Submitted in response to the Call for Proposals: Curve Risk Assessment and Market Monitoring. All figures in this proposal and its attached documents were generated from public on-chain data by our production system. No privileged access. Every number is a rerunnable query. Xerberus terms of art are glossed at first use and collected in the glossary at the end.
TL;DR: We bid Scope 2 (Llamalend / isolated markets) plus a system-wide simulation layer for the whole Curve perimeter, awardable separately or together (§4). Before asking for anything, we pointed our production engine at Curve and attached one working sample of each service we’re bidding (the monitoring report, the parameter simulation, and the systemic alert), with four material findings (§2), including that the DAO’s largest single crvUSD exposure, the ~$265M drawn Yield Basis credit line, sits outside every monitoring surface today. Price: $100k per year, paid entirely in CRV, 100% locked as veCRV for four years (§5). Public checkpoint at month 3; the DAO can walk away at any point and keeps a runnable copy of everything (§6). Monitoring is live today and lands on the DAO’s own alert channel in week 1 (§3).
1. Who is Xerberus, and why the numbers below exist
Xerberus is a funded risk-analytics company building the risk-rating standard for crypto. Our production engine, V7, rebuilds every lending position, pool, wrapper, and oracle read directly from raw Ethereum events and traces (no third-party data feeds, no privileged access) across 21 protocols, roughly $37.5B of TVL and $26.9B of debt. Those 21 protocols are the same ones Curve’s collateral is rehypothecated into.
We have no history on this forum, and we know what that means in a decision like this one. So instead of describing what we could do for Curve, we did it: we reconstructed Curve’s entire crvUSD and Llamalend perimeter: every mint market, PegKeeper, and Llamalend market, including a wei-exact replay of LLAMMA’s collateral bands (1.2M band transitions anchored to genuine TokenExchange events, 164k in-transaction oracle reads). Everything below comes from that work.
2. The CFP asks one core question. Here is the measured answer.
“Is the Curve DAO taking the right risk-adjusted approach, and are those risks being monitored properly?”
Mostly yes: your core is sound. In four specific places, no, and each one is measured, not modelled.
Finding 1: Most of the Llamalend book cannot exit at the speed it might need to be liquidated.
79% of borrowed value sits in three markets (sreUSD, sfrxUSD, sUSDe) where a yield-bearing stablecoin is looped against another stablecoin at ~98% of max LTV. The safety margin on those loans is a 1.3–2.0% liquidation discount, but for markets like these the binding risk is not price volatility, it is exit capacity. The largest, sreUSD: $18.2M borrowed, against collateral of which only ~$2.1M can be sold in a single day without breaking the price (~$13.2M sellable in total across all venues). sUSDe’s only real exit is Ethena redemption, which sits behind a 7-day cooldown. A smaller market of the same type, fxSAVE, has already recorded a single day four times worse than the discount that is supposed to cover it.
What to do: cap stable-loop books at their measured daily exit capacity. Example 2 demonstrates the method on five live markets.
Finding 2: Llamalend v1 has cost its suppliers roughly $11.6M and earned the DAO $0.
This is the CFP’s compensation question answered literally. All v1 interest accrues to suppliers, and those same suppliers absorbed the realized losses, about $10.6M of it in the 2024 CRV market episodes. Example 1 closes the lifetime ledger in its section “Is Curve compensated for the risk?”.
What to do: this is the strongest empirical argument available for v2’s fee design, and for capping today’s stable-loop books until v2 lands.
Finding 3: The WBTC mint market’s safety margin has already been exceeded by its own history.
A market’s parameters should stand above the worst day that market has actually produced. WBTC’s loan discount is 9%; its worst measured day was a 24.6% single-day loss share (2026-02-03), contained only through a wave of 99 hard liquidations. Mint markets are Scope 1, but the instrument does not care which scope a market is in, so we surface it.
What to do: revisit the discount, or accept in writing that containment depends on hard-liquidation throughput.
Finding 4: The DAO’s largest single crvUSD exposure has no monitoring surface at all.
The Yield Basis credit line has roughly $265M drawn of $1,000M authorized, a ceiling raised from $60M to $1,000M within four months, executed on-chain rather than merely proposed (the three mint transactions sum to exactly 1,000M; receipts on request). That is about eight times all mint-market debt combined, and it sits outside every LLAMMA-era monitoring surface.
What to do: bring the credit line inside a monitoring perimeter, ours or anyone’s.
Where these numbers come from: one working sample of each service
Three attached documents. They are not marketing material: each is a working sample of a different service the DAO would be buying, generated on Curve’s live book (static captures from 2026-07-15; Example 3’s simulation recomputed 2026-07-19 on our calibrated cascade, as noted in its provenance). Treat each as a starting point, not a fixed format; the townhall and request-register loop in §3 exists precisely to reshape these deliverables into what the DAO actually needs.
- Example 1, Curve Risk Monitor (view): the reporting service. This is what the semiannual market-health report and monthly digest could look like; the final shape is set with the DAO, not for it. As a starting point: every crvUSD mint market, PegKeeper, and Llamalend market reconstructed from raw Ethereum events, each with its worst measured day rather than an assumed one, ending in an 8-item action register where every item carries the measurement that justifies it. It also closes the revenue-versus-losses ledger behind Finding 2. And because the underlying surface rebuilds every window, under a mandate this report is not a twice-a-year event; it is available on demand.
- Example 2, Five ceilings, five verdicts (view): the parameter-simulation service. The simulation engine run over parameter changes: one question against five live Curve markets: how big can this book get before a bad day produces more forced selling than its collateral’s exits can absorb? Two books are already past that line. Every pre-vote memo and ceiling recommendation in this proposal is produced exactly this way, and the DAO can rerun every number and dispute the assumptions rather than the arithmetic.
- Example 3, Incident pack (simulated) (view): the alerting and escalation service. What lands in the DAO’s channel when a systemic event outside Curve threatens Curve: a USDe depeg of 15% run through our validated cascade engine on the real 2026-07-13 book: the automated alert at T+0, the Curve exposure read, the system-wide cascade context, and the escalation memo with recommended actions.
Verify us, don’t trust us
Self-generated evidence deserves suspicion, so three standing offers:
- Delegate verification, before any award. Named delegates receive read-only access to rerun the headline numbers themselves: the sreUSD exit depth, the WBTC measured tail, the v1 loss ledger.
- A backtest against 10 October 2025. The October 2025 crash was the hardest single day any DeFi monitoring system has recently had to survive, so we apply our own miss-accounting KPI to ourselves, retroactively: in Phase 0 we publish a replay of our current alert set against that day’s data: which alerts would have fired, at what time, and when the DAO would have received the written escalation, together with an itemized ledger of what that day cost Llamalend v1 suppliers. If our system would have missed it, the backtest will say so.
- “Validated” should not be an adjective. Our cascade engine is validated against replayed historical crises (UST, the stETH discount, Euler, the 2023 Curve/Vyper reentrancy) and a 28-window historical stress backtest. We will publish the per-crisis error table (predicted versus realized losses and liquidations) at townhall #1.
Whether or not this proposal is selected, we hope the documents are useful to the DAO.
3. What the DAO gets, month to month
Coverage starts in week 1, not in a later phase: the monitoring shown in Example 1 is already running today, and the first deliverable is pointing it at a DAO-owned alert channel.
The machine layer, which runs regardless of anyone’s calendar:
- Refresh of every in-scope market every 12 hours: positions, utilization, bad-debt exposure, collateral composition, oracle behaviour, exit depth versus book size, liquidation proximity. Twelve hours is the committed cadence; improvements ship when they are live, not when they are promised.
- Standing automated alerts delivered to a DAO-owned Telegram or webhook channel: depeg, utilization, liquidation-spike, oracle-staleness, concentration, and contagion-index watch types. Three are already live on the Curve scope today, created while preparing this response; the DAO can keep or delete them. Every alert carries the timestamp of the state it read, so a T+0 alert never hides that its position snapshot can be up to one window old.
- Scenario simulation on request and on schedule: custom shock baskets through the cascade engine, ceiling sweeps of the Example 2 kind, and pre-vote hypothetical books for proposed markets.
- A public findings register: Example 1’s action list maintained as a living document, where every open risk item carries the measurement that justifies it, its status, and its resolution.
The human layer, which keeps the machine pointed at what Curve actually needs:
- A monthly public townhall with the DAO. One to two hours, on the forum and/or the community call: here is what changed in your risk picture this month; here is what you asked us to monitor last month and what we shipped; what should we point the engine at next? Requests go into a public request register (requested / in review / shipped / declined with reasons).
- Pre-vote risk memos for Scope 2 proposals (the Example 2 method), targeting delivery at least 3 business days before the vote where deployment addresses and configuration are disclosed at least 5 business days ahead.
- Written escalations within 12 hours of a critical trigger (the Example 3 format), with a recommended action, logged publicly with the outcome. Twelve hours is what our live system supports today, so twelve hours is what we commit to. If the DAO wants a tighter tier after seeing us work, that is a scaling conversation, not a rebuild (§5, §7).
4. Scope: two modules, awardable separately or together
Module A (committed): Scope 2, Llamalend / isolated markets, plus LLAMMA-related infrastructure. Per the CFP’s responsibility list:
- Collateral-risk and market-risk reports for new Llamalend markets before the DAO vote: collateral quality, backing trace to terminal assets, oracle dependencies, liquidity depth, liquidation assumptions, and market-specific failure modes.
- Risk-driven parameter recommendations for new deployments, on the reproducible basis demonstrated in Example 2: safe-book ranges anchored to each market’s own measured tail, absorption measured from actual pool state.
- Ongoing monitoring of all active lending markets (49 are already under reconstruction today) at the §3 cadence: utilization, liquidity health, oracle behaviour, bad-debt risk, solvency, and abnormal activity.
- Parameter-change recommendations where conditions deteriorate, and add / adjust / deprecate recommendations where risk conditions justify them.
- Governance posts and payloads, stated plainly: we draft and publish the risk memo and the governance post; we review executable payloads against our reconstructed state and publish that review; payload authorship and execution remain with the eDAO and Curve’s existing contributors.
- Llamalend v1 deprecation support from a risk-monitoring perspective (the v1 wind-down surface is live in Example 1), and Llamalend v2 rollout support, with the Optimism build scheduled rather than claimed (§7).
- Detection and escalation of critical stress via automated alerts and the §3 escalation commitment.
- Public reporting: a semiannual Llamalend market-health report plus a monthly monitoring digest. Example 1 is our proposed starting format; we expect to iterate it with the DAO, through the townhall loop, until it carries exactly what Curve contributors need. Because the surface rebuilds every window, the same report is available on demand between publications.
Module B (offered, non-exclusive): the systemic-risk and simulation layer for the whole Curve perimeter. The engine already watches the 21 protocols Curve’s collateral is rehypothecated into, so when a non-Curve event fires (a yield-stable breaks, an LST depegs, a major lender cascades) we read Curve’s exposure inside the system-wide cascade rather than in isolation. Example 3 shows it end to end: a USDe depeg of 15%, propagated through a 75-token value graph and run through our calibrated cascade on the real 2026-07-13 book, forces about $360M of deleveraging across 272 positions ($353M of it through Aave’s books, with zero new bad debt under venue-oracle gating) and touches Curve for under $1M of forced repayments; but that covers 17 of the 24 borrowers in the sUSDe Llamalend market, effectively the whole $1.75M book. Because the mint markets, PegKeepers, and the credit-line perimeter are already reconstructed, this layer covers both scopes by construction. It is deliberately compatible with any Scope 1 award: we are glad to share data and coordinate with whichever team the DAO selects there.
The modules are separable. Award both, or either alone; the price in §5 is the same either way, because the price is a commitment device, not a rate card. The DAO should not have to choose between a service provider and a simulation engine; it can have both, from us alone or in combination with other teams.
We are not bidding: gauge and emissions analysis (outside our core; would need separate scoping), production frontend development, or a tighter human response tier than the 12-hour commitment we can honestly make today (§7).
5. Price: $100,000 per year, paid entirely in CRV, 100% locked as veCRV
- Ask: $100k per year equivalent in CRV, paid quarterly. Every token is locked to the four-year maximum on receipt and maintained at max lock for as long as we work with Curve. No stablecoin component. Zero sell pressure, ever.
- Trial and review, per CFP requirement 10: a public checkpoint at month 3 against the §8 KPIs, and a full renewal decision at month 12. The DAO can end the engagement at either point, or at any point, and keeps everything in §6. If we have not been useful, do not renew. The cost of having tried us is a locked governance position, not treasury spend.
Why this price, plainly: we are funded and are not bidding for revenue. What we want from this mandate is a design partner (the monthly townhall loop tells us what a serious DAO needs from risk infrastructure, and that knowledge is genuinely half our compensation) and the chance to prove ourselves in public against our own KPIs. Our commercial upside sits where the CFP already put it: the ownership terms let us bring the tooling we harden for Curve to other DAOs and institutions afterwards, so a mandate done well pays us even when Curve pays us almost nothing. That is also the honest answer to the retention question (“what happens when a bigger client calls?”): Curve is not a $100k account to us; it is the design partnership the rest of the product is built around.
For transparency about the future: a full-service mandate of this scope, with a staffed incident desk, a tighter response SLA, and the always-on alerting tier, is realistically a $200–250k per year engagement. If after a year the DAO wants that tier, that is the conversation we would expect to have. In year one we would rather prove the machine is worth it.
6. What the DAO keeps if we disappear tomorrow
A perpetual license to configurations and documentation is worthless if the engine they run on leaves with us. So the deliverable is runnable, not documented:
- From Phase 0, a DAO-org repository holds the Curve-scope data schema, periodic state snapshots, the replay scripts that rebuild the monitoring surface from public data, and every alert configuration, version-controlled throughout the mandate, not handed over on a final day.
- Per the CFP’s own terms: the DAO receives a perpetual license and operational access to the Curve-scoped models, alert configurations, dashboards, documentation, and runbooks; Xerberus retains the right to commercialise the underlying tooling.
- If Xerberus vanishes mid-mandate, the DAO (or its next provider) re-runs the Curve scope without us.
The DAO has just lived through why this matters.
7. What we can’t do yet
We would rather the DAO trust our alerts than discover our gaps later:
- We are unknown in this community. No forum history, no prior Curve mandate. The verification offers in §2 and the structure in §5–§6 exist so that trying us costs the DAO almost nothing.
- Our committed response tier is 12 hours, because that is what is live. Automated watches evaluate as each 12-hour window closes, with intra-window triggers for depeg and oracle-staleness as an escalation tier. We are funded, so this is not a staffing constraint; it is an honesty constraint: the always-on, event-driven alerting tier and the operational routine around it are not built yet. Building them on the Curve scope is a named Phase 1 deliverable, and tightening the committed SLA once proven is a decision the DAO can take when it has seen us work. Until then we commit to 12 hours and will regularly beat it, rather than committing to 2 hours and hoping.
- Llamalend v2 is on Optimism, and V7 is Ethereum-mainnet-only today. The Optimism data plane is a genuine new-chain build. We commit to delivering it by the end of month 3 (Phase 1), ahead of v2 reaching mainnet, with Arbitrum following in month 4 if in-scope markets deploy there; the full chain footprint of in-scope markets is confirmed during Phase 0 so nothing falls silently out of coverage. The remedy if we slip: the following quarter’s payment abates until the Optimism plane is live, and the miss is a termination trigger at the DAO’s option.
- Parameter recommendations are analyst-authored on top of automated evidence. The measurements (tails, absorption, backing, oracle behaviour) are reproducible machine output. The recommendation and the governance post are human work, and the DAO and eDAO retain all decisions and execution, as the CFP specifies.
- Known measurement caveats are printed on the documents themselves: every attached example carries its own honesty box. The largest today: CRV’s on-chain depth floor is under-indexed, because Curve’s own crypto-pool venues are not yet reconstructed in our depth index. In a Curve mandate that gap deserves a schedule, not a caveat: closing it is a named Phase 1 deliverable.
8. KPIs: measurable, and sized to what we actually commit
| KPI | Commitment |
|---|---|
| Monitoring coverage | 100% of active Llamalend markets under automated 12h monitoring; new markets indexed within one window of activation |
| Pre-vote coverage | 100% of in-scope Llamalend proposals receive a published risk memo before the vote (at least 3 business days prior, given 5-business-day address disclosure) |
| Critical-alert escalation | Written escalation to the DAO/eDAO channel within 12 hours of a critical trigger, with a recommended action, logged publicly with outcome |
| Townhall cadence | 12 of 12 monthly public sessions held, each opening with a shipped-versus-requested recap |
| Request follow-through | 100% of townhall and forum monitoring requests triaged with a written disposition in the public register within 10 business days |
| Miss accounting (a KPI we adopt from Pharos’s proposal, with credit) | Every material Llamalend stress event (bad debt, insolvency, exit crunch) receives a public post-incident note stating whether our monitoring flagged it in advance. Misses are reported as misses |
| Public reporting | Semiannual Llamalend market-health report, monthly monitoring digest, and the living findings register |
| Reusable deliverables | Alert configurations, model documentation, runbooks, and the Curve-scoped serving surface delivered per §6, documented quarterly |
9. Team and disclosures
- Simon Peters (LinkedIn), mandate lead: Xerberus founder. Single point of accountability for delivery, DAO communication, the monthly townhalls, and escalation follow-through.
- Noach Detwiler (LinkedIn), quantitative and data lead: built the V7 Curve data plane, including the wei-exact LLAMMA band replay, deploy-block parameter recovery for all 49 lend markets, and the PegKeeper event reconstruction.
- Supported by the ten-person Xerberus engineering team operating the V7 pipeline: ingestion, state reconstruction, simulation, and alerting.
V7 has produced institutional risk dossiers on major DeFi protocols (available to delegates on request via the Swiss Stake channels) and serves a deployed 134-tool query interface. Key-person continuity: Simon and Noach are the named leads on this mandate. If either steps away, the DAO is notified and a named replacement proposed within 10 business days, and the change is itself a review trigger the DAO can act on.
Conflict disclosure. Xerberus publishes an independent public rating of crvUSD (currently S, the top grade on our S-to-F scale; systemic risk 9.6/100). That rating is produced by our open methodology and is outside this mandate: the DAO does not buy influence over it, it can move in either direction, and any change is published with the evidence that drove it. And the deeper version, because our own doctrine demands it: Xerberus’s standing rule is that asset issuers do not pay us to rate their assets, and Curve DAO issues crvUSD and would pay us in CRV. The line we hold is that this mandate buys monitoring, simulation, and reporting; it does not buy the rating. If the DAO ever perceives the mandate and the rating pulling on each other, the correct resolution is to end the mandate: the rating stays.
10. Transition phases and coordination
Coverage is live before Phase 0 begins (§3); the phases describe what gets added on top.
- Phase 0 (weeks 1–4): Monitoring on the DAO’s own alert channel from week 1. Survivability repository stood up per §6. LlamaRisk handoff review, delivered as a written memo classifying materials as reusable, deprecate, or rebuild, with any coverage V7 does not yet replicate flagged so nothing is silently dropped. The 10 October 2025 replay and itemized v1 loss ledger published (§2). Delegate verification access granted. Curve-scoped serving surface stood up. Townhall #1 held, opening with the cascade validation error table (§2).
- Phase 1 (months 2–3): Pre-vote memo pipeline operational. Event-driven Tier-1 alerting built on the Curve scope. Optimism data plane delivered by the end of month 3 (remedy if missed: §7), ahead of the Llamalend v2 mainnet rollout; Arbitrum follows in month 4 if in-scope markets deploy there. Curve crypto-pool depth reconstruction closing the CRV depth gap (§7). Month-3 public checkpoint (§5).
- Phase 2 (month 4 onward): Steady state. v2 coverage in place before mainnet rollout. Semiannual report #1.
Coordination we would ask of Curve contributors: deployment addresses and configuration at least 5 business days before votes; a DAO-owned alert channel; data-interface alignment with Swiss Stake and the backend team where monitoring infrastructure is shared; access to the LlamaRisk transition materials; and data-sharing coordination with the Scope 1 provider, whoever that is.
11. Compliance map
CFP requirements → sections
| CFP requirement | Where |
|---|---|
| Scope covered | §4: Scope 2 committed (Module A); systemic and simulation layer offered across the perimeter (Module B) |
| Optional responsibilities | §4: dashboards and indicators feasible via existing surfaces; gauge and emissions work honestly declined |
| KPIs and reporting cadence | §8 |
| Team background | §9 plus attached documents |
| Tooling, models, approach, dependencies | §1–§2, attached Examples 1–3, §10 coordination |
| Operated services during mandate | §3 |
| DAO-owned deliverables after mandate | §6 |
| Ownership, access terms, documentation, handoff | §6 |
| Coordination needs | §10 |
| Budget, payment structure, trial and review period | §5 |
12. Glossary
Our terms of art: nothing in this proposal requires prior knowledge of Xerberus
| Term | Meaning |
|---|---|
| V7 | Xerberus’ production risk engine (seventh generation). It ingests raw Ethereum events and traces, reconstructs every lending position, pool, wrapper, and oracle read, and computes risk on top. Currently covering roughly $37.5B TVL and $26.9B of debt across 21 protocols. |
| Window | One monitoring cycle. The engine rebuilds its full state every 12 hours; “this window” means the most recent rebuild. |
| Book | The total outstanding debt in one market. |
| Measured tail / worst measured day | A market’s largest single-day soft-liquidation loss share since launch, obtained by replaying every LLAMMA trade at the oracle price recorded in the same transaction. An observed number from the market’s own history, not a modelling assumption. |
| Band replay | The position-by-position reconstruction of LLAMMA’s collateral bands over time, exact to the wei, which is what makes measured tails possible. |
| Stable-loop market | A lending market where a yield-bearing stablecoin is deposited as collateral to borrow another stablecoin at very high loan-to-value, typically to loop the yield. Low price volatility, but exit capacity is the binding risk. |
| Exit depth / absorption | How much of a market’s collateral can actually be sold per day at its liquidation discount, measured from real on-chain pool state (plus listed CEX depth where relevant), not from quoted order books. |
| Backing trace | Resolving what ultimately stands behind an asset by unwrapping it to terminal collateral (e.g. crvUSD resolves today to roughly 67% BTC wrappers plus LSTs, fully on-chain). |
| Cascade engine | Our simulator that propagates a price shock through every reconstructed position across all tracked protocols, including second-round liquidation effects. Validated against replayed historical crises (UST, the stETH discount, Euler, the 2023 Curve/Vyper incident, and others) and a 28-window historical stress backtest; the per-crisis error table is published at townhall #1 (§2). |
| Watch / alert | A standing, parameterized tripwire (depeg, utilization, liquidation spike, oracle staleness, concentration, contagion index) that fires on a clear-to-breached transition and re-arms on recovery. |
| Findings register | The public, living list of open risk items on the Curve scope, each carrying the measurement that justifies it, its status, and its resolution. |
| S–F rating scale | Xerberus’ public rating grades: S (strongest) through F (weakest), with NR for assets below our materiality floor. Methodology is public. |
Prepared by Xerberus for the Curve DAO. We are available in this thread for any question, and via the Swiss Stake channels for anything the contributors prefer to discuss privately.