★ Rescue/emergencyWithdraw without timelock
Curve Finance's assessment for RD-F-041 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Emergency DAO can kill pools (freeze deposits/swaps, NOT withdrawals) and kill gauges via 5-of-9 multisig without a 7-day timelock (24h eDAO vote). Explicitly confirmed: eDAO 'unable to take action to pause the pool or handle user funds in any way.' This is a limited operational kill-switch, not a full fund-drain rescue function. Yellow (not red) because direct fund drain is not possible via this path.
Sources #
- DocsCurve DAO Protocol Ownership — Emergency DAO limitationscurve.readthedocs.io/dao-ownership.html — Emergency DAO 'unable to take action to pause the pool or handle user funds'retrieved 2026-04-28
- Curve emergency DAO halts hack-related token rewardscryptorank.io/news/feed/18655 — eDAO terminates gauge rewards (July 2023), confirming limited powersretrieved 2026-04-28
Methodology #
Determine whether a `rescue(…)` or `emergencyWithdraw(…)` function exists callable by admin without a timelock delay on execution.
See the full factor methodology and distribution across all protocols →