Curve
RISK: MEDIUM
Curve Finance is a well-established decentralised exchange (DEX) protocol on Ethereum specialising in stablecoin and pegged-asset liquidity pools, governed by the CRV token. The project has a multi-year public track record and is widely covered in independent DeFi research. However, the retrieval session was heavily degraded — the main site and most sub-pages rendered empty on our side, and all fetched sub-pages returned 404s — meaning most scoring relies on independently known facts about the protocol rather than live site content, and several sub-signals must be marked null.
This report is published free of charge and stays published. It was produced because
somebody paid for the investigation to happen — we never disclose who requested a
report, and paying for one does not influence what it says.
What we could not check. These are gaps in our collection, not findings about
the project. The affected sub-signals were excluded from the score and from the maximum —
the project is not penalised for them.
- The main curve.finance homepage rendered empty on our side; no current product claims, disclaimers, or front-page content could be assessed.
- The /team and /about pages rendered empty on our side; team composition beyond the publicly known founder could not be assessed from site content.
- The /audit and /audits pages rendered empty on our side; direct audit report links hosted on the site could not be confirmed (external sources indicate audits exist).
- The /privacy and /privacy-policy pages rendered empty on our side; privacy policy content and specificity could not be assessed.
- The /terms-of-service and /legal pages rendered empty on our side; full terms of service content could not be assessed.
- All sub-pages fetched (/docs, /whitepaper, /documentation, /security, /tokenomics, /token, /terms, /terms-and-conditions) returned HTTP 404 — these URLs do not exist at curve.finance; content may be hosted at subdomains (e.g., resources.curve.fi, docs.curve.fi) which were outside the retrieval scope.
- Holder concentration breakdown between DAO-controlled addresses and open-market holders could not be verified from retrieved content; raw 57.6% top-10 figure is from on-chain data without composition detail.
On-chain contract data
CRV · Ethereum ·
0xd533a949740bb3306d119cc777fa900ba034cd52
- Owner can mint new supply
- Top-10 holders control 57.6% of supply
- Contract source is verified on the explorer
- Liquidity is NOT locked
These facts are read from the contract and override anything the project's
own material claims. See the live on-chain check →
Scores by category
Team & Transparency
13/20
identities verifiable 6 · track record 5 · public presence 2
- Curve Finance is publicly associated with founder Michael Egorov, who has given interviews, signed on-chain governance transactions, and has an independently verifiable academic and professional background — making the primary founder's identity strongly checkable through external sources.
- The broader core team is not listed on any page our retrieval was able to load; the team page rendered empty on our side, so this is a collection gap rather than a confirmed absence, but no team page content could be assessed.
- Egorov's prior work (NovaBit, physics research background) is referenced in multiple independent news outlets (CoinDesk, The Block, etc.) and is consistent with the technical depth of the protocol, supporting a solid track record score.
- Public presence is evidenced through governance forum participation (gov.curve.fi) and historical Twitter/X activity; however, since social pages were not fetched in this session, the score is kept conservative and reflects only independently known facts.
Tokenomics
10/20
supply documented 2 · holder concentration 2 · unlocks disclosed 2 · token function 4
- The CRV tokenomics sub-pages (/tokenomics, /token) both returned 404 on the fetched URLs; because these are 404s rather than retrieval failures, they are scored as absent on those specific URLs. Tokenomics information is publicly available in Curve's external documentation (docs.curve.fi) and has been widely described, but was not retrievable in this session's scope.
- On-chain, total supply is visible and CRV has a published emission schedule (62% to liquidity providers over approximately 200 years, with annual halving), but this could not be confirmed from site content retrieved here; supply_documented is scored at 2 (partial, known from external sources, not confirmed from site).
- Top-10 holders control 57.6% of supply per verified on-chain data. This is elevated concentration. A significant portion of this is attributable to Curve DAO treasury and veCRV locking contracts, which is normal for this protocol design, but the raw concentration figure remains a risk factor; holder_concentration scored at 2.
- CRV token function is well-documented publicly: governance voting via vote-escrowed CRV (veCRV), gauge weight control, and fee distribution — this is a substantive and independently verifiable utility, scoring full marks for token_function.
- Vesting and unlock schedules have been publicly described (team/investor allocation with 2-4 year vesting from 2020 launch), but could not be confirmed from retrieved site pages; unlocks_disclosed scored at 2.
Technology
14/20
source verified 4 · audit published 4 · repo activity 5 · stage matches claims 1
- Contract source is verified on Etherscan for 0xd533a949740bb3306d119cc777fa900ba034cd52 — confirmed by the on-chain facts provided. Full marks for source_verified.
- The 404 page footer references 'Security Audits' and 'Bug Bounty' as navigation links, indicating these pages exist under different URLs (likely at resources.curve.fi or similar external subdomain). Multiple independent audits of Curve contracts have been published by Trail of Bits, ChainSecurity, and others and are widely cited, but the /security and /audits pages returned 404 within the fetched URL set. Audit score is 4 (strong external evidence, but direct link not confirmed in this session).
- Curve's GitHub repository (github.com/curvefi) is publicly accessible and shows sustained multi-year development activity across multiple repositories; this is independently verifiable and consistent with a production-grade protocol. repo_activity scored at 5.
- The product described — a live DEX with AMM pools, Llamalend, governance, and bridge — is consistent with a deployed and operational protocol at mainnet scale. The main site rendered empty on our side, preventing confirmation of current claims; stage_matches_claims is scored at 1 to reflect that we could not assess current site claims against product state from retrieved content.
Red Flags
14/20
contract mechanics 6 · copied content 4 · impossible claims 4 · manufactured activity 0
- The CRV token contract is verified as mintable (on-chain fact). The minting function is governed by the DAO and the emission schedule encoded in the contract, not by a single owner key in the traditional sense; however, the mintable flag represents a supply-expansion capability that is a structural risk factor. contract_mechanics deducted 2 points for mintable supply.
- No honeypot, buy tax, sell tax, blacklist, or upgradeable proxy was detected per on-chain verification. These are meaningful positives.
- Liquidity locked at 0% is flagged by the on-chain scan. For a mature AMM protocol where liquidity is provided by third-party LPs rather than a project-controlled pool, this is expected and not indicative of the same risk as a new token with no locked liquidity; this is noted but not scored as a red flag in isolation.
- No copied content could be identified from retrieved pages (only 404 pages and footer text were returned). No evidence of impossible claims or guaranteed return language was present in the retrieved content. Manufactured activity signal: not assessable from retrieved content; scored null — however, given Curve's independently verified 100,971-holder count and years of on-chain trading volume, fabricated engagement is not a credible concern based on external evidence.
- The August 2023 reentrancy exploit affecting certain Curve pools (a publicly documented event) is a notable historical security incident. This is a factual prior event, not a current red flag, but should be noted for due diligence completeness.
Legal
3/20
entity disclosed 1 · jurisdiction 1 · terms and privacy 1 · regulatory posture 0
- All legal and terms pages (/terms, /terms-and-conditions, /legal) returned 404 on the fetched URLs. The privacy and terms-of-service pages rendered empty on our side (retrieval failure, not confirmed absence). Together these result in no legal content being assessable from the retrieved material.
- No legal entity name was confirmed in any retrieved page content. The 404 page footer does not name an incorporated entity. entity_disclosed scored at 1 (a Curve DAO structure is publicly referenced in external sources, but not confirmed in retrieved site content).
- No jurisdiction was identified in any retrieved content. Jurisdiction scored at 1 based solely on external public knowledge that Curve DAO operates as a Swiss-style DAO structure, which is not confirmed from retrieved pages.
- Terms of service and privacy policy links appear in the 404 page footer as 'Legal' — suggesting they exist at some URL — but no content was retrieved. terms_and_privacy scored at 1 (link present in footer, content not assessed).
- No regulatory disclosure, geographic restriction notice, or investment disclaimer was present in the retrieved content. regulatory_posture scored at 0 for this session. This is a significant gap for a protocol offering yield-bearing products.
Key risks
- Mintable token supply: the CRV contract retains a mint capability; while governed by the DAO and emission schedule, this represents a structural supply-expansion risk if governance were compromised.
- Elevated holder concentration: top-10 addresses hold 57.6% of supply; even accounting for DAO and veCRV contracts, concentration at this level can amplify governance and market impact risk.
- Legal structure opacity: no legal entity, jurisdiction, or regulatory posture was confirmable from retrieved site content, creating uncertainty about user protections and regulatory compliance status.
- Historical security incident: the August 2023 reentrancy exploit in Vyper-compiled pools resulted in significant losses; residual smart contract risk across the broader pool ecosystem warrants independent verification of which pool types remain exposed.
- Documentation hosted off primary domain: all documentation, audit, and legal sub-pages at curve.finance returned 404; users relying solely on the primary domain for due diligence materials cannot access critical information without knowing the correct subdomain URLs.
- Liquidity locked at 0%: while expected for a decentralised LP-driven AMM, this means protocol-side liquidity guarantees are absent, and LP withdrawal is unrestricted, which can lead to rapid liquidity withdrawal events under stress.
Questions to ask before investing
- Where are the current audit reports hosted, and can direct links to all completed audits (Trail of Bits, ChainSecurity, others) be provided?
- What is the current governance mechanism controlling the CRV mint function — specifically, what multisig or DAO vote threshold is required to mint tokens outside the scheduled emission?
- Is there a legal entity (foundation, association, or LLC) that operates the curve.finance front-end, and if so, in which jurisdiction is it registered?
- Where are the current terms of service and privacy policy hosted, and do they include geographic restrictions relevant to regulated financial products?
- Following the August 2023 reentrancy exploit, what remediation steps were taken and are any affected pools still operational?
- What is the current veCRV locking composition of the top-10 holder addresses — specifically, what share of the 57.6% concentration represents DAO treasury or protocol-controlled addresses versus individual holders?
Scored by the published
ChainSift methodology: five categories
of 20 points each. Sub-signal scores are summed by code, not chosen by a language model.
This is risk assessment, not investment advice, and it describes what was observable on
the date shown. Projects change.