Morpho Blue is DeFi's most institutional-grade permissionless lending primitive with a clean core contract record, formal verification, and $7.75B TVL. The C grade reflects scale-driven systemic risk, oracle surface exposure in long-tail markets, and curator trust model that adds a human attack vector. For large-cap collateral in reputable curated vaults, this is a relatively safe lending venue; for long-tail market exposure, risks are materially higher.
Risk Breakdown
Top Risks
Oracle-agnostic permissionless markets: any oracle can be used in any market, including low-quality or malicious ones; the October 2024 PAXG exploit ($230K) confirmed oracle misconfiguration is the primary attack vector
Curator trust model: MetaMorpho vault curators (Gauntlet, Steakhouse, Re7, etc.) control where LP capital flows; a compromised or malicious curator can shift funds to high-risk markets within the timelock window
Systemic scale: $7.75B TVL across 200+ markets makes Morpho Blue a systemic lending counterparty; a protocol-wide failure would reverberate through the broader DeFi ecosystem
Third-party collateral contagion: sdeUSD (3.6% vault bad debt) and xUSD ($700K) events show that bad collateral in permissionless markets creates bad debt even when core contracts are unaffected
Frequently Asked Questions
Is Morpho Blue safe to use?
What are the main risks of using Morpho Blue?
What is Morpho Blue's risk score breakdown?
How does Morpho Blue compare to other Lending protocols?
Has Morpho Blue ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.