LibraryCredit and stable value2022Design paperCorpus record
Curve stablecoin design
crvUSD design. Michael Egorov.
A stablecoin lent against volatile collateral, where liquidation is a continuous trade into a special pool rather than a one-shot auction. The paper calls that pool LLAMMA. A peg keeper and a monetary-policy rate sit beside it. Simulations in the paper are not a promise about later losses.
The Curve stablecoin design liquidates continuously. Collateral sits in bands of an AMM called LLAMMA and is converted as an oracle price moves, instead of being sold in one auction. A peg keeper and a borrowing rate try to hold the stablecoin near its reference. The paper's simulation is not a loss guarantee.
The five-minute read
Bands, not a cliff
A price move converts part of the collateral. A bounce can convert some of it back. That is the difference from a vault that auctions everything once a line is crossed.
The oracle is still required
LLAMMA reacts to an external price. It is not itself the oracle. A wrong oracle moves the bands wrongly, continuously.
The peg keeper is a trader
When the stablecoin leaves its peg against a reference coin, the design trades inventory to push it back. That inventory is finite.
The rate is a policy
Borrowing cost changes with the peg. The paper states the direction. It does not state a number you can treat as a market quote for all time.
One action, walked through
- A borrower posts collateral and receives stablecoin, within the design's limits.
- Collateral is placed into LLAMMA bands around the oracle price.
- If the oracle price falls, bands trade collateral toward the stablecoin.
- If the oracle price recovers, bands can trade back, at a cost the paper discusses.
- If the stablecoin itself leaves its peg, the peg keeper and the rate are the other two levers.
The argument, unpacked
Smaller loss is not no loss
The PDF simulates historical ether prices and argues that a short, shallow dip destroys less collateral than a hard liquidation. A simulation inside a design note is not a promise about the next dip, and it is not a track record of a live system.
Three mechanisms, not one
LLAMMA, the peg keeper and the rate do different jobs. A summary that says 'the AMM keeps the peg' has merged them and lost the oracle.
What has to be true
- The oracle updates inside the time the bands were built for. A gap through every band is the failure the design is trying to soften, not a case it cannot see.
- Reference liquidity for the peg keeper exists. An empty reference pool cannot defend a peg.
- Parameters are those of the deployment. The PDF uses examples.
- The stablecoin is not a claim on bank deposits. Nothing in the design adds that claim.
What happened after the paper
crvUSD is the later system built from this note. Read the PDF for LLAMMA and the peg keeper. Read Maker and Liquity for the auction and the stability pool, which are different answers to the same liquidation question. Do not mix their loss stories.
What to check before you use the idea
- What oracle moves the bands?
- What is left for the borrower after a dip and a recovery, in the design?
- Who funds the peg keeper?
- Is a simulation being quoted as a guarantee?
Terms
- LLAMMA
- The lending-liquidating AMM: collateral is converted across price bands as an oracle moves, rather than in a single auction.
- Peg keeper
- A mechanism that trades the stablecoin against a reference asset when the market price leaves the peg.
The problem the paper names
A vault that liquidates all at once can sell into a hole and charge the borrower the whole gap. The design asks whether liquidation can be a band of liquidity that converts collateral to the stablecoin as the price falls, and converts back if the price rises.
What the design proposes
- LLAMMA: collateral sits in a range of AMM bands and is traded as an external price moves.
- A peg keeper trades the stablecoin against a reference coin when the price is off its peg.
- A rate policy changes the cost of borrowing as the peg moves. The paper states the direction of that response.
How the mechanism is specified
- The external price is an input. The design needs an oracle. The AMM does not replace that oracle. It uses it.
- A borrower who is 'liquidated' may still hold a mix of collateral and stablecoin, and may be deleveraged rather than closed. That is the point of the bands.
- The paper includes a historical simulation of ether. A simulation is an illustration inside the PDF, not a track record.
What this page does not treat as proven
- Soft liquidation can still lose value. The paper argues the loss is smaller in its simulation. It does not set that loss to zero.
- The stablecoin is a mechanism claim, not a claim on dollars in a bank.
- Oracle failure, parameter changes, and later governance are outside the theorems, because the paper is a design note rather than a formal proof.
Why a venture studio still reads it
Name the oracle, the band, and who loses if the oracle gaps through the band. If the pitch says liquidations cannot lose money, it is not this paper.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
