Is Moonwell Vaults Safe?
Risk Grade: C (45/100)
Moonwell Vaults is rated as elevated risk — multiple novel mechanisms and notable interaction risks.
Moonwell Vaults offer convenient exposure to Morpho lending yields with professional curation. However, the protocol's track record of three security incidents in twelve months, combined with the discontinued bug bounty and ongoing curator transition, creates elevated risk. The underlying Morpho infrastructure is solid, but Moonwell's integration layer has demonstrated persistent vulnerability to oracle attacks. Only suitable for risk-aware users who closely monitor security developments.
Moonwell Vaults is a yield product that deposits your crypto into Morpho lending markets on Base to earn returns from borrower interest. A professional risk curator decides which markets your money goes to and how much goes where, while the vault automatically reinvests your earnings. Think of it as hiring a fund manager who allocates your deposits across different lending opportunities.
TVL
$26M
Mechanisms
5
Interactions
5
Value Grade
C-
Key Risks for Moonwell Vaults Users
Moonwell has been exploited three times in the past year ($320K in Dec 2024, $1.7M in Oct 2025, $1M in Nov 2025) — a concerning pattern of repeated security failures
The protocol discontinued its bug bounty program before the latest exploits, meaning fewer security researchers are looking for vulnerabilities
Your money is managed by a risk curator (recently changed from Block Analitica to Anthias Labs) — you are trusting their judgment on which markets are safe
The November 2025 exploit was caused by a Chainlink oracle glitch — the same type of failure could happen again
Top Risk Factors
- •Moonwell suffered a $1M oracle exploit in November 2025 where a Chainlink price feed malfunction valued 0.02 wrstETH at $5.8M, enabling the attacker to extract 292 ETH. This is the third major security incident in 3 years, demonstrating persistent vulnerability patterns.
- •Moonwell Vaults deploy capital through Morpho isolated markets controlled by external curators (recently transferred from Block Analitica/B.Protocol to Anthias Labs). Curator decisions directly determine which markets receive vault capital and associated risk exposure.
- •The protocol discontinued its Immunefi bug bounty program earlier in 2025, months before the November 2025 exploit. This signals reduced commitment to proactive security and removes a critical defense layer.
How Moonwell Vaults Compares to Peers
Moonwell Vaults ranks #99 of 116 Yield protocols (bottom quartile — among the riskiest). At a risk score of 45/100, it's 8 points riskier than the sector average of 37/100.
Adjacent peers: Looped Hype (C, 44/100) is ranked just safer, and Goose (C, 45/100) is ranked just riskier.
See the full Yield sector leaderboard or the Moonwell Vaults vs Goose comparison.
Common Questions about Moonwell Vaults
Plain-English answers based on Moonwell Vaults's scores across Hindenrank's 8 risk dimensions. The highest-scoring (riskiest) dimension is Track Record (12/15).
Has Moonwell Vaults ever been hacked or exploited?
Moonwell Vaults has a documented incident history that materially raised its risk grade — the track record dimension scored 12/15, near the high end of the scale. Past exploits, governance failures, or contract issues are baked into this rating. Anyone considering deposits should review the incident details before allocating capital.
How much money is at stake in Moonwell Vaults?
Moonwell Vaults currently holds roughly $26M in user deposits. Smaller TVL means individual depositors carry a larger share of any loss event, and it can be harder to exit a position quickly during stress.
What's the worst-case scenario for Moonwell Vaults?
Hindenrank has identified specific collapse scenarios for Moonwell Vaults. The most prominent: "Repeated Oracle Exploit at Scale". The trigger condition is Chainlink oracle malfunction recurs, this time affecting a larger Morpho market receiving Moonwell Vault capital, enabling a more damaging price manipulation attack. Reading through the full scenario list on the protocol page is the single best way to understand the actual failure modes — generic "smart contract risk" is rarely the thing that takes a protocol down.
Is Moonwell Vaults regulated or insured?
Moonwell Vaults has low regulatory exposure on Hindenrank's framework (3/10). The protocol is structured in a way that minimizes counterparty and jurisdiction concentration, though regulatory risk in crypto can change rapidly. No DeFi protocol carries FDIC-style insurance — even with low regulatory risk, depositors are not protected in the way bank customers are.
What are the biggest red flags for Moonwell Vaults?
Hindenrank's retail-focused risk audit flagged: Moonwell has been exploited three times in the past year ($320K in Dec 2024, $1.7M in Oct 2025, $1M in Nov 2025) — a concerning pattern of repeated security failures The protocol discontinued its bug bounty program before the latest exploits, meaning fewer security researchers are looking for vulnerabilities Your money is managed by a risk curator (recently changed from Block Analitica to Anthias Labs) — you are trusting their judgment on which markets are safe
Should beginners deposit into Moonwell Vaults?
Moonwell Vaults's C grade puts it in the elevated-risk band. This is not a beginner-friendly protocol. Anyone depositing here should treat the position as speculative and avoid concentrating significant savings in it.
How does Moonwell Vaults compare to safer Yield alternatives?
Moonwell Vaults is one protocol in Hindenrank's Yield coverage. The safest Yield protocols on the leaderboard tend to share three traits: a long incident-free track record, conservative mechanism design, and high-quality public documentation. Compare Moonwell Vaults against the full Yield ranking before committing capital.
For the full 8-dimension score breakdown, the radar chart, and dependency graph, see the Moonwell Vaults risk report.
Read the Full Moonwell Vaults Risk Report
This protocol has 2 collapse scenarios. 2 high-severity interaction risks identified. See the full mechanism classification, interaction matrix, and deep-dive recommendations.
View Full Report →Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.