Moderate risk — elegant design at massive scale, but permissionless market creation and curator trust introduce real attack surface
Risk Breakdown
Top Risks
P2P matching engine adds complexity: if matching fails, fallback to pool rates may surprise users
Morpho Blue's permissionless market creation allows risky collateral/oracle combinations to emerge
Two incidents on record: Bundler3 vulnerability put $2.6M at risk (white hat rescued, 2025), and xUSD bad debt (~$700K) from Balancer hack cascade; Resolv USR stablecoin depeg (March 2026) caused cascading liquidations on Morpho Blue — Morpho contracts unaffected but curator-allocated vault depositors faced exposure
Governance: $256M+ in cumulative protocol fees directed to the Morpho Association (French nonprofit) rather than the DAO treasury. MIP 94 (May 2026) routed Berachain license fees to the Association over the DAO, passing despite community requests for fee amount disclosure that went unanswered. Fee switch exists in smart contracts (up to 25% of borrower interest) but has never been activated. The Aave Chan Initiative departed over concentrated voting power; recent governance proposals attract 8–12 voters.
Frequently Asked Questions
Is Morpho safe to use?
What are the main risks of using Morpho?
What is Morpho's risk score breakdown?
How does Morpho compare to other Lending protocols?
Has Morpho ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.