-relevant outcomes:
-
Maintain: economics and controls remain proportionate to the measured risk.
-
Reprice: fees, rates, discounts, or other terms do not adequately compensate for risk.
-
Reduce: the market remains useful, but its ceiling, cap, or concentration should be smaller.
-
Pause: new exposure should stop while an identified condition is investigated or remediated.
-
Exit: the DAO is not adequately compensated or the risk cannot be controlled within defensible parameters.
The first methodology and market table will be delivered in Months 2–3. Every active assessment will be refreshed at least every 90 days and published quarterly. The portfolio view will aggregate exposure across crvUSD issuance channels without hiding the different mechanics underneath them.
3.6 Governance, optional responsibilities, and boundaries
Every in-scope proposal will enter a tracked queue. Approved recommendations will become governance-ready posts and, after an agreed ramp-up, simulated executable payloads for independent review. Tulipa will verify the resulting onchain state.
Where a material risk turns on off-chain facts, such as issuer counterparties, team conduct, treasury movements, or an incident’s origin, Tulipa will incorporate targeted investigation into the relevant assessment or escalation at no additional charge.
All optional RFP areas are included behind core coverage: gauge reviews and efficiency analysis; pool-parameter recommendations; risk-focused asset pre-screening; and public dashboards, frontend indicators, yield-source breakdowns, and user disclosures. Business-development support is limited to two asset pre-screens per month unless scope expands.
Tulipa’s role is advisory. We will hold no protocol keys and perform no automated or discretionary onchain execution. Legal opinions are outside scope; reviews will flag legal-dimension issues for counsel selected by the DAO. When optional work competes with monitoring, incident response, or required assessments, core service levels take priority.
4. Operating Model
The operating loop is straightforward: monitor, validate, recommend, escalate, support the response, and verify the result.
Automated systems will handle continuous detection, enrichment, and prioritization. A human operator will validate material alerts before escalation. When a signal may cross markets or depend on off-chain facts, the workflow will add contagion-map context: connected wallets and positions, underlying-asset dependencies, relevant flows, and direct checks with ecosystem teams. Tulipa’s investigator will support validation where fraud indicators, source-of-funds questions, or counterparties are material. Primary and backup coverage will prevent the response process from depending on one individual. As the mandate and operating load grow, Tulipa will expand capacity rather than dilute the agreed service levels.
In Month 1, Tulipa and relevant Curve contributors will agree on the severity taxonomy, alert recipients, private escalation channels, and an incident response manual. Critical alerts will be validated and routed under 30 minutes of Tulipa’s monitoring system generating the alert. Warnings will be reviewed and communicated under two hours. Each escalation will include the affected market, timestamp, evidence, severity, exposed positions or mechanisms, contagion-map context where relevant, recommended next action, and the responsible DAO or eDAO decision-maker.
Tulipa will remain engaged through the response, update the recommendation as evidence changes, and verify the resulting onchain state. A significant incident will receive an initial report under two hours of confirmation and a full report under 72 hours, covering the timeline, detection, response, impact, known causes, and follow-up work.
Daily coordination will run through a Telegram group with relevant Curve contributors. A weekly working session with Swiss Stake and other designated contributors will review open recommendations, upcoming votes, new markets, incidents, launches, and migrations. Public questions in the proposal thread will receive a substantive response within two business days, with regular office hours for community review.
Curve first-party data and contributor infrastructure will be used where reliable. Critical values will be cross-checked through public RPCs and third-party sources. Backend access will accelerate implementation but is not a prerequisite. Gaps affecting coverage or confidence will be disclosed with their cause, impact, and remediation plan.
5. Deliverables, KPIs, and Reporting
Tulipa will publish a biweekly risk bulletin, a monthly deep dive by the fifth business day, quarterly risk-economics tables, biannual crvUSD market-health updates, and the incident reports described above. Recommendations arising from a threshold breach will be issued when action is required rather than held for a scheduled report.
The public KPI ledger will make the mandate auditable. It will record:
| KPI | Commitment |
|---|---|
| Pre-vote coverage | 99% of in-scope proposals reviewed before vote close where timing and complete inputs allow |
| Active-market coverage | 99% of active in-scope markets, including small markets with nonzero debt |
| Critical response | Validated and routed under 30 minutes of alert generation |
| Warning response | Reviewed and communicated under two hours of alert generation |
| Initial incident report | Issued under two hours of confirming a significant incident |
| Full incident report | Issued under 72 hours of confirming a significant incident |
| Reporting | Biweekly, monthly, quarterly, biannual, and incident commitments tracked publicly |
| Reusable assets | Dashboards, monitors, schemas, methods, documentation, and runbooks tracked as delivery milestones |
Every recommendation will remain open until implemented, rejected, superseded, or accepted as residual risk. Significant incidents will review monitoring performance. Numeric detection benchmarks will be set after the Month-3 operating baseline; setting them before observing production data would create marketing guarantees rather than accountable KPIs.
By approximately Month 3, Tulipa will also publish a draft DAO risk-appetite framework and facilitate community review. Ratification remains the DAO’s decision, but the framework will give later parameter recommendations a consistent policy reference.
6. Commercial Terms
Tulipa requests $1,000,000 for a 12-month mandate, structured as two cancellable six-month terms with two months’ notice.
A $150,000 upfront mobilization payment, paid in crvUSD, is due upon approval and is credited toward the $1,000,000 annual fee. The remaining $850,000 will be paid in four quarterly installments of $212,500: $137,500 in crvUSD and $75,000 in CRV tokens per quarter. Across those quarterly payments, this is $550,000 in crvUSD and $300,000 in CRV tokens; including mobilization, the annual mix is $700,000 in crvUSD and $300,000 in CRV.
The fee is all-inclusive for the defined scope. It covers monitoring and on-call operations, reviews and parameter work, risk-economics assessments, incident response, governance and reporting, the Month-2 handoff assessment, Curve-specific tooling and documentation, data infrastructure, and the phased optional responsibilities. Material additions beyond the defined scope will be discussed at a six-month term boundary rather than absorbed through ambiguous commitments. All products built for Curve while Tulipa Capital is under contract will remain under the control of the DAO.
7. Roadmap and Continuity
Month 1: Handoff review and operational setup
Tulipa will begin with the task required by the RFP: review inherited LlamaRisk materials, reports, simulations, models, dashboards, and repositories. Each item will receive a reuse, deprecate, or rebuild classification, with its dependencies, access requirements, and operating condition documented. Month 1 will also establish the monitored-market inventory, critical dependency map, data access, severity taxonomy, escalation runbook, alert recipients, coordination channels, and implementation order. The goal is to understand and organize the full inherited environment before representing new infrastructure as delivered.
Months 2-3: Core monitoring and operating baseline
By early Month 2, Tulipa will have integrated the reusable inherited infrastructure into the active operating environment and begun building the Tulipa monitoring stack on top of it.
During Months 2-3, selected inherited services will continue operating while Tulipa assumes full ownership of the governance workflow including proposal reviews, recommendations, execution follow-through, and state verification. Alert thresholds will be calibrated against live data, and the first wave of public dashboards and tools will be released. These will prioritize system dependency and contagion maps, market-health views, position-level LlamaLend coverage, and initial public data access.
At the same time, the standardized pre-vote template, risk-economics table, public KPI baseline, recommendation register, monthly deep-dive reports, and full weekly cadence will be in operation. Scenario analysis work will begin once the core monitoring pipeline is stable.
Months 4-6: Migration and proactive risk work
The v1-to-v2 workstream will move into focus: parallel monitoring, migration-risk tracking, v2 readiness, exposure-limit methodology, and post-migration validation. Tulipa will deliver the first historical-replay scenarios, move recurring parameter optimization into operation, and publish a bad-debt policy framework addressing recognition, reserving, recoverability, and socialization-versus-treasury questions. By the end of this phase, the first measurable evidence of the mandate’s value should be visible in public: completed recommendations, improved parameters, investigated risk signals, governance outcomes, operating service levels, and adoption of the community-facing tools.
At six months, a live handoff drill will show that Curve contributors can access and understand the operating assets, data paths, alerts, documentation, and runbooks. The DAO can evaluate term 2 against recorded performance.
Term 2: Public goods and model development
Subject to continuation and maintenance of core service levels, term 2 will develop the operating base into an integrated public risk platform: multiple community tools, position monitoring, public APIs, accessible visualizations, contagion mapping, gauge and emissions analysis, frontend risk indicators, and model-based scenarios. The result should be a system that contributors and users can interrogate directly, built on the evidence and workflows proven during the first term.
Tulipa will maintain a written succession procedure. Curve should be able to review what was built, test the handoff, and replace the provider without losing the risk record or operating context.
Conclusion
Curve’s central challenge is clear: Can the DAO accurately see the risks it is taking, properly assess whether those risks are sufficiently rewarded, detect deterioration while options still remain, and ensure high-quality recommendations translate into timely, documented decisions?
Tulipa is prepared to operate this full process across both core scope areas. With our own capital directly exposed to the same risks and decisions, we will bring rigorous discipline, transparency, and accountability to Curve. We will make the work professional, measurable, and fully visible to the community, all while leaving every policy and execution decision exactly where it belongs: with the Curve DAO and eDAO.