Xerberus Proposal for Scope 2: Llamalend / Isolated Markets Risk (plus a systemic-risk layer for the whole Curve perimeter)

Submitted in response to the Call for Proposals: Curve Risk Assessment and Market Monitoring. All figures in this proposal and its attached documents were generated from public on-chain data by our production system. No privileged access. Every number is a rerunnable query. Xerberus terms of art are glossed at first use and collected in the glossary at the end.

TL;DR: We bid Scope 2 (Llamalend / isolated markets) plus a system-wide simulation layer for the whole Curve perimeter, awardable separately or together (§4). Before asking for anything, we pointed our production engine at Curve and attached one working sample of each service we’re bidding (the monitoring report, the parameter simulation, and the systemic alert), with four material findings (§2), including that the DAO’s largest single crvUSD exposure, the ~$265M drawn Yield Basis credit line, sits outside every monitoring surface today. Price: $100k per year, paid entirely in CRV, 100% locked as veCRV for four years (§5). Public checkpoint at month 3; the DAO can walk away at any point and keeps a runnable copy of everything (§6). Monitoring is live today and lands on the DAO’s own alert channel in week 1 (§3).


1. Who is Xerberus, and why the numbers below exist

Xerberus is a funded risk-analytics company building the risk-rating standard for crypto. Our production engine, V7, rebuilds every lending position, pool, wrapper, and oracle read directly from raw Ethereum events and traces (no third-party data feeds, no privileged access) across 21 protocols, roughly $37.5B of TVL and $26.9B of debt. Those 21 protocols are the same ones Curve’s collateral is rehypothecated into.

We have no history on this forum, and we know what that means in a decision like this one. So instead of describing what we could do for Curve, we did it: we reconstructed Curve’s entire crvUSD and Llamalend perimeter: every mint market, PegKeeper, and Llamalend market, including a wei-exact replay of LLAMMA’s collateral bands (1.2M band transitions anchored to genuine TokenExchange events, 164k in-transaction oracle reads). Everything below comes from that work.

2. The CFP asks one core question. Here is the measured answer.

“Is the Curve DAO taking the right risk-adjusted approach, and are those risks being monitored properly?”

Mostly yes: your core is sound. In four specific places, no, and each one is measured, not modelled.

Finding 1: Most of the Llamalend book cannot exit at the speed it might need to be liquidated.
79% of borrowed value sits in three markets (sreUSD, sfrxUSD, sUSDe) where a yield-bearing stablecoin is looped against another stablecoin at ~98% of max LTV. The safety margin on those loans is a 1.3–2.0% liquidation discount, but for markets like these the binding risk is not price volatility, it is exit capacity. The largest, sreUSD: $18.2M borrowed, against collateral of which only ~$2.1M can be sold in a single day without breaking the price (~$13.2M sellable in total across all venues). sUSDe’s only real exit is Ethena redemption, which sits behind a 7-day cooldown. A smaller market of the same type, fxSAVE, has already recorded a single day four times worse than the discount that is supposed to cover it.
What to do: cap stable-loop books at their measured daily exit capacity. Example 2 demonstrates the method on five live markets.

Finding 2: Llamalend v1 has cost its suppliers roughly $11.6M and earned the DAO $0.
This is the CFP’s compensation question answered literally. All v1 interest accrues to suppliers, and those same suppliers absorbed the realized losses, about $10.6M of it in the 2024 CRV market episodes. Example 1 closes the lifetime ledger in its section “Is Curve compensated for the risk?”.
What to do: this is the strongest empirical argument available for v2’s fee design, and for capping today’s stable-loop books until v2 lands.

Finding 3: The WBTC mint market’s safety margin has already been exceeded by its own history.
A market’s parameters should stand above the worst day that market has actually produced. WBTC’s loan discount is 9%; its worst measured day was a 24.6% single-day loss share (2026-02-03), contained only through a wave of 99 hard liquidations. Mint markets are Scope 1, but the instrument does not care which scope a market is in, so we surface it.
What to do: revisit the discount, or accept in writing that containment depends on hard-liquidation throughput.

Finding 4: The DAO’s largest single crvUSD exposure has no monitoring surface at all.
The Yield Basis credit line has roughly $265M drawn of $1,000M authorized, a ceiling raised from $60M to $1,000M within four months, executed on-chain rather than merely proposed (the three mint transactions sum to exactly 1,000M; receipts on request). That is about eight times all mint-market debt combined, and it sits outside every LLAMMA-era monitoring surface.
What to do: bring the credit line inside a monitoring perimeter, ours or anyone’s.

Where these numbers come from: one working sample of each service

Three attached documents. They are not marketing material: each is a working sample of a different service the DAO would be buying, generated on Curve’s live book (static captures from 2026-07-15; Example 3’s simulation recomputed 2026-07-19 on our calibrated cascade, as noted in its provenance). Treat each as a starting point, not a fixed format; the townhall and request-register loop in §3 exists precisely to reshape these deliverables into what the DAO actually needs.

  • Example 1, Curve Risk Monitor (view): the reporting service. This is what the semiannual market-health report and monthly digest could look like; the final shape is set with the DAO, not for it. As a starting point: every crvUSD mint market, PegKeeper, and Llamalend market reconstructed from raw Ethereum events, each with its worst measured day rather than an assumed one, ending in an 8-item action register where every item carries the measurement that justifies it. It also closes the revenue-versus-losses ledger behind Finding 2. And because the underlying surface rebuilds every window, under a mandate this report is not a twice-a-year event; it is available on demand.
  • Example 2, Five ceilings, five verdicts (view): the parameter-simulation service. The simulation engine run over parameter changes: one question against five live Curve markets: how big can this book get before a bad day produces more forced selling than its collateral’s exits can absorb? Two books are already past that line. Every pre-vote memo and ceiling recommendation in this proposal is produced exactly this way, and the DAO can rerun every number and dispute the assumptions rather than the arithmetic.
  • Example 3, Incident pack (simulated) (view): the alerting and escalation service. What lands in the DAO’s channel when a systemic event outside Curve threatens Curve: a USDe depeg of 15% run through our validated cascade engine on the real 2026-07-13 book: the automated alert at T+0, the Curve exposure read, the system-wide cascade context, and the escalation memo with recommended actions.

Verify us, don’t trust us

Self-generated evidence deserves suspicion, so three standing offers:

  • Delegate verification, before any award. Named delegates receive read-only access to rerun the headline numbers themselves: the sreUSD exit depth, the WBTC measured tail, the v1 loss ledger.
  • A backtest against 10 October 2025. The October 2025 crash was the hardest single day any DeFi monitoring system has recently had to survive, so we apply our own miss-accounting KPI to ourselves, retroactively: in Phase 0 we publish a replay of our current alert set against that day’s data: which alerts would have fired, at what time, and when the DAO would have received the written escalation, together with an itemized ledger of what that day cost Llamalend v1 suppliers. If our system would have missed it, the backtest will say so.
  • “Validated” should not be an adjective. Our cascade engine is validated against replayed historical crises (UST, the stETH discount, Euler, the 2023 Curve/Vyper reentrancy) and a 28-window historical stress backtest. We will publish the per-crisis error table (predicted versus realized losses and liquidations) at townhall #1.

Whether or not this proposal is selected, we hope the documents are useful to the DAO.

3. What the DAO gets, month to month

Coverage starts in week 1, not in a later phase: the monitoring shown in Example 1 is already running today, and the first deliverable is pointing it at a DAO-owned alert channel.

The machine layer, which runs regardless of anyone’s calendar:

  • Refresh of every in-scope market every 12 hours: positions, utilization, bad-debt exposure, collateral composition, oracle behaviour, exit depth versus book size, liquidation proximity. Twelve hours is the committed cadence; improvements ship when they are live, not when they are promised.
  • Standing automated alerts delivered to a DAO-owned Telegram or webhook channel: depeg, utilization, liquidation-spike, oracle-staleness, concentration, and contagion-index watch types. Three are already live on the Curve scope today, created while preparing this response; the DAO can keep or delete them. Every alert carries the timestamp of the state it read, so a T+0 alert never hides that its position snapshot can be up to one window old.
  • Scenario simulation on request and on schedule: custom shock baskets through the cascade engine, ceiling sweeps of the Example 2 kind, and pre-vote hypothetical books for proposed markets.
  • A public findings register: Example 1’s action list maintained as a living document, where every open risk item carries the measurement that justifies it, its status, and its resolution.

The human layer, which keeps the machine pointed at what Curve actually needs:

  • A monthly public townhall with the DAO. One to two hours, on the forum and/or the community call: here is what changed in your risk picture this month; here is what you asked us to monitor last month and what we shipped; what should we point the engine at next? Requests go into a public request register (requested / in review / shipped / declined with reasons).
  • Pre-vote risk memos for Scope 2 proposals (the Example 2 method), targeting delivery at least 3 business days before the vote where deployment addresses and configuration are disclosed at least 5 business days ahead.
  • Written escalations within 12 hours of a critical trigger (the Example 3 format), with a recommended action, logged publicly with the outcome. Twelve hours is what our live system supports today, so twelve hours is what we commit to. If the DAO wants a tighter tier after seeing us work, that is a scaling conversation, not a rebuild (§5, §7).

4. Scope: two modules, awardable separately or together

Module A (committed): Scope 2, Llamalend / isolated markets, plus LLAMMA-related infrastructure. Per the CFP’s responsibility list:

  • Collateral-risk and market-risk reports for new Llamalend markets before the DAO vote: collateral quality, backing trace to terminal assets, oracle dependencies, liquidity depth, liquidation assumptions, and market-specific failure modes.
  • Risk-driven parameter recommendations for new deployments, on the reproducible basis demonstrated in Example 2: safe-book ranges anchored to each market’s own measured tail, absorption measured from actual pool state.
  • Ongoing monitoring of all active lending markets (49 are already under reconstruction today) at the §3 cadence: utilization, liquidity health, oracle behaviour, bad-debt risk, solvency, and abnormal activity.
  • Parameter-change recommendations where conditions deteriorate, and add / adjust / deprecate recommendations where risk conditions justify them.
  • Governance posts and payloads, stated plainly: we draft and publish the risk memo and the governance post; we review executable payloads against our reconstructed state and publish that review; payload authorship and execution remain with the eDAO and Curve’s existing contributors.
  • Llamalend v1 deprecation support from a risk-monitoring perspective (the v1 wind-down surface is live in Example 1), and Llamalend v2 rollout support, with the Optimism build scheduled rather than claimed (§7).
  • Detection and escalation of critical stress via automated alerts and the §3 escalation commitment.
  • Public reporting: a semiannual Llamalend market-health report plus a monthly monitoring digest. Example 1 is our proposed starting format; we expect to iterate it with the DAO, through the townhall loop, until it carries exactly what Curve contributors need. Because the surface rebuilds every window, the same report is available on demand between publications.

Module B (offered, non-exclusive): the systemic-risk and simulation layer for the whole Curve perimeter. The engine already watches the 21 protocols Curve’s collateral is rehypothecated into, so when a non-Curve event fires (a yield-stable breaks, an LST depegs, a major lender cascades) we read Curve’s exposure inside the system-wide cascade rather than in isolation. Example 3 shows it end to end: a USDe depeg of 15%, propagated through a 75-token value graph and run through our calibrated cascade on the real 2026-07-13 book, forces about $360M of deleveraging across 272 positions ($353M of it through Aave’s books, with zero new bad debt under venue-oracle gating) and touches Curve for under $1M of forced repayments; but that covers 17 of the 24 borrowers in the sUSDe Llamalend market, effectively the whole $1.75M book. Because the mint markets, PegKeepers, and the credit-line perimeter are already reconstructed, this layer covers both scopes by construction. It is deliberately compatible with any Scope 1 award: we are glad to share data and coordinate with whichever team the DAO selects there.

The modules are separable. Award both, or either alone; the price in §5 is the same either way, because the price is a commitment device, not a rate card. The DAO should not have to choose between a service provider and a simulation engine; it can have both, from us alone or in combination with other teams.

We are not bidding: gauge and emissions analysis (outside our core; would need separate scoping), production frontend development, or a tighter human response tier than the 12-hour commitment we can honestly make today (§7).

5. Price: $100,000 per year, paid entirely in CRV, 100% locked as veCRV

  • Ask: $100k per year equivalent in CRV, paid quarterly. Every token is locked to the four-year maximum on receipt and maintained at max lock for as long as we work with Curve. No stablecoin component. Zero sell pressure, ever.
  • Trial and review, per CFP requirement 10: a public checkpoint at month 3 against the §8 KPIs, and a full renewal decision at month 12. The DAO can end the engagement at either point, or at any point, and keeps everything in §6. If we have not been useful, do not renew. The cost of having tried us is a locked governance position, not treasury spend.

Why this price, plainly: we are funded and are not bidding for revenue. What we want from this mandate is a design partner (the monthly townhall loop tells us what a serious DAO needs from risk infrastructure, and that knowledge is genuinely half our compensation) and the chance to prove ourselves in public against our own KPIs. Our commercial upside sits where the CFP already put it: the ownership terms let us bring the tooling we harden for Curve to other DAOs and institutions afterwards, so a mandate done well pays us even when Curve pays us almost nothing. That is also the honest answer to the retention question (“what happens when a bigger client calls?”): Curve is not a $100k account to us; it is the design partnership the rest of the product is built around.

For transparency about the future: a full-service mandate of this scope, with a staffed incident desk, a tighter response SLA, and the always-on alerting tier, is realistically a $200–250k per year engagement. If after a year the DAO wants that tier, that is the conversation we would expect to have. In year one we would rather prove the machine is worth it.

6. What the DAO keeps if we disappear tomorrow

A perpetual license to configurations and documentation is worthless if the engine they run on leaves with us. So the deliverable is runnable, not documented:

  • From Phase 0, a DAO-org repository holds the Curve-scope data schema, periodic state snapshots, the replay scripts that rebuild the monitoring surface from public data, and every alert configuration, version-controlled throughout the mandate, not handed over on a final day.
  • Per the CFP’s own terms: the DAO receives a perpetual license and operational access to the Curve-scoped models, alert configurations, dashboards, documentation, and runbooks; Xerberus retains the right to commercialise the underlying tooling.
  • If Xerberus vanishes mid-mandate, the DAO (or its next provider) re-runs the Curve scope without us.

The DAO has just lived through why this matters.

7. What we can’t do yet

We would rather the DAO trust our alerts than discover our gaps later:

  1. We are unknown in this community. No forum history, no prior Curve mandate. The verification offers in §2 and the structure in §5–§6 exist so that trying us costs the DAO almost nothing.
  2. Our committed response tier is 12 hours, because that is what is live. Automated watches evaluate as each 12-hour window closes, with intra-window triggers for depeg and oracle-staleness as an escalation tier. We are funded, so this is not a staffing constraint; it is an honesty constraint: the always-on, event-driven alerting tier and the operational routine around it are not built yet. Building them on the Curve scope is a named Phase 1 deliverable, and tightening the committed SLA once proven is a decision the DAO can take when it has seen us work. Until then we commit to 12 hours and will regularly beat it, rather than committing to 2 hours and hoping.
  3. Llamalend v2 is on Optimism, and V7 is Ethereum-mainnet-only today. The Optimism data plane is a genuine new-chain build. We commit to delivering it by the end of month 3 (Phase 1), ahead of v2 reaching mainnet, with Arbitrum following in month 4 if in-scope markets deploy there; the full chain footprint of in-scope markets is confirmed during Phase 0 so nothing falls silently out of coverage. The remedy if we slip: the following quarter’s payment abates until the Optimism plane is live, and the miss is a termination trigger at the DAO’s option.
  4. Parameter recommendations are analyst-authored on top of automated evidence. The measurements (tails, absorption, backing, oracle behaviour) are reproducible machine output. The recommendation and the governance post are human work, and the DAO and eDAO retain all decisions and execution, as the CFP specifies.
  5. Known measurement caveats are printed on the documents themselves: every attached example carries its own honesty box. The largest today: CRV’s on-chain depth floor is under-indexed, because Curve’s own crypto-pool venues are not yet reconstructed in our depth index. In a Curve mandate that gap deserves a schedule, not a caveat: closing it is a named Phase 1 deliverable.

8. KPIs: measurable, and sized to what we actually commit

KPI Commitment
Monitoring coverage 100% of active Llamalend markets under automated 12h monitoring; new markets indexed within one window of activation
Pre-vote coverage 100% of in-scope Llamalend proposals receive a published risk memo before the vote (at least 3 business days prior, given 5-business-day address disclosure)
Critical-alert escalation Written escalation to the DAO/eDAO channel within 12 hours of a critical trigger, with a recommended action, logged publicly with outcome
Townhall cadence 12 of 12 monthly public sessions held, each opening with a shipped-versus-requested recap
Request follow-through 100% of townhall and forum monitoring requests triaged with a written disposition in the public register within 10 business days
Miss accounting (a KPI we adopt from Pharos’s proposal, with credit) Every material Llamalend stress event (bad debt, insolvency, exit crunch) receives a public post-incident note stating whether our monitoring flagged it in advance. Misses are reported as misses
Public reporting Semiannual Llamalend market-health report, monthly monitoring digest, and the living findings register
Reusable deliverables Alert configurations, model documentation, runbooks, and the Curve-scoped serving surface delivered per §6, documented quarterly

9. Team and disclosures

  • Simon Peters (LinkedIn), mandate lead: Xerberus founder. Single point of accountability for delivery, DAO communication, the monthly townhalls, and escalation follow-through.
  • Noach Detwiler (LinkedIn), quantitative and data lead: built the V7 Curve data plane, including the wei-exact LLAMMA band replay, deploy-block parameter recovery for all 49 lend markets, and the PegKeeper event reconstruction.
  • Supported by the ten-person Xerberus engineering team operating the V7 pipeline: ingestion, state reconstruction, simulation, and alerting.

V7 has produced institutional risk dossiers on major DeFi protocols (available to delegates on request via the Swiss Stake channels) and serves a deployed 134-tool query interface. Key-person continuity: Simon and Noach are the named leads on this mandate. If either steps away, the DAO is notified and a named replacement proposed within 10 business days, and the change is itself a review trigger the DAO can act on.

Conflict disclosure. Xerberus publishes an independent public rating of crvUSD (currently S, the top grade on our S-to-F scale; systemic risk 9.6/100). That rating is produced by our open methodology and is outside this mandate: the DAO does not buy influence over it, it can move in either direction, and any change is published with the evidence that drove it. And the deeper version, because our own doctrine demands it: Xerberus’s standing rule is that asset issuers do not pay us to rate their assets, and Curve DAO issues crvUSD and would pay us in CRV. The line we hold is that this mandate buys monitoring, simulation, and reporting; it does not buy the rating. If the DAO ever perceives the mandate and the rating pulling on each other, the correct resolution is to end the mandate: the rating stays.

10. Transition phases and coordination

Coverage is live before Phase 0 begins (§3); the phases describe what gets added on top.

  • Phase 0 (weeks 1–4): Monitoring on the DAO’s own alert channel from week 1. Survivability repository stood up per §6. LlamaRisk handoff review, delivered as a written memo classifying materials as reusable, deprecate, or rebuild, with any coverage V7 does not yet replicate flagged so nothing is silently dropped. The 10 October 2025 replay and itemized v1 loss ledger published (§2). Delegate verification access granted. Curve-scoped serving surface stood up. Townhall #1 held, opening with the cascade validation error table (§2).
  • Phase 1 (months 2–3): Pre-vote memo pipeline operational. Event-driven Tier-1 alerting built on the Curve scope. Optimism data plane delivered by the end of month 3 (remedy if missed: §7), ahead of the Llamalend v2 mainnet rollout; Arbitrum follows in month 4 if in-scope markets deploy there. Curve crypto-pool depth reconstruction closing the CRV depth gap (§7). Month-3 public checkpoint (§5).
  • Phase 2 (month 4 onward): Steady state. v2 coverage in place before mainnet rollout. Semiannual report #1.

Coordination we would ask of Curve contributors: deployment addresses and configuration at least 5 business days before votes; a DAO-owned alert channel; data-interface alignment with Swiss Stake and the backend team where monitoring infrastructure is shared; access to the LlamaRisk transition materials; and data-sharing coordination with the Scope 1 provider, whoever that is.

11. Compliance map

CFP requirements → sections
CFP requirement Where
Scope covered §4: Scope 2 committed (Module A); systemic and simulation layer offered across the perimeter (Module B)
Optional responsibilities §4: dashboards and indicators feasible via existing surfaces; gauge and emissions work honestly declined
KPIs and reporting cadence §8
Team background §9 plus attached documents
Tooling, models, approach, dependencies §1–§2, attached Examples 1–3, §10 coordination
Operated services during mandate §3
DAO-owned deliverables after mandate §6
Ownership, access terms, documentation, handoff §6
Coordination needs §10
Budget, payment structure, trial and review period §5

12. Glossary

Our terms of art: nothing in this proposal requires prior knowledge of Xerberus
Term Meaning
V7 Xerberus’ production risk engine (seventh generation). It ingests raw Ethereum events and traces, reconstructs every lending position, pool, wrapper, and oracle read, and computes risk on top. Currently covering roughly $37.5B TVL and $26.9B of debt across 21 protocols.
Window One monitoring cycle. The engine rebuilds its full state every 12 hours; “this window” means the most recent rebuild.
Book The total outstanding debt in one market.
Measured tail / worst measured day A market’s largest single-day soft-liquidation loss share since launch, obtained by replaying every LLAMMA trade at the oracle price recorded in the same transaction. An observed number from the market’s own history, not a modelling assumption.
Band replay The position-by-position reconstruction of LLAMMA’s collateral bands over time, exact to the wei, which is what makes measured tails possible.
Stable-loop market A lending market where a yield-bearing stablecoin is deposited as collateral to borrow another stablecoin at very high loan-to-value, typically to loop the yield. Low price volatility, but exit capacity is the binding risk.
Exit depth / absorption How much of a market’s collateral can actually be sold per day at its liquidation discount, measured from real on-chain pool state (plus listed CEX depth where relevant), not from quoted order books.
Backing trace Resolving what ultimately stands behind an asset by unwrapping it to terminal collateral (e.g. crvUSD resolves today to roughly 67% BTC wrappers plus LSTs, fully on-chain).
Cascade engine Our simulator that propagates a price shock through every reconstructed position across all tracked protocols, including second-round liquidation effects. Validated against replayed historical crises (UST, the stETH discount, Euler, the 2023 Curve/Vyper incident, and others) and a 28-window historical stress backtest; the per-crisis error table is published at townhall #1 (§2).
Watch / alert A standing, parameterized tripwire (depeg, utilization, liquidation spike, oracle staleness, concentration, contagion index) that fires on a clear-to-breached transition and re-arms on recovery.
Findings register The public, living list of open risk items on the Curve scope, each carrying the measurement that justifies it, its status, and its resolution.
S–F rating scale Xerberus’ public rating grades: S (strongest) through F (weakest), with NR for assets below our materiality floor. Methodology is public.

Prepared by Xerberus for the Curve DAO. We are available in this thread for any question, and via the Swiss Stake channels for anything the contributors prefer to discuss privately.

3 Likes

Welcome, and thanks for leading with the measurements instead of the pitch — the reconstructed per-market worst-days are exactly the kind of thing this scope has been missing.

One finding deserves to be pulled out of the appendix and put in front of the DAO, because it reframes the whole mandate: your number that Llamalend v1 has cost suppliers roughly $11.6M while returning the DAO $0, with about $10.6M of that realized in the 2024 CRV-market episodes. That isn’t a monitoring input — it’s a standing, unresolved liability that predates whoever wins this mandate.

Which raises a scoping question worth settling now, before the award rather than after: does Scope 2 cover the bad debt that already exists in wound-down markets — measuring it, tracking it, and recommending how it gets resolved — or only forward-looking risk on active and new markets?

The CFP language (“minimize preventable losses, bad debt, and market impairment”) reads forward-looking. But the largest realized losses aren’t in the markets you’d be monitoring going forward; they’re sitting in markets that are already deprecated with no working exit. CRV-long has had maxWithdraw at zero for months. The WFRAX case (Proposal to Compensate for the WFRAX Market's Bad Debt.) has been dormant since March. If the incoming provider’s remit stops at “don’t create new bad debt,” the existing bad debt has no owner at all — which is how these things quietly stall.

There are already mechanisms on the forum record that a risk mandate could evaluate rather than invent: the DAO providing recovery-pool liquidity as an LP rather than a grant (CRV-long LlamaLend market recovery - #18 by strky), a standing rule routing a capped share of already-collected fees into recovery pools (LlamaLend v1 Market Deprecation Plan - #2 by strky), and the capped-emission repayment the DAO actually executed for sDOLA-long2 (sDOLA-long2 Repayment Funds Source Proposal). A team that measured the $11.6M is well placed to say which of these is defensible per market, and at what size.

Even a clear “that’s a DAO execution decision, outside monitoring scope” is a useful answer — it tells the DAO the resolution of existing losses needs an owner this mandate won’t supply. Better to have that on the record now than to discover it in month two.

Either way — useful work, and good to have another set of eyes rebuilding these markets from the chain.

4 Likes

Hey @strky — thank you for the response and the careful reading of our proposal.

To address your question up front: measuring, tracking, and recommending on legacy bad debt and deprecated markets is in scope for our bid — with recommendations applied only upon DAO request. We see ourselves as the measuring and analysis layer for the DAO; the ultimate decision-making stays with the DAO, as the CFP specifies. Concretely, our public findings register would carry a standing, per-market line item — the measured hole, its status, its resolution — so the existing losses stay visible even where they don’t yet have an owner.

And since we like to lead with examples and data: you mentioned several mechanisms already on the forum record, so rather than answer in the abstract, we rebuilt every position, trade, and oracle read in the Llamalend perimeter from raw Ethereum events and pointed the reconstruction at what is already in motion. Here is our data-driven read — first what the record shows, then our recommendations on top of it.

1. What’s already in motion — attested from the chain

The record deserves its due, and we can do better than praise it — we can attest it:

  • The recovery pool works. Since its deployment under vote #1400, 36 distinct sellers have exited $295,578 of nominal claims at an average of 67.9¢ per claim-dollar, against nearly matched buy-side volume ($294k, 38 addresses) — while the vault’s own withdrawals cleared $5.7k in all of July against available cash of $0.16 (RPC-verified against our reconstruction at 0.6% parity; withdrawals are instant redemptions bounded by controller cash, a first-come race). Your April 27 audit read $198 of depth; your May 6 read $63k; this morning it is ~$613k at market value ($291,690 crvUSD + $473k of nominal claims). The post-gauge leg of that growth — $63k to $613k after the 0.45% weight went live on May 7 — answers the “will investors arrive” test you posed on May 3: they arrived. Hubert’s call-spread floor was a reasonable ex-ante argument for why they wouldn’t; the gauge carry changed the economics it assumed.
  • The deprecation plan is executed, not just written. Rate-to-zero is live on-chain for the illiquid markets (CRV-long, UwU, sDOLA-long2 — all at 0.00% borrow APR today); WETH-Long2 sits on the liquid-market track exactly as the plan routes it.
  • The pool’s 71% centring is independently confirmed. Our per-position measurement of the CRV-long hole — $826,077 across 26 of 73 open positions — gives 71.4% solvency at the July 8 oracle read ($0.2043; ≈73% at the July 20 price_oracle() of $0.2188), derived separately from the OP’s analysis and landing on the same ratio. July’s trades clear ~4–6¢ below that static mark — a coherent price for immediacy plus the deliquidation-path losses the OP models in the $0.47–$0.84 range.
  • The disclosure fix shipped. Michael’s reply to specialist78 in the recovery thread says bad-debt visibility moved into the UI rather than living on third-party sites. A standing measured register makes that structural — for every market, whoever the provider is — and it is, almost line for line, the dashboard LlamaRisk asked for in their safeguards review: pool price, estimated backing, liquidation floor, bad debt cleared, depth. The two documents published with this reply are that dashboard’s v0; under a mandate they refresh every 12 hours.

The record shows the DAO is not missing mechanisms. What it is missing is a standing, measured picture that connects them — three snapshots of the same hole ($700k in the OP, ~$754k in your May 6 read, $826k at our July 8 mark, ≈$780k at the fresher July 20 price) drifted ±$50k a month in both directions while everyone watched. That picture is what we build.

2. To the lenders in this thread

Most of this reply is measurement, so one section that isn’t. The 67.9¢ average above means 36 of you accepted a ~32% haircut for cash — the pool gives you a choice, which the frozen vault did not, but nobody should mistake a haircut taken for a problem solved. Two things from our reconstruction are yours regardless of what happens with this mandate. First: specialist78 asked whether the large pre-freeze withdrawal was real. It is — a single $728,315 withdrawal on 2026-04-17, 60% of April’s entire outflow, eleven days before deposits stopped, by an address that remains among the largest holders; size and timing are published in the companion ledger, and the address is available to designated delegates on request. That is exactly the class of event a standing register surfaces in real time instead of months later. Second: on the responsibility question this thread keeps circling — the three-haircuts accounting, the Vyper-exploit precedent and the others strky catalogued — measurement can size every option on that list, and the numbers below do, but whether lenders bear 100% is a values decision only the DAO can take. We won’t pretend a dashboard answers it; we can promise the DAO decides it with the true numbers in front of them, updated every window, misses reported as misses.

3. Recommendations

Each carries its basis and what would change our mind. Sizing details and stop-condition definitions live in the evidence panel — standing trigger values belong in a live register, not hard-coded in a forum post.

R1 — Fund the CRV-long recovery pool to full exit capacity, from a capped fee stream routed as a DAO LP position.
Basis: the pool is proven and its crvUSD side covers ~19% of exit demand ($292k against ~$1.55M to cash out the seven largest non-pool holders — 76.9% of claims — at the ~68¢ the pool clears). The target is a flow target (cumulative crvUSD routed), because depth is consumed by the exits it funds. This is your fee-routing leg and the OP’s pool composing into one design — no lump-sum treasury spend, though it does need a parameter vote, fee-receiver plumbing, and (for L2 legs) the same admin handovers R2 lists. On the full-protocol fee base at a 25% cap it completes in ~7–9 months depending on the split rule; the base choice and whose income it is are laid out in the evidence panel. Would change our mind: the pool’s 30-day volume-weighted clearing price sustained below 60¢ on meaningful volume — the market signalling path losses beyond what the models price.

R2 — One joint funding picture before either funding vote.
Basis: the sDOLA-long2 reimbursement ($822,475 to 27 borrowers) and any cohort-wide framework both draw on the same uncollected L2 fee pot (~$1.14M gross) — roughly $2M of claims against a one-off pot plus a stream. Prerequisite: fix the fee-burner min_amount_out = 500 crvUSD hardcode before converting anything, or the gross-to-net haircut can be severe. This recommendation costs nothing and prevents two proposals discovering mid-vote that they spent the same money.

R3 — Mark UwU manually before it enters any split rule.
Basis: its oracle is dead (last in-transaction read January 2025; its single position last touched June 2024). Its per-position gap mechanically reads $0 and its aggregate netting reads ~$15.6k — neither is decision-grade, and a dead market’s allocation share should not be computed off a dead oracle. One external mark, then it slots into whatever rule the DAO adopts.

Your two open design questions from the deprecation thread — sustainable fee share, and the split rule — are answered with tables in the evidence panel: the short version is that the fee-share answer differs ~7× depending on which base the rule names (crvUSD-system fees vs full-protocol admin fees — the latter is the veCRV distribution’s own income, so the cap is a haircut its voters approve on themselves), and the split rules agree on CRV-long (~77–78%) and diverge exactly where harm class differs, which argues for your floor-plus-cap variant with borrower-harm routed through reimbursement. The register also opens with three further watch items — WETH-Long2’s accrual split, the live WBTC market’s latent gap, and the off-mainnet cohort including the FXS/FRAX market on Fraxtal, whose dormant compensation thread is your own baseline for per-case resolution — bases and properly-defined trigger conditions in the evidence panel.

4. The evidence

Per-market ledger, pool tape, recovery curve, split rule, fee bases, watch items

Per-market ledger (Ethereum lend markets with realized loss > $500 or open gap > $100; debt at last on-chain touch throughout):

id market realized bad debt (lifetime) forced liqs open debt per-position gap insolvent / open suppliers
3 CRV-long $10,615,458 214 $2,890,221 $826,077 26 / 73 199¹
8 UwU $433,450 3 $32,051† n/a† —† 20
39 fxSAVE $201,570 103 $341,792 $37,305 1 / 14 19
12 WETH-Long2 $164,085 65 $664,169 $228,605 6 / 27 31
1 WETH (OG) $130,760 30 $37,076 $21,991 1 / 8 29
14 USDe $26,836 19 $2,228 $1,900 2 / 6 20
2 tBTC $25,737 10 $28,247 $0 0 / 3 41
11 sUSDe $22,178 10 $1,728,645 $0 0 / 24 28
9 WBTC $3,667 31 $3,461,588 $103,740 1 / 63 60
17 sDOLA (old market) $0 0 $794 $794 3 / 3 17
30 sDOLA-long2 $0‡ 28‡ $58,291 $0 0 / 2 22
Lend family total $11,646,275 $1,221,518°

¹ includes the recovery pool itself, the #1 holder at 15.95%; seven largest non-pool holders = 76.9%.
† UwU’s oracle is dead (last read 2025-01-03); per-position reads $0 and aggregate netting ~$15.6k — neither is decision-grade (see R3). Accrual-inclusive debt: $54,173.
‡ the 2026-03-02 exploit; the realized-bad-debt estimator reads $0 because those liquidations repaid in full at manipulated prices — the harm was borrower equity ($822,475 per the post-mortem).
° per-position family total with UwU at n/a; includes dust rows not shown (sreUSD $702, wstUSR $210, PROS $100, ETHFI/wstETH/sFRAX/pufETH ≤ realized-only). Distinct from the deprecation plan’s all-chain cohort figure ($1,217,845) — the near-match is coincidence, not agreement.

CRV-long claim recovery curve (static mark — lower bound; the OP’s path-adjusted analysis puts arbitrage-clean recovery nearer $0.957):

CRV price vs 07-08 oracle gap claim value
$0.102 0.50× $1,287,934 55.4%
$0.204 1.00× $826,080 71.4%
$0.306 1.50× $525,633 81.8%
$0.409 2.00× $225,740 92.2%
$0.613 3.00× $15,335 99.5%

Only $15,335 is unrecoverable at any price. 90% solvency ≈ CRV $0.39 (interpolated; 1.89× the 07-08 mark, 1.77× the 07-20 price — read it off the live register, not this post). Denominator note: 71.4% is debt-basis (gap / $2.89M last-touch debt); claims-basis (vs $2.97M totalAssets) ≈ 69.5%. Three “full recovery” prices circulate in the thread — $1.24 (bad debt self-clears), $0.957 (OP, arbitrage-clean), $0.54 (our static mark) — all correct under their own definitions.

Recovery pool tape (pool 0x516c3ecf…3cb5, deployed 2026-04-25; A=2, fee 1%; 212 trades / 132 adds / 36 removes through 07-19; full addresses in the notes panel):

month claims sold (nominal) avg exit claims bought avg buy
Apr (from 25th) $1,115 80.2¢ $1,323 76.8¢
May $234,021 68.5¢ $190,274 69.9¢
Jun $40,455 64.7¢ $98,482 67.9¢
Jul (to 19th) $19,986 66.7¢ $3,630 67.5¢
total $295,578 → 200,596 crvUSD (67.9¢) $293,710 (69.2¢)

Depth: $198 (Apr 27) → ~$1,760 (May 3) → $63k (May 6, pre-gauge) → $291,690 crvUSD + $473k nominal claims (~$613k at market) on Jul 21 (post-gauge leg).

Split rule (strky Q2), measurable Ethereum cohort:

market gap by-gap share impacted users by-users share
CRV-long $826,077 78.3% 199¹ 77.4%
WETH-Long2 $228,605 21.7% 31 12.1%
sDOLA-long2 $0 (reimbursement-class harm) 0.0% 27 borrowers 10.5%
UwU n/a — enters after manual mark (R3) 20 (held out)

Measured cohort vs the deprecation plan’s Ethereum snapshot: $1,054,682 today vs $810,500 at plan time (+ UwU unmeasured) — price drift, accrual where rates still run, and per-position vs snapshot methodology; the mark moves in both directions with CRV.

Two fee bases (R1 basis) — they differ ~7×; any rule must name its base:

base measured value 25% cap fills Ethereum cohort (~$1.05M) in
A: crvUSD-system fees (mint interest + PegKeeper profits — our reconstruction) $95.6k/30d run rate ($4.44M trailing-365d, decaying; trailing-year quotes flatter by ~3.9×) ~44 months
B: full-protocol DAO admin fees (per DefiLlama; strky’s scale check) ~$8.6M/yr ~6 months

Base B is the veCRV distribution’s income — the cap is a haircut its own voters approve. We cannot yet independently reconstruct the AMM admin-fee stream (Curve’s crypto pools are our known depth-index gap, scheduled Phase 1) — Base B is quoted, not measured by us. The uncollected L2 pot (~$1.14M gross) is a one-off, contested between R1-class funding and the sDOLA reimbursement (R2), and subject to the burn-haircut prerequisite.

sDOLA-long2 definitional pins: 2026-03-02, 28 positions closed in 2 transactions; $21.8M debt extinguished (consistent with $20.8M net vault supply pre-exploit plus accrued interest); $24.7M crvUSD + ~39k sDOLA seized — the manipulated oracle had already converted the collateral inside the bands. The “~$10.9M” in press coverage is the single largest borrower’s debt ($10,904,728), not the market total; the post-mortem’s $822,475 / 27 borrowers is assessed equity harm — a different quantity. All three numbers are correct for what they measure.

Register watch items (opened at register launch, with defined triggers):

  • WETH-Long2 accrual split: the liquid track accrues 3.11% (≈$20.7k/yr on the $664k book) while 6 of 27 positions are underwater; we publish the underwater share of accrual first, and flag for the illiquid track if it sustains above 50% across two windows (rate is per-market via the MonetaryPolicy contract — the action is market-wide, and zeroing also removes healthy borrowers’ repayment incentive, so this is a measured tradeoff, not automatic).
  • WBTC latent gap: $103,740 in one position on a healthy $3.46M book; escalation if the gap grows ≥ 25% window-over-window and ≥ $50k absolute, sustained two windows (single-position gaps are differences of large numbers; raw percentage triggers are noise).
  • Off-mainnet cohort: $407k across Arbitrum/Fraxtal/Optimism incl. FXS/FRAX $145,857 — named in our Phase 0 chain-footprint confirmation so it cannot silently drop; split-rule table extends to all eleven markets when those planes land.

5. Raw data, definitions, and reproduction notes

Definitions, addresses, methods, honesty box, references

Definitions.

  • Realized bad debt = Σ per-liquidation max(0, debt_repaid − collateral_seized × day-price) over market lifetime. Excludes losses socialized without a Liquidate event and soft-liquidation grind (reported separately).
  • Per-position gap = Σ over open positions of max(0, debt_at_last_touch − (banded crvUSD + banded collateral × oracle price)). Insolvency is per-position: aggregate netting (≈ 0 here) is the wrong measure because a healthy borrower’s excess collateral does not back a neighbour’s empty debt.
  • Debt extinguished vs assessed harm: debt closed in Liquidate events vs post-mortem borrower-equity loss.
  • Claim value / solvency = (debt − gap) / debt at a stated price and stated debt basis (last-touch unless marked accrued).

Addresses (Ethereum mainnet).

  • Lend factory: 0xea6876dde9e3467564acbee1ed5bac88783205e0 (48 markets)
  • CRV-long controller: 0xeda215b7666936ded834f76f3fbc6f323295110a · vault: 0xcea18a8752bb7e7817f9ae7565328fe415c0f2ca · AMM: 0xafca625321df8d6a068bdd8f1585d489d2acf11b
  • Recovery pool: 0x516c3ecfe45f0820653e08dd7c93633d71b93cb5 · gauge: 0xF429AeC167C92aCA16cD77aef54F196B1988cBA3
  • crvUSD: 0xf939e0a03fb07f59a73314e73794be0e57ac1b4e

Method + windows. All positions, trades, band states, and oracle reads reconstructed from raw Ethereum logs and traces (no third-party data feeds). Position state 2026-07-20; risk-ledger build 2026-07-10; pool tape through 2026-07-19; RPC verification-only checks 2026-07-20/21 (controller cash, totalAssets, price_oracle(), pool reserves; reconstruction parity 0.6% on vault assets).

Honesty box.

  • Debt is at each position’s last on-chain touch; accrual since is not added (moot where rate = 0; live for WETH-Long2). Collateral valued at each market’s last in-transaction oracle read (CRV-long 2026-07-08; UwU 2025-01-03 — see R3).
  • Recovery-curve prices are oracle reads, not depth-adjusted exit prices; our depth index under-covers Curve’s own crypto pools (named Phase 1 deliverable).
  • Pool-tape claim-dollar conversion holds the current price-per-share (0.001251) constant across the three-month tape; drift is sub-cent with rates at zero, and per-trade pps from our replay is a scheduled upgrade.
  • The OP’s April chart showed 38 underwater positions (22 non-dust); we count 26 insolvent (> $1) of 73 open at the Jul-8 price — price movement and closures account for the difference.
  • Supplier counts are addresses with share balance > 0 from vault Transfer events; contract holders are not unwrapped to end users.

References.
CFP · our proposal thread · CRV-long recovery thread (strky’s Apr-27 audit; LlamaRisk safeguards; strky’s DAO-as-LP post) · v1 deprecation plan (strky’s framework, post #2) · sDOLA-long2 post-mortem · sDOLA-long2 funds-source proposal · WFRAX Curve-side thread · Vyper-exploit recompensation · vote #1400 · vote #1391 (CRV-long wind-down) · DefiLlama Curve revenue: defillama.com/protocol/curve-finance

Every number above is a rerunnable query; designated delegates can be given read-only access to rerun the headline figures — the CRV-long gap, the pool tape, the v1 loss ledger — before taking anything on faith.


1 Like

Thanks for the clear answer, Simon — and it’s the right one. A standing, per-market line item that keeps the measured hole visible even where it has no owner is exactly the structural fix; carrying it in the findings register rather than an appendix is what stops these losses from quietly aging out. That’s a real contribution independent of who wins the mandate.

One refinement, and it comes straight out of your own tape. The pool’s growth is being read in places as evidence the hole is closing; your reconstruction shows the opposite. Depth went ~$198 (Apr 27) → ~$63k (May 6) → ~$613k this morning — and the post-gauge leg alone ($63k → $613k after the 0.45% weight went live) is a ~10× deepening. Across that whole arc the clearing price never left the high-60s: 36 sellers out at an average of 67.9¢, buy-side matched, trades landing 4–6¢ under the 71% static mark throughout. If depth pulled price toward par, a 10× deeper book would have moved it. It didn’t, and structurally can’t: the pool is zero-sum and bounded by backing — anyone adding crvUSD so a holder can exit ends up holding the same ~71¢ claim, and an AMM can’t sit above true backing without being arbitraged.

So the two things are genuinely separate. R1 — route a capped fee stream in as a DAO LP — resolves illiquidity, and that’s worth doing. But it leaves the ~$826k solvency gap you measured (26 of 73 positions, ~71% backing) 1:1 intact. Funding exits doesn’t shrink the hole; it changes who stands in front of it.

Two things a measurement layer is well placed to hard-code:

First — carry the two numbers separately in the register, per market, never netted: (a) liquidity / exit-capacity, and (b) the unremediated solvency gap in dollars. Once the DAO’s own surface separates them, “pool funded to $X” can’t be reported as “hole closed” — which is the exact slippage that lets a ~32% haircut get reclassified as resolved.

Second — a scoping question on R1 that’s really a design question. If a capped fee stream is going to be routed anyway, is it best spent only funding discounted exits at ~68¢, or should a share also retire the measured gap for the original impaired positions directly — a snapshot facility keyed to the pre-freeze position, not to current holdings? sDOLA-long2 is the on-record template for the capped-emission mechanics; the difference is only where the DAO’s capital lands — closing the measured hole for the positions that took the loss, versus subsidizing whoever shows up to buy the discount. R1 reads better as the on-ramp than the destination.

And if the answer is “whether the DAO closes that gap at all is a values decision, not a monitoring one” — that’s still a useful result. It puts on the record that the solvency gap is a distinct, still-open, unowned liability rather than something the pool quietly dissolves. Better to name it now than to rediscover it in month two.

Either way — genuinely strong work, and the per-position reconstruction is exactly what this has been missing.

2 Likes