Morpho
Moderate risk — elegant design at massive scale, but permissionless market creation and curator trust introduce real attack surface
Top Risks
1
P2P matching engine adds complexity: if matching fails, fallback to pool rates may surprise users
2
Morpho Blue's permissionless market creation allows risky collateral/oracle combinations to emerge
3
Two 2025 incidents: Bundler3 vulnerability put $2.6M at risk (white hat saved), and xUSD bad debt (~$700K) from Balancer hack cascade
4
Relatively short track record at scale compared to Aave/Compound; untested through a severe market crash
Risk Breakdown
Frequently Asked Questions
Is Morpho safe to use?
Morpho receives a B- risk grade (32/100) from Hindenrank, where lower scores indicate lower risk. Moderate risk — elegant design at massive scale, but permissionless market creation and curator trust introduce real attack surface A lending protocol that matches borrowers and lenders directly for better rates, managing $5.9B in deposits with $73.6M in funding. It also lets anyone create isolated lending markets with custom rules. Its B- grade reflects strong architecture and rapid growth, offset by the risk that anyone can create a market with a bad price feed that curators accidentally funnel your deposits into.
What are the main risks of using Morpho?
The key risks identified for Morpho are: (1) Anyone can create a lending market with any price feed. If a market uses a manipulable price source, an attacker can inflate collateral value and steal deposited funds from that market. (2) Vault curators decide where your deposits go across multiple markets. If a curator makes a bad allocation into a risky market, all vault depositors share the losses. (3) At $5.9B, Morpho is one of DeFi's largest lending protocols but has a shorter track record than Aave or Compound. It has not been tested through a severe market crash at this scale.
What is Morpho's risk score breakdown?
Morpho scores 32/100 across eight risk dimensions: Mechanism Novelty: 6/15, Interaction Severity: 5/20, Oracle Surface: 3/10, Documentation Gaps: 1/10, Track Record: 3/15, Scale Exposure: 9/10, Regulatory Risk: 2/10, Vitality Risk: 3/10. The highest risk area is Scale Exposure at 9/10.
How does Morpho compare to other Lending protocols?
Among 90 rated Lending protocols on Hindenrank, Morpho ranks #33 by safety (lowest risk score = safest). Its 32/100 risk score and B- grade place it in the middle tier of Lending protocols.
Has Morpho ever been hacked or exploited?
Morpho scores 3/15 on the Track Record risk dimension, indicating some history of security incidents or exploits. Higher scores reflect more severe or frequent incidents. Review the full risk report for details.
Last scanned 2026-02-26