DeFiPunk'd

Curvance

Lending

TVL $73.3M
Type Lending
Chain Monad
View on DeFiLlama ↗
Control criteria
Upgradeability Unknown Bug bounty docs.curvance.com Governance forum Docs docs.curvance.com
About

Curvance is a lending and borrowing protocol deployed on Monad Mainnet that lets users deposit crypto assets as collateral, borrow against them, and earn yield simultaneously. The protocol uses ERC4626-based cTokens (collateral and borrowable variants) organized into isolated MarketManagers, each focused on a specific financial thesis (e.g., LST markets, stablecoin markets). Users interact via PositionManagers and Zapper plugins; CVE token emissions are distributed through per-market GaugeManagers with optional vote-escrow locking for boosted rewards.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 79 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 7 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Curvance has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 79addresses
  • 0verified source
  • 0proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-04-26.

Monadadmin0x1310…12ffdiscovery
Monadoracle (ChainlinkAdaptor)0xacfe…9c00discoveryoracle
Monadoracle (Oracle Manager)0x32fa…cdb6discoveryoracle
Monadoracle (RedstoneClassicAdaptor)0x0fa6…331ediscoveryoracle
Monadoracle (RedstoneCoreAdaptor)0x1779…16d8discoveryoracle
Monadother (AUSD DynamicIRM, loAZND market)0xf4e1…95aadiscovery
Monadother (AUSD DynamicIRM, muBOND market)0x08dc…8cd5discovery
Monadother (cAUSD DynamicIRM, earnAUSD market)0x46e2…b904discovery
Monadother (cAUSD DynamicIRM, sAUSD market)0x22dc…07bbdiscovery
Monadother (cAUSD DynamicIRM, WMON/AUSD market)0x72cb…d1badiscovery
Monadother (cUSDC DynamicIRM, WBTC/USDC market)0x9f57…1e86discovery
Monadother (cUSDC DynamicIRM, WETH/USDC market)0x034f…ab26discovery
Monadother (cUSDC DynamicIRM, WMON/USDC market)0x1622…afb4discovery
Monadother (cWBTC DynamicIRM)0x8a78…1adediscovery
Monadother (cWETH DynamicIRM, ezETH market)0xf23d…2a23discovery
Monadother (cWETH DynamicIRM, WETH/USDC market)0x8c82…7739discovery
Monadother (cWMON DynamicIRM, aprMON market)0x0d44…13f4discovery
Monadother (cWMON DynamicIRM, WMON/USDC market)0x5026…87b4discovery
Monadother (NativePositionManager, aprMON market)0x82f8…67c8discovery
Monadother (NativePositionManager, shMON market)0x2faa…72fediscovery
Monadother (ProtocolReader view contract)0x878c…a6d2discovery
Monadother (SimplePositionManager, aprMON market)0x6697…1770discovery
Monadother (SimplePositionManager, earnAUSD market)0xd807…b881discovery
Monadother (SimplePositionManager, ezETH market)0xd8d3…c584discovery
Monadother (SimplePositionManager, gMON market)0x77b9…66eediscovery
Monadother (SimplePositionManager, loAZND market)0x9e46…a917discovery
Monadother (SimplePositionManager, muBOND market)0xa3d2…29e4discovery
Monadother (SimplePositionManager, sAUSD market)0x491e…fd57discovery
Monadother (SimplePositionManager, shMON market)0x7e87…9d5ediscovery
Monadother (SimplePositionManager, sMON market)0x3d6b…11ecdiscovery
Monadother (SimplePositionManager, WBTC/USDC market)0x8ca5…57f6discovery
Monadother (SimplePositionManager, WETH/USDC market)0x3a1b…ff73discovery
Monadother (SimplePositionManager, WMON/AUSD market)0x2619…8c74discovery
Monadother (SimplePositionManager, WMON/USDC market)0x960c…20efdiscovery
Monadother (VaultPositionManager, sAUSD market)0xe94a…41a1discovery
Monadother (WMON DynamicIRM, gMON market)0x034c…5c7bdiscovery
Monadother (WMON DynamicIRM, shMON market)0x16cb…b1bcdiscovery
Monadpool (caprMON/cWMON Market Manager)0x5ea0…b1acdiscovery
Monadpool (cearnAUSD/cAUSD and cWMON/cAUSD Market Manager — shared address)0xd636…8545discovery
Monadpool (cezETH/cWETH Market Manager)0x8384…7c37discovery
Monadpool (cgMON/cWMON Market Manager)0xb00a…e42fdiscovery
Monadpool (cloAZND/AUSD Market Manager)0x7c82…4f90discovery
Monadpool (cmuBOND/AUSD Market Manager)0x830d…c944discovery
Monadpool (csAUSD/cAUSD Market Manager)0xbbe7…41ebdiscovery
Monadpool (cshMON/cWMON Market Manager)0xe1c2…43e2discovery
Monadpool (csMON/cWMON Market Manager)0xe597…d05bdiscovery
Monadpool (cWBTC/cUSDC Market Manager)0x01c4…aea9discovery
Monadpool (cWETH/cUSDC Market Manager)0xb3e9…bb49discovery
Monadpool (cWMON/cUSDC Market Manager)0xa6a2…1093discovery
Monadrouter (NativeVaultZapper plugin)0xbfe3…5ec0discoveryrouter
Monadrouter (SimpleZapper plugin)0x91da…b22ediscoveryrouter
Monadrouter (VaultZapper plugin)0x9cb6…13f1discoveryrouter
Monadtimelock0x2677…8c08discoverytimelock
Monadvault (caprMON cToken)0xd9e2…ab26discoveryvault
Monadvault (cAUSD cToken, loAZND market)0xdadb…983ddiscoveryvault
Monadvault (cAUSD cToken, muBOND market)0x2b4e…09ecdiscoveryvault
Monadvault (cAUSD cToken, WMON/AUSD market)0x6e18…04d8discoveryvault
Monadvault (cearnAUSD cToken)0x852f…263ddiscoveryvault
Monadvault (cezETH cToken)0x20f1…220bdiscoveryvault
Monadvault (cgMON cToken)0x5ca6…f11fdiscoveryvault
Monadvault (cloAZND cToken)0xf7a6…a735discoveryvault
Monadvault (cmuBOND cToken)0x92ee…dbf1discoveryvault
Monadvault (csAUSD cToken, earnAUSD market)0xad4a…abf2discoveryvault
Monadvault (csAUSD cToken)0x84c5…d9acdiscoveryvault
Monadvault (cshMON cToken)0x926c…6230discoveryvault
Monadvault (csMON cToken)0x4948…c928discoveryvault
Monadvault (cUSDC cToken, WBTC/USDC market)0x7c9d…6f1ddiscoveryvault
Monadvault (cUSDC cToken, WETH/USDC market)0x21ad…97b5discoveryvault
Monadvault (cUSDC cToken, WMON/USDC market)0x8ee9…1774discoveryvault
Monadvault (cWBTC cToken)0x3d2f…28d5discoveryvault
Monadvault (cWETH cToken, ezETH market)0xa206…0227discoveryvault
Monadvault (cWETH cToken, WETH/USDC market)0x8af0…7d50discoveryvault
Monadvault (cWMON cToken, aprMON market)0xf32b…84f2discoveryvault
Monadvault (cWMON cToken, gMON market)0xf473…c925discoveryvault
Monadvault (cWMON cToken, shMON market)0x0fce…b183discoveryvault
Monadvault (cWMON cToken, sMON market)0xebe4…d708discoveryvault
Monadvault (cWMON cToken, WMON/AUSD market)0xe01d…22eddiscoveryvault
Monadvault (cWMON cToken, WMON/USDC market)0x1e24…10d4discoveryvault
Monadvault (sAUSD token, Agora sAUSD market)0xfd49…d73cdiscoverytoken

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@Curvance

Security

[curated] Source: curated human overlay [:] Source: DEFI@home quorum
Security contact
security@curvance.com

Technical

[:] Source: DEFI@home quorum
Upgradeability
Unknown

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-07-13 09:20 UTC