Convex Finance is a battle-tested yield protocol with a dominant market position in the Curve ecosystem. However, its governance concentration risks, one-way cvxCRV lock, and dependency on Curve's continued relevance are meaningful concerns. The March 2022 bug and June 2025 downstream Resupply exploit (fully repaid) show ongoing smart contract risk in the ecosystem. Best suited for DeFi-native users who understand the Curve/Convex governance dynamics.
Risk Breakdown
Top Risks
Convex controls ~50% of veCRV voting power, creating systemic Curve governance centralization risk
Smart contract bug history (March 2022 vote-lock bug) and downstream exploit exposure (June 2025 Resupply $9.5M, fully repaid by mid-2025)
73% of CVX supply held by top wallets amplifies governance capture and price manipulation risk
Frequently Asked Questions
Is Convex Finance safe to use?
What are the main risks of using Convex Finance?
What is Convex Finance's risk score breakdown?
How does Convex Finance compare to other Yield protocols?
Has Convex Finance ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.