Moonwell Vaults offer convenient exposure to Morpho lending yields with professional curation. However, the protocol's track record of three security incidents in twelve months, combined with the discontinued bug bounty and ongoing curator transition, creates elevated risk. The underlying Morpho infrastructure is solid, but Moonwell's integration layer has demonstrated persistent vulnerability to oracle attacks. Only suitable for risk-aware users who closely monitor security developments.
Risk Breakdown
Top Risks
Moonwell suffered a $1M oracle exploit in November 2025 where a Chainlink price feed malfunction valued 0.02 wrstETH at $5.8M, enabling the attacker to extract 292 ETH. This is the third major security incident in 3 years, demonstrating persistent vulnerability patterns.
Moonwell Vaults deploy capital through Morpho isolated markets controlled by external curators (recently transferred from Block Analitica/B.Protocol to Anthias Labs). Curator decisions directly determine which markets receive vault capital and associated risk exposure.
The protocol discontinued its Immunefi bug bounty program earlier in 2025, months before the November 2025 exploit. This signals reduced commitment to proactive security and removes a critical defense layer.
Frequently Asked Questions
Is Moonwell Vaults safe to use?
What are the main risks of using Moonwell Vaults?
What is Moonwell Vaults's risk score breakdown?
How does Moonwell Vaults compare to other Yield protocols?
Has Moonwell Vaults ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.