Convex Finance

Orange · 43/100 Data confidence 96/100

Executive summary

Convex Finance is an Ethereum-based yield aggregator for Curve that pools veCRV to boost LP rewards, scoring 43/100 (orange band). The protocol is run by an anonymous team led by pseudonymous developer "C2tp," with critical operations controlled by a 3-of-5 multisig that manages treasury, parameters, and governance execution—though this multisig has no direct access to user deposits.

  • Security: Audited by MixBytes (April 2021) and ChainSecurity (April 2023), with detailed findings unverified. OpenZeppelin disclosed a critical December 2021 vulnerability enabling potential $15B rug-pull risk before patching; June 2022 DNS compromise affected five wallets. Bug bounty active with up to $250k rewards, but payout history unverified.
  • Governance & custody: Non-custodial for users (deposits into immutable contracts, withdrawable anytime); CRV converts permanently to cvxCRV. Governance via vlCVX token voting with multisig execution; no verified legal entity or named founders. Treasury holds ~9.7% of CVX supply under multisig control.
  • Top risks: (1) Structural dependence on Curve—any Curve failure directly impairs Convex yields and TVL; (2) stablecoin/LST depeg exposure in underlying Curve pools (USDC depegged to $0.87 in March 2023); (3) governance concentration via multisig and large vlCVX holders; (4) permanent CRV lock-up creates illiquidity; (5) regulatory/sector cyclicality risk in DeFi yield farming.
  • Strengths: Delivers higher Curve yields without users locking CRV; simplified one-stop interface; extra CVX incentives; strong meta-governance influence; no major core-contract exploit reported.
  • Incidents: December 2021 vlCVX bug (no funds lost, contract redeployed); June 2022 DNS compromise (five wallets affected, no verified reimbursement amount).
  • Unverified: Exact multisig signer identities and current threshold (sources conflict: 2-of-3 vs. 3-of-5); legal entity status (terms reference "Convex Labs" but independent filings show no disclosed incorporation); circulating supply, market cap, and on-chain treasury balances; protocol-specific stress-test models for collateral depeg or counterparty insolvency; KYC/AML policies and any court cases or enforcement actions.

Score

Component Weight Raw Points Reason
security 25% 65 16.2 1 audit(s); no fresh audit; active bug bounty bonus
incidents 25% 50 12.5 0 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 84 12.6 0 onchain, 23 two-source, 1 one-source of 28 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 8; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Convex Finance is a Curve-focused yield aggregation and boosting protocol on Ethereum, with native token CVX and a set of core contracts centered around the Booster and voting/treasury infrastructure. ### Protocol identification

  • Name: Convex Finance (often “Convex” in DeFi context).
  • Category: DeFi yield aggregator / Curve boosting and rewards redistribution protocol (not a DEX itself; the main functionality is deposit and boost Curve LP positions and manage CRV/CVX voting power).
  • Website: Convex Finance front-end at the convexfinance.com domain.
  • Docs: Hosted at docs.convexfinance.com, including FAQs and contract address list.
  • Chains: Ethereum only for core protocol in this context; key contracts and CVX token are on Ethereum mainnet.
  • Native token: CVX, ERC‑20 on Ethereum at 0x4e3FBD56CD56c3e72c1403e103b45Db9da5B9D2B, labeled “Convex Finance: CVX Token” on Etherscan.
  • Launch date: Public references place Convex’s launch in 2021 as a Curve-focused yield platform; exact block/time is Not verifiable as of 2026-08-29 under current constraints. ### Main Ethereum contract addresses (≥2-source cross-check)
  • CVX token: 0x4e3FBD56CD56c3e72c1403e103b45Db9da5B9D2B
  • Listed in Convex docs contract table.
  • Verified ERC‑20 token on Etherscan under “Convex Finance: CVX Token”.
  • Booster (main deposit contract): 0xF403C135812408BFbE8713b5A23a04b3D48AAE31
  • Named “Booster (main deposit contract)” in docs.
  • Etherscan labels it “Convex Finance: Booster” with verified source code.
  • Voter Proxy (Curve whitelist / vote power contract): 0x989AEb4d175e16225E39E87d0D97A3360524AD80
  • Listed in docs.
  • Etherscan shows contract address with Convex labeling and verified code.
  • Multisig: 0xa3C5A1e09150B75ff251c1a7815A07182c3de2FB
  • Listed as multisig in docs.
  • Visible on Etherscan with Convex-related labeling.
  • Treasury Vault: 0x1389388d01708118b497f59521f6943Be2541bb7
  • Labeled “Convex Finance: Treasury Vault” on Etherscan, holding CVX and other assets.
  • vlCVX locking contract (v2): 0x72a19342e8f1838460ebfccef09f6585e32db86e
  • Appears on Etherscan as “Convex Finance: vlCVX Token V2.0”. All above contracts have verified source code on Etherscan, satisfying explorer verification. ### Fork lineage and modifications
  • Fork status: Convex is not presented as a simple fork of a single upstream protocol; it is a custom system built around Curve staking, reward routing, and vote-escrowed CVX (vlCVX). Its design borrows concepts from Curve’s veCRV and general yield aggregator patterns but is not labeled an explicit fork in official docs.
  • Key differences vs. upstream concepts:
  • Introduces Booster contract architecture to aggregate Curve LPs and boost rewards.
  • Implements vlCVX vote-locked governance and reward sharing separate from Curve’s veCRV model.
  • Uses specialized wrapper tokens (e.g., cvxFXS) for partner assets.
  • Audit coverage of changes: Public audit reports for Convex’s specific contract set are Not verifiable as of 2026-08-29 under current data, so audit status cannot be confirmed here.
  • Malicious-modification history in similar forks: No credible records of Convex Finance deploying malicious changes or of direct forks of Convex with documented malicious modifications were identified in the retrieved data; any such history remains Not verifiable as of 2026-08-29. > Contradiction check box: No direct contradictions were observed between docs’ contract list and explorer data for the core Ethereum contracts; addresses and labels match across independent sources.
Evidence (9)

maturity

two sources

Convex Finance appears to be a mature, live Ethereum dApp rather than a static landing page: its main site describes staking/deposit flows, withdrawal availability, and governance, and the docs include step-by-step deposit instructions plus direct navigation into the app. The documentation set is substantial and current enough to expose markdown/llms index pages and technical integration material, which is consistent with a maintained product surface rather than a template site. Live user actions are explicitly documented: users can deposit Curve/Frax/f(x) LP tokens, earn rewards, and withdraw LP tokens at any time; the docs also describe approve/deposit-and-stake flows in the UI. A public subgraph-based GraphQL API is also listed for Convex analytics, covering pools, deposits, withdrawals, revenue, and user activity, so an open API does exist. I did not find evidence in the gathered sources of broken links, fake metrics, or obvious template signs; however, that specific negative check is not fully verifiable from the available web snippets alone. Not verifiable as of 2026-08-29. Overall verdict: mature and operational frontend + documented user flows + public analytics API, with no clear signs in the retrieved material of a fake or placeholder portal.

Evidence (7)

Security

audit

unverified

Convex Wrapper Audit. The Convex audits page lists an April 2023 audit by ChainSecurity and links the report in the convex-eth GitHub repository. The snippet does not reveal the full issue list or whether all findings were fixed, so detailed severity counts and fix status are not verifiable as of 2026-08-29.

Auditor
ChainSecurity
Report Date
2023-04
Scope
Convex wrapper / related platform components
Evidence (1)

audit

unverified

General Contracts Audit for Convex Finance core platform. The Convex audits page lists this as the ‘General Contracts Audit by MixBytes’ from April 2021 and links the PDF report in the convex-eth GitHub repository. The page indicates this audit is part of the deployed platform’s security review program. The specific count, severity breakdown, and fix-status details are not fully extractable from the search snippet alone, so those fields are not verifiable as of 2026-08-29.

Auditor
MixBytes
Report Date
2021-04
Scope
General contracts / core platform
Evidence (1)

audit

one source

Convex Finance also has additional audit entries referenced by external summaries, including the Frax staking platform and sidechain-related reviews, but the search results provided here do not expose enough of those reports to reliably enumerate findings or remediation status. Because on-chain verification is unavailable in this run, whether each report covers deployed Ethereum code specifically is only partially inferable from the audit titles and is otherwise not verifiable as of 2026-08-29.

Auditor
PeckShield
Report Date
2022-04
Scope
Frax staking platform
Evidence (1)

audit

unverified

Convex Wrapper Audit. The Convex audits page lists a September 2022 audit for the Convex staking wrapper and links the corresponding report in the convex-eth GitHub repository. The snippet does not expose the full findings table or remediation status, so critical/high/medium findings and fix status are not verifiable as of 2026-08-29.

Auditor
PeckShield
Report Date
2022-09
Scope
Convex staking wrapper
Evidence (1)

bug bounty

unverified

Convex Finance appears to have an active bug bounty program. The program details page is a Convex docs page, and the available materials show a payout table with rewards ranging from $1,000 to $250,000 depending on severity and likelihood; the highest listed payout is $250,000 for an almost-certain, high-severity issue. I could not verify the exact start date from the provided sources. The docs page confirms the program exists, but the search results do not include a launch date or archival page showing when it began. Therefore, the start date is Not verifiable as of 2026-08-29. Parameters shown in the sources:

  • Rewards are tiered by Likelihood and Severity.
  • Payouts listed are $1,000, $10,000, $50,000, and $250,000 across the matrix.
  • Reports should be sent promptly to Convex’s bug bounty contact address listed in the docs. Results / outcomes:
  • The materials provided do show at least one historical security issue was responsibly disclosed and no loss of funds occurred in the vote-locked CVX contract migration incident.
  • However, I could not verify a public ledger of bounty payouts, number of reports, or aggregate bounty results from the provided sources. Those results are Not verifiable as of 2026-08-29.
Evidence (3)

counterparty risks

two sources

Convex Finance is a meta-yield aggregator on top of Curve; its core risk is concentrated exposure to Curve, its tokens, and the broader stablecoin/LST ecosystem. 1. Protocol & counterparty dependencies

  • Curve Finance (primary dependency): Convex deposits user liquidity into Curve pools and optimizes CRV rewards; CRV/veCRV and Curve gauges are structural dependencies. A critical Curve smart contract failure, governance takeover, or reward cessation would materially impair Convex yields and potentially TVL.
  • Curve tokens (CRV, CVX, veCRV, vlCVX): Convex’s business model and governance power rely on accumulated veCRV and CVX staking; price collapse of CRV/CVX reduces incentives and could trigger feedback loops in leveraged positions using these tokens as collateral on other protocols.
  • Other DeFi protocols: Convex positions are widely rehypothecated (e.g., as collateral on lending markets like Aave, Frax-based systems, etc.); stress there can force deleveraging of Convex LP and reward tokens, amplifying volatility. 2. Stablecoin & LST/restaking exposure
  • Stablecoin pools on Curve: Convex heavily farms major Curve pools (3pool, stables like USDT/USDC/DAI, FRAX, etc.). A depeg or insolvency of any constituent stablecoin (e.g., USDT/USDC/DAI/FRAX) would cause LP losses for Convex depositors and reduce TVL and fee revenue.
  • LST/LST-backed pools: Convex also routes into Curve’s LSD/LST pools (stETH, frxETH, etc.). An LST depeg or validator slashing event would impair those pools, leading to losses for Convex users in affected vaults.
  • Restaking exposure: Where Curve integrates LRTs or restaked-LST pools (e.g., EigenLayer-linked assets), Convex inherits smart contract and slashing risk from those ecosystems via the underlying Curve pools. 3. Oracles & manipulation risk
  • Curve AMM pricing: Convex does not run its own price oracles; it inherits Curve’s AMM-based pricing and any associated manipulation risk (e.g., low-liquidity pool attacks) that can impact reward distributions and LP PnL.
  • External oracle risk: Any Curve pool that relies on Chainlink or other oracles for parameters (e.g., lending-style pools or metapools) passes through oracle failure/manipulation risk to Convex depositors. 4. Bridges, custodians, CEX/MM, RWA
  • Bridges: Core Convex deployment is on Ethereum; cross-chain variants/“Convex-like” deployments elsewhere use bridges, but for the specified Ethereum instance direct bridge risk is limited to users who bridge LP tokens or rewards themselves.
  • Custodians & CEX/MM exposure: Convex is non-custodial; however, CRV/CVX liquidity and price formation depend on CEXs/MMs. Exchange failures or delistings could impair liquidity, affecting collateral uses and liquidation cascades.
  • RWA issuer/SPV risk: Indirect only, via any Curve pools that hold RWA-backed stablecoins (e.g., USDC, tokenized T-bills). Issuer/SPV credit and regulatory risk transmit to Convex through those pools. 5. Failure / depeg / insolvency scenarios
  • Curve smart contract exploit: Loss of LP funds in Curve vaults translates nearly 1:1 to Convex users.
  • Stablecoin or LST depeg: Direct mark-to-market losses in affected pools; governance tokens (CRV/CVX) may also sell off, impairing incentives.
  • Governance capture of Curve or Convex: Malicious gauge allocation or reward redirection could strand user positions or siphon rewards. On-chain verification of specific TVL or position sizes: Not verifiable as of 2026-08-29.
Evidence (3)

crypto custody

two sources

Convex Finance’s custody model is non-custodial for end users in the sense that users deposit assets into smart contracts and can withdraw their LP tokens at any time; Convex says its contracts are immutable and non-custodial. For CRV deposits, Convex locks the CRV into Curve’s veCRV system and returns users a 1:1 tokenized claim called cvxCRV; the docs describe this as a one-way conversion, meaning the user no longer directly holds the original CRV inside Convex custody. For CVX holders, custody is split between normal staking and vote-locking: locked CVX is used to create vlCVX, which gives governance voting rights and extra rewards. Administrative control is concentrated in a 3-of-5 multisig, which can adjust protocol parameters, manage the treasury, and direct emissions, but the available sources state that this multisig has no direct access to user deposits. The Convex Treasury is separately controlled by that multisig and is reported as holding about 9.7% of CVX supply.

Evidence (4)

incident

two sources

In December 2021, OpenZeppelin reported a severe bug in Convex’s vlCVX locking/incentives system that could have enabled a very large rug-pull style risk against locked assets. Convex redeployed a new contract, said no funds were lost and user deposits were not jeopardized, and the old contract was abandoned because the system was immutable. The fix was a contract redeployment, and the vulnerability was reportedly patched after disclosure. I could not verify any reimbursement because no customer loss was reported.

Date
2021-12-14
Cause
smart_contract_exploit
Loss Usd
None
Evidence (3)

incident

two sources

In June 2022, Convex Finance disclosed a DNS/front-end compromise that caused users to approve malicious contracts; the team said five wallets were affected, while funds in verified Convex contracts were safe. The reported response was to warn users to review approvals, set up alternate domains, and investigate the breach. Affected users were asked to contact the team, but I could not verify any public reimbursement or a quantified loss amount from the available sources. The fix was to move users to new URLs and address the domain compromise.

Date
2022-06-23
Cause
frontend_infra_hack
Loss Usd
None
Evidence (3)

key management

two sources

Convex Finance’s key management appears to be organized around a small multisig-controlled admin layer rather than a foundation or broad on-chain admin system. The strongest independent source in the results says the protocol has no foundation with pause, upgrade, or executor authority; those powers sit with a 3-of-5 multisig at 0xa3C5A1e09150B75ff251c1a7815A07182c3de2FB, which controls key protocol parameters, treasury address changes, Curve voting, fee settings, deposit pausing, and vlCVX-related controls. An earlier security review also found a manual upgrade path and identified the Convex deployer as a single EOA controlled by a private key, plus a Gnosis multisig as the main control point. That report described the multisig as 2-of-3 at the time of review, with three named owners and control over components such as the Booster, Voter Proxy, and Pool Manager. So the practical answer is: Convex centralizes critical operational keys in a multisig, while the protocol’s smart contracts are marketed as immutable and non-custodial for users. However, there is a discrepancy between sources on the multisig threshold and signers: the due-diligence report reflects an earlier 2-of-3 configuration, while the later token-transparency filing describes a 3-of-5 setup with different participants. The on-chain state of the multisig is not verifiable here, so the exact current signer set is Not verifiable as of 2026-08-29.

Evidence (3)

smart-contract

two sources

Convex Finance on Ethereum is a multi-contract yield aggregator with core contracts controlled by governance and, in some cases, a security council; however, full on-chain verification via Dune is Not verifiable as of 2026-08-29. ### Key Contracts & Verification

  • Main contracts (e.g. ConvexToken, Booster, staking rewards) are deployed on Ethereum and are verified on Etherscan, with source code and ABI visible.
  • Architecture is modular: Booster coordinates Curve pool deposits; reward contracts handle CRV/CVX distribution; lockers manage CVX vote-locking. ### Upgradeability & Admin Roles
  • Several contracts use Ownable-style admin with owner able to set parameters (reward distributions, fees, whitelist strategies).
  • Governance has migrated from original multi-sig to DAO-style governance using CVX voting, with proposals and parameter changes recorded in Convex governance forums and Snapshot/DAO tooling.
  • Emergency or guardian roles exist for pausing deposits/strategies or adjusting reward contracts; exact role mapping contract-by-contract is Not verifiable as of 2026-08-29 from on-chain tables.
  • Some components are non-upgradeable (fixed logic), while others can be redeployed/redirected via admin-controlled settings (e.g., changing reward contract addresses). ### Timelocks & User Exit
  • Governance proposals typically include timelock or delay mechanics at the protocol-process level (off-chain governance followed by on-chain execution), but a precise on-chain timelock duration per contract is Not verifiable as of 2026-08-29.
  • Users can withdraw underlying Curve LP tokens and claim rewards as long as Booster and reward contracts are functioning; there is no global admin needed to approve individual exits. ### Worst-Case Admin Key Compromise If admin/owner keys or governing multisig are compromised:
  • Attackers could:
  • Redirect rewards to attacker-owned addresses.
  • Change fee parameters to confiscatory levels.
  • Pause deposits/withdrawals where pause hooks exist.
  • Potentially misconfigure strategies to send funds to malicious contracts.
  • Core Curve LP tokens are generally held in Convex’s contracts; a fully malicious upgrade or parameter change could block exits or misdirect new deposits, though exact steal-vs-freeze risk is contract-specific and Not verifiable as of 2026-08-29. ### Architecture Map (High-Level)
  • Users → deposit Curve LP → Booster → Curve gauge.
  • Rewards (CRV, CVX, others) → Reward contracts / Staking contracts → users.
  • CVX lockers → voting power in Curve and Convex governance.
  • Governance / Multisig / Security council → admin roles on Booster, rewards, fee setters, and some emergency controls.
Evidence (3)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Convex Finance is run by an anonymous, pseudonymous team with no verified legal entity, founders, or physical office publicly disclosed as of the latest available data. Founders & team identity

  • Multiple independent sources (Kraken, Bitstamp, DeFiSafety, Omniscia, Kraken UK documentation) state that Convex was created and launched by an anonymous or pseudonymous team, not by named individuals.
  • The lead figure is known only by the handle “C2tp” (also written C2tP/Ct2P), described as the sole or lead pseudonymous developer; there is no confirmed real‑world identity behind this handle.
  • A number of web articles that attribute Convex to known DeFi personalities (e.g., Michael Egorov, Charlie Noyes, “Ricardo Rosales”) conflict directly with exchange due‑diligence material and specialist risk reviews and appear to be low‑quality or inaccurate summaries. These claims are not independently corroborated and should be treated as unreliable marketing-style content. Prior track record / projects
  • Reputable profiles (Kraken, Bitstamp) only infer that the founder(s) likely have a software / DeFi development background, based on GitHub and governance activity, but explicitly note this is not verified.
  • No credible source ties C2tp or the team to specific prior projects, successful or hacked. Not verifiable as of 2026‑08‑29. Public vs. anon; governance & centralization
  • DeFiSafety’s due‑diligence and Omniscia’s centralization review explicitly classify the team as anonymous and note the difficulty of mapping on‑chain control (deployer EOA, multisig signers) to real‑world persons or entities.
  • This anonymity exacerbated disclosure complexity around a past critical vulnerability identified by OpenZeppelin (a potential large rug‑pull vector that only Convex devs could exploit, later patched). Jurisdiction, office, and “real business” footprint
  • There is no reliable evidence of a registered company, office, or on‑shore jurisdiction that is clearly linked to the DeFi protocol Convex Finance. UK corporate and brand records and various “Convex/ConvEx” finance companies refer to unrelated TradFi or corporate‑finance businesses, not the DeFi protocol.
  • As of 2026‑08‑29, Convex should be treated as a purely on‑chain protocol with an anonymous team and no verifiable formal corporate wrapper, making it closer to a web‑native collective than a conventional, regulated business entity. From an institutional risk lens, this anonymity and lack of clear jurisdiction/office materially increases key‑person, governance, and enforcement risk, even though the protocol is widely used and has undergone third‑party security scrutiny.
Evidence (8)

general reputation

two sources

Convex Finance has a generally strong DeFi reputation as a long-running Ethereum yield protocol tied to Curve, but it also has meaningful security-history and governance risks. Its publicly listed external audit evidence includes a MixBytes general contracts audit (April 2021), and OpenZeppelin later disclosed that a late-2021 review found a critical vulnerability that could have given the Convex multisig direct control over roughly $15 billion in locked value before it was patched. On founders/investors: the search results did not provide a reliably sourced, protocol-specific founder or investor profile beyond Convex’s own documentation, so those details are not verifiable as of 2026-08-30. Sentiment in the sources is mixed-positive: the project is treated by audit firms and security reviewers as a major, established DeFi protocol, but there is clear criticism that some live code may have launched without comprehensive external audit coverage, and that the multisig control model created a severe trust assumption. On fraud/rug/insolvency allegations, the only strong allegation surfaced was from an AML-network watchdog page claiming money-laundering and sanctions-evasion links; however, that source is not independently corroborated here, and I would treat it as an unverified allegation rather than established fact. I found no reliable evidence in the gathered material of a confirmed rug pull, insolvency event, or formal fraud finding against Convex. Legal/regulatory: no confirmed lawsuit, enforcement action, or sanctions designation was verified in the gathered sources for Convex Finance itself. The protocol documentation acknowledges risk and auditors, but that is not a legal finding. Unresolved concerns: security-history dependence on a multisig, limited clearly verifiable audit coverage for all live code, and the general governance/MEV/bribe-driven nature of Convex’s Curve-boosting model.

Evidence (5)

Economy

TVL: $449.3M

model

two sources

Convex Finance is a yield aggregator for Curve on Ethereum that pools veCRV to grant maximum boost to Curve LPs and monetize that boost for CRV holders and CVX stakers. Strategy & assets in/out

  • In: Curve LP tokens and CRV deposited by users.
  • Convex stakes LP tokens in Curve, using a large protocol-owned veCRV position to apply up to 2.5x reward boost to LPs.
  • CRV deposits are permanently locked as veCRV; users receive cvxCRV 1:1 as a liquid claim on the veCRV position. Yield sources & organic vs. subsidized
  • Primary yield is organic: boosted CRV emissions and Curve trading fees (3CRV) to LPs and cvxCRV stakers.
  • Additional, more subsidized/incentive-driven components:
  • CVX token rewards to Curve LPs and CRV/cvxCRV stakers.
  • Bribes/governance incentives to veCRV/cvxCRV voting power (indirect to holders). Risk profile: market‑neutral vs directional; leverage
  • Core positions are unlevered Curve LPs plus CRV locked as veCRV; no native leverage/looping or restaking inside Convex.
  • Exposure is directional to CRV, CVX, and underlying Curve pool assets (often stablecoins but also volatile tokens).
  • External exposure comes from Curve’s gauge/bribe economy; Convex votes gauges to maximize revenue. Lock‑ups, withdrawal mechanics
  • Curve LP deposits via Convex: no additional lock‑up beyond Curve; users can withdraw LP tokens and rewards subject to normal network conditions.
  • CRV converted to cvxCRV is permanently locked as veCRV at protocol level; exit requires selling cvxCRV on secondary markets rather than redeeming CRV. Fees, gates, limits, protocol revenue
  • Convex charges a performance fee (~16% of boosted CRV rewards), distributed entirely to Convex users:
  • 10% to cvxCRV stakers/CRV stakers.
  • 5% to CVX stakers.
  • ~1% to harvest caller.
  • DefiLlama notes fees and revenue metrics including protocol revenue and holder revenue (CVX/cvxCRV stakers and liquid derivatives). Collateral, TVL, APY history
  • Collateral is primarily Curve LP positions and locked CRV (via veCRV); no borrowing means no liquidation collateral in the usual sense.
  • TVL by chain: Convex is Ethereum‑only; all TVL is on Ethereum.
  • Exact TVL levels, product split, and trends are Not verifiable as of 2026-08-30 without on‑chain or fresh analytics queries.
  • APY history is driven by Curve CRV emission schedules, trading volume, bribes, and CVX incentive programs, so volatile and regime‑dependent rather than stable; sustainability depends on ongoing CRV emissions and governance incentive budgets. Key economic takeaway Convex’s model is to aggregate veCRV, sell the boost and governance power to Curve LPs and CRV holders, and distribute performance fees plus CVX inflation to LPs, cvxCRV stakers, and CVX stakers, creating reflexive exposure to the Curve/CVX/bribe ecosystem rather than a market‑neutral yield source.
Evidence (15)

reserves

two sources

Convex Finance’s reserve/treasury picture on Ethereum is only partially verifiable from the provided web results, and the on-chain balance component is Not verifiable as of 2026-08-29 because Dune access is unavailable in this run. Off-chain, independent sources consistently describe a treasury allocation of 9.7% of 100,000,000 CVX (about 9.7 million CVX) and note that the treasury is governed by a 3-of-5 multisig; CoinGecko also surfaces a specific treasury wallet (0x1389) in its supply breakdown, but that wallet-level balance is an aggregator view, not raw on-chain verification. What can be said with confidence is that Convex’s reserve composition is token-based rather than a large stablecoin treasury: the cited allocation scheme places most “reserves” in CVX itself plus operational holdings for incentives and governance, while DefiLlama separately reports a protocol treasury estimate of $10.12m and breaks protocol assets into own tokens, stablecoins, majors, and others. Because these are aggregator estimates and not raw-chain queries, they should be treated as directional only. For custody and control, the most specific publicly cited claim in the results is the 3-of-5 multisig governing the treasury, with signers named as C2tP, Winthorpe, Charlie, Tommy, and Sam. The reserve policy appears to be to hold the treasury allocation for future incentives or community-driven activities, but that policy is sourced from secondary tokenomics summaries rather than a formal treasury policy document, so it should be treated as an unverified marketing/summary claim unless confirmed in governance records. Attestations of reserves are limited in the provided results: there is no auditor- or protocol-issued reserve attestation here, and the only concrete references are token distribution summaries and aggregator balance breakdowns.

Evidence (5)

tokenomics

two sources

Convex Finance does have a native token: CVX on Ethereum. 1. Token identity & supply

  • Token: Convex Finance (CVX), ERC‑20 on Ethereum.
  • Contract: 0x4e3fbd56cd56c3e72c1403e103b45db9da5b9d2b.
  • Max/total supply: Hard‑capped at 100,000,000 CVX.
  • Circulating supply / market cap / FDV: Not verifiable as of 2026-08-29 (no tools; rely on aggregators like CoinGecko/CoinMarketCap, which may differ). 2. Token utility & governance
  • Primary utilities:
  • Stake CVX to receive vlCVX (vote‑locked CVX) which controls Convex’s voting power over Curve gauge weights via locked veCRV.
  • vlCVX holders receive platform fees (a share of Convex’s CRV/CVX revenue) and bribes from protocols buying Curve emissions.
  • Governance: vlCVX votes on Convex governance proposals and on how Convex’s aggregated veCRV voting power is deployed in Curve. 3. Revenue share, buybacks, burns, staking rewards
  • Convex charges a performance/platform fee on Curve staking yields and redistributes a large portion to cvxCRV stakers and vlCVX lockers.
  • Part of protocol revenue is used to market-buy CVX and CRV which are then distributed to stakers (buy‑pressure rather than hard burn).
  • No routine burn mechanism for CVX is documented; supply is capped instead. 4. Emissions & unlocks
  • Emission schedule: CVX emissions follow a declining schedule with halving‑like reductions in rewards per CRV deposited, ending at 100M max supply.
  • Unlock schedule: No new CVX minting or vesting after max supply; historical team/investor/airdrop allocations are fully unlocked by design (no ongoing linear vesting).
  • Whether specific historical unlocks occurred on-chain is Not verifiable as of 2026-08-29. 5. Allocations & concentration
  • Initial allocation (high‑level):
  • Liquidity mining/community incentives: majority of supply.
  • Team & treasury: minority share with multi‑year vesting (now effectively completed).
  • No large VC round is highlighted in original tokenomics; protocol is primarily yield‑driven.
  • Exact current top-holder concentration, insider wallets, and distribution are Not verifiable as of 2026-08-29. 6. Control functions & listings
  • CVX is a standard capped ERC‑20; no public evidence of arbitrary mint/blacklist/fee‑switch functions in the main token contract (but full verification requires on‑chain inspection – Not verifiable as of 2026-08-29).
  • Governance/treasury is controlled by a multi‑sig and vlCVX governance processes.
  • DEX liquidity: Deepest liquidity historically on Curve and Uniswap on Ethereum; also listed on major CEXs (Binance, Coinbase, etc.), but exact current depth is Not verifiable as of 2026-08-29.
Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 would most likely be a severe *risk-off shock* for Convex Finance (CVX), but the direct impact on Convex is not verifiable as of 2026-08-29 from the available sources. The best-supported inference is that CVX would likely fall with the broader crypto market, with outsized downside because it is a high-beta altcoin and because existing commentary already frames CVX as sensitive to broader market sentiment and Bitcoin moves. What can be said with some confidence is that the scenario described for BTC at $10,000 is a tail-risk, crisis-level outcome, not a normal drawdown. Independent market commentary in the search results says such a move would likely require extreme global stress, including deep recession, severe liquidity contraction, persistent ETF outflows, leverage cascades, and/or major geopolitical or plumbing shocks. For Convex specifically, the available evidence suggests the main transmission channels would be:

  • Correlation shock: CVX already shows underperformance when Bitcoin weakens, indicating amplified beta.
  • Liquidity shock: A market-wide deleveraging event would likely compress demand for governance and yield tokens like CVX.
  • Sentiment shock: Existing analysis describes CVX as vulnerable to broader crypto rotations and momentum loss rather than a unique protocol-specific catalyst. However, protocol-level stress metrics such as on-chain treasury exposure, revenue resilience, and chain-specific TVL concentration are Not verifiable as of 2026-08-29 in this run because on-chain checks are unavailable. Bottom line: a sub-$10k Bitcoin likely implies severe downside pressure for CVX, but the magnitude for Convex cannot be quantified from the provided sources without on-chain verification.
Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

Convex Finance does not have a publicly verifiable, protocol-specific stress-test model in the provided sources for a scenario where the largest collateral depegs 20%. Convex’s own risk page only states that losses are possible and does not publish a collateral-specific stress framework or asset-by-asset exposure map, so the impact of a 20% depeg is Not verifiable as of 2026-08-29. What can be said from the available sources is only generic: a 20% collateral depeg would reduce the market value of any positions or reserves that depend on that collateral, and DeFi liquidation mechanics typically react when collateral value falls relative to debt. However, Convex Finance is primarily a yield/boosting protocol built around Curve liquidity incentives, and the supplied sources do not show a lending book, borrow balances, or a collateralized balance sheet that would let me quantify a loss under that shock. So the risk answer is qualitative only: exposure exists only if Convex directly holds the depegging asset or has protocol assets economically linked to it, but the size of that exposure is Not verifiable as of 2026-08-29.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Convex Finance on Ethereum, a “top counterparty insolvent” stress is only partially verifiable from public sources; the protocol documents audits and says contracts are immutable, non-custodial, and third-party audited, but that does not eliminate counterparty or dependency risk.

  • Expected loss path: the loss would most likely enter through the external venue or pool Convex is interacting with, then propagate into the specific Convex wrapper/reward flow tied to that venue; any shortfall would first hit the affected strategy or pool, not every Convex user uniformly.
  • Who absorbs it: in the base design, users in the affected pool/strategy absorb the loss economically because Convex’s contracts are reward-routing and staking wrappers, not an insured balance sheet.
  • Compensation: I found no public, protocol-level guarantee of principal protection or insolvency compensation. Convex’s published materials emphasize audits and risk review, but do not state an insurance backstop.
  • Impact path through smart contracts: the likely impact is operational rather than a global protocol failure—reward accrual, deposits/withdrawals, or wrapper accounting for the impacted integration could degrade if the external counterparty/pool fails, while unrelated Convex pools should continue operating normally unless they depend on the same venue. Relevant contradiction / limitation: Convex’s marketing language claims contracts are immutable, non-custodial, and audited, but an external review notes that only part of the codebase was originally audited and some live contracts were out of scope or changed after audit, so audit coverage is not a guarantee against insolvency-linked losses. Because on-chain verification is unavailable in this run, the exact exposure concentration and loss magnitude are Not verifiable as of 2026-08-29.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For Convex Finance on Ethereum, I found no verified evidence that the Convex DAO or owners committed fraud. The strongest available sources instead describe Convex as a non-custodial protocol with immutable contracts and document a known governance/operational weakness involving fake gauges and shutdown mechanics, which is a risk scenario but not proof of fraud. The most relevant allegation in the search results is not against Convex itself: it concerns the Mochi Finance founder and a 2021 Curve/Convex-related governance attack narrative, where Convex was used as part of the attack path. That is an allegation about another project’s conduct and does not establish fraudulent conduct by Convex DAO or its owners. Assessment:

  • Fraud by Convex DAO/owners: Not verifiable as of 2026-08-29.
  • Protocol risk posture: Convex publicly acknowledges a known path that could abuse fake gauges and the shutdown system, but states it is mitigated through DAO proposal, shutdown, and timelock requirements.
  • Most credible interpretation: If you are stress-testing for “committed fraud by the DAO or owners,” the current evidence set does not support that claim; it supports a concern about governance/design exploits and third-party misuse. Important caveat: the protocol’s own website claims the contracts are immutable and non-custodial, but that is an *unverified marketing claim* unless independently corroborated.
Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For Convex Finance, the key stress implication of a negative 30d primary yield source is that the protocol’s core reward stream is under pressure, so depositor returns can compress materially even if principal remains intact. Convex’s stated function is to boost Curve rewards by pooling CRV and passing boosted emissions to users, so a sustained drawdown in the primary yield source would directly reduce the economic value of that boost. In a stress scenario, this is best treated as a revenue/yield shock rather than a solvency shock: if the underlying Curve-linked rewards fall for 30 days, Convex’s ability to deliver attractive APY weakens first, and only secondarily does this affect user retention and TVL. The most relevant external macro analogy is a broader risk-off environment, where yields and risk appetite can deteriorate sharply; the Federal Reserve’s severely adverse scenario is explicitly built around a severe global recession, declining risky-asset prices, and elevated volatility. A practical institutional interpretation is:

  • Primary yield source negative 30d = lower expected depositor APY, weaker incentive to stay parked in the vaults.
  • TVL sensitivity = likely negative if capital is yield-seeking and mobile.
  • Protocol credit risk = not directly indicated by this scenario from the available sources. What is not verifiable as of 2026-08-29 from the provided sources is Convex’s current Ethereum-chain TVL, the exact 30-day realized yield trajectory, and any quantified drawdown threshold from on-chain data. The web results only support the qualitative stress interpretation, not a chain-level measurement. If you want, I can turn this into a compact risk memo format with: shock, transmission, likely impact, and monitoring points.
Evidence (2)

Governance & Legal

governance

two sources

Convex Finance is governed by a token-based DAO (vlCVX holders) with significant additional control retained via multisigs and delegates, so governance is partially decentralized but not purely on-chain. Not verifiable on-chain as of 2026‑08‑29. ### Who controls what

  • Core contracts (Convex staking/boosting on Ethereum): Upgradability and parameter changes are governed by Convex governance (CVX/vlCVX voting) plus designated governance multisig(s) that can execute approved changes or emergency actions.
  • Funds (treasury, fees): Controlled by the DAO via governance votes; execution typically goes through a multisig with signers selected by the community or core team.
  • Frontend / website: Operated by the core Convex team (not a DAO-controlled asset); this is effectively company/developer controlled. This is an unverified marketing claim unless explicitly confirmed by independent sources. ### Governance design and proposal process
  • Token & voting: Governance uses CVX, with voting power coming from vote-locked CVX (vlCVX); lockups give proportional voting rights in proposals and gauge votes for Curve.
  • Proposal flow:
  • Ideas usually discussed in forum and Discord.
  • Formal proposals are voted on-chain or via Snapshot by CVX or vlCVX holders (depending on proposal type).
  • Execution of successful proposals is performed by governance contracts and/or multisig.
  • The DAO is real (controls fees distribution, incentives, parameter changes) but symbolic to the extent that technical execution and frontend remain in the hands of a smaller group. ### Voting concentration & top holders
  • Detailed holder distribution, voting concentration and top vlCVX holders cannot be verified on-chain via Dune in this run: “Not verifiable as of 2026‑08‑29.” ### Timelock / multisigs / powers
  • Convex governance uses multisigs for:
  • Treasury management.
  • Contract upgrades/emergency powers.
  • Key design elements (exact timelock parameters, signer list, thresholds, and independence of signers) require explorer or Dune contract inspection and are Not verifiable as of 2026‑08‑29 in this environment.
  • Typical powers include:
  • Updating strategy contracts.
  • Adjusting reward configurations.
  • Moving treasury funds in accordance with governance decisions. ### Legal entity / ToS
  • Public sources do not clearly identify a parent company (name, jurisdiction, registration, directors) for Convex Finance; this is Not verifiable as of 2026‑08‑29.
  • Any Terms of Service hosted by Convex would be treated as unverified marketing claims unless corroborated independently.
Evidence (4)

legal & regulatory

two sources

Convex Finance’s publicly identifiable legal posture is mixed: its current terms reference “Convex Labs” with a California governing law and exclusive jurisdiction clause for customer disputes in Los Angeles County, but a separate independent filing states Convex Finance operates without a publicly identified legal entity, incorporation record, or jurisdiction disclosed for the protocol itself. On KYC/AML and user restrictions, I did not find a verified, protocol-specific policy in the gathered sources; based on the available material, KYC/AML requirements are not verifiable as of 2026-08-29. The same is true for sanctions-screening controls and formal user-eligibility restrictions: not verifiable as of 2026-08-29. On classification and enforcement risk, the main regulatory concern is that the protocol may be treated as a technology or service operated through a legal wrapper for certain commercial arrangements, while the core DeFi protocol itself appears to lack a clearly disclosed on-chain legal person. That gap increases actual enforcement and counterparty risk relative to the paper legal structure, because claims against a protocol can be difficult to map to a responsible entity. I found no verified court cases, regulatory actions, or sanctions listings specifically naming Convex Finance in the gathered sources. Court cases and enforcement actions are not verifiable as of 2026-08-29. For data protection, the available sources do not provide a protocol-specific privacy/data-processing framework sufficient to verify obligations, controller/processor status, or retention rules. Data protection details are not verifiable as of 2026-08-29. Overall legal-risk view: the strongest verified point is the presence of a California-governed contractual framework for Convex Labs, but that does not eliminate the broader legal uncertainty around the DeFi protocol’s actual operating entity, venue for claims, and regulatory classification.

Evidence (3)

Stability

stability

two sources

For Convex Finance, the stablecoin exposure used on Ethereum is not verifiable from the provided sources alone, so the exact answer depends on which Convex pool or wrapper token you mean. If you mean the main stables used in Convex’s Curve-related Ethereum strategy set—especially USDC and DAI—then yes, depegs have happened: both USDC and DAI depegged during the March 10–13, 2023 banking event, with USDC falling about 13% below $1 and reaching roughly $0.87; the cited sources do not provide a protocol-specific count of how many times Convex’s stablecoin basket depegged, only market-wide history for the stablecoins themselves. The last clearly documented depeg in the provided sources is the March 10–13, 2023 USDC event (also affecting DAI), with USDC at about $0.87, i.e. around 13% below peg. A separate secondary source lists a USDT event on May 12, 2022 at about $0.945 (around 5.5% below peg), but this was a market-wide USDT event, not Convex-specific. So, in short: yes, depegs happened for stablecoins relevant to Convex’s Ethereum strategies; the last one in the sources was March 2023, and the largest cited drop was USDC to about $0.87 (≈13%). The number of times this occurred for the exact stablecoin(s) used by Convex is Not verifiable as of 2026-08-29 from the supplied material.

Evidence (3)

Risks & Strengths

risks

two sources

Convex Finance’s top five risks are: 1) Dependence on Curve and connected protocols — Convex explicitly says users are exposed to risks from Curve.fi and Frax because Convex integrates directly with them; a failure or exploit in those systems would flow through to Convex users. 2) Smart-contract / protocol risk — Convex acknowledges that users can lose some or all funds, and third-party analysis flags contract vulnerability as a continuing risk. 3) Governance concentration / capture risk — external risk analyses highlight that large holders and Convex’s meta-governance position can concentrate voting power and influence protocol outcomes. 4) Liquidity and lock-up risk — cvxCRV is described as permanently locked, while locked CVX requires a long waiting period before it can be moved, creating illiquidity during stress events. 5) Regulatory and sector cyclicality risk — Convex is exposed to broader DeFi drawdowns, weaker TVL/rewards in bear markets, and potential regulatory scrutiny of yield farming and liquidity protocols.

Evidence (5)

strengths

two sources

Convex Finance’s top strengths are: higher Curve yields without users having to lock CRV themselves; simplified yield management for Curve LPs through a one-stop interface; extra reward streams via CVX incentives on top of boosted CRV and trading fees; strong meta-governance influence in the Curve ecosystem through aggregated veCRV voting power; and a security/reliability reputation supported by third-party audits and no major core-contract exploit reported in the provided sources. These strengths are repeatedly described across independent coverage as Convex’s core value proposition on Ethereum, with the main theme being capital-efficient optimization of Curve positions rather than a separate standalone yield strategy.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 23 two independent sources, 1 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-29.