Morpho Blue

Green · 87/100

Executive summary

Morpho Blue is a minimalist, permissionless lending protocol with isolated markets, scoring 45/100 (orange band) with high data confidence (89/100) and a -10 penalty for unresolved incident remediation.

  • Security: Multiple audits by Cantina, ChainSecurity, OpenZeppelin, and Spearbit (2023–2025) covering core contracts, IRMs, and periphery; Cantina competition found 1 high and 8 medium issues (all acknowledged, not fixed); OpenZeppelin identified 1 high (bad-debt socialization bypass) and 1 medium (fee avoidance), both acknowledged but unresolved; $2.5M bug bounty active on Cantina; bytecode-to-deployment matching and fix verification are not verifiable as of September 2026.
  • Incidents: October 2024 PAXG/USDC oracle misconfiguration ($230k borrowed against $350 collateral, claimed reimbursed but not independently verified); May 2025 Base Aerodrome LP oracle manipulation ($49k bad debt, curator reimbursed in full); November 2025 Stream Finance xUSD depeg (exposure and loss unverified, status unresolved); March 2026 Resolv USR key compromise (~$6.2M vault exposure, remediation in progress, reimbursement unverified); April 2026 Kelp rsETH bridge incident (curators report no user losses); April 2025 frontend interception (no loss, white-hat returned funds).
  • Governance & custody: Hybrid governance—core contracts immutable, DAO controls treasury, fee switch (capped 25%, currently off), and approved LLTVs/IRMs via 5/9 multisig (0xcBa…9AFa); noncustodial for users; vault curators manage allocation but cannot pause withdrawals or seize funds; signer independence not verified; Morpho Association (France) holds operational control.
  • Top risks: Oracle failure/manipulation (high severity, market-specific, immutable once set); bad debt from liquidation shortfalls (socialized to lenders per market, not protocol-wide); collateral/issuer risk (stablecoins, LSTs, RWAs, bridged assets); permissionless market creation allows weak configurations; residual unresolved audit findings (high-severity bad-debt bypass acknowledged, not fixed); cross-market contagion via shared assets and correlated liquidity despite isolation design.
  • Strengths: Capital-efficient isolated markets with flexible risk parameters; minimal governance surface (core immutable, no admin drain); permissionless market creation; low gas costs; strong institutional backing (a16z, Coinbase Ventures $18M seed); active bug bounty; noncustodial architecture; no protocol-wide stablecoin depeg risk.
  • Unverified: Deployed bytecode matching to audited commits across all 12 chains; per-chain exposure, bad-debt levels, and current collateral composition; exact loss/recovery amounts for xUSD and USR incidents; multisig signer independence; sustainability of organic vs. subsidized yields; real-world withdrawal success rates.
  • Recommended exposure: Conservative allocation (≤5% of DeFi portfolio) given unresolved high-severity audit findings, multiple oracle/collateral incidents, and remediation-in-progress status; limit to Ethereum and Base (largest TVL, most audit coverage); avoid markets with stale/centralized oracles, thin liquidity, or unaudited collateral; prefer established vault curators with documented incident response; monitor bad-debt levels and curator actions; exit if fee switch activates without transparent distribution or if governance multisig composition degrades.
  • Open questions: Verify deployed bytecode matches audited commits on target chains; confirm current bad-debt exposure and per-market collateral composition; validate multisig signer independence and rotation policy; assess organic yield sustainability without subsidies; review vault curator track records and incident-response protocols; confirm final loss/reimbursement status for xUSD and USR incidents; evaluate oracle quality and liquidity depth for target markets; verify withdrawal queue behavior under stress.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 21 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 80 16.0 full audit within 365 days (latest 2026-05-08); auditor not in top-20 -20
Incidents 20% 100 20.0 3 open incident(s), $6,200,000 at risk (1 with unknown loss) = 0.1% of TVL (threshold 10%)
Governance 20% 100 20.0 immutable contracts: no upgrade path, no admin drain
TVL 20% 55 11.0 TVL $9,722,912,112 = 55% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 26/57 verified facts; 57/57 fresh (180d)

Identification

protocol identification

two sources

Morpho Blue is a minimalist lending protocol that allows isolated, oracle-optional lending markets, designed as the successor to Morpho’s earlier Aave/Compound overlays. ### Basic identification

  • Name: Morpho Blue
  • Category: DeFi lending / money market protocol
  • Website: morpho.org (Morpho main site; Morpho Blue is the core product).
  • Docs: docs.morpho.org (section “Morpho Blue”).
  • Launch date: Morpho Blue was announced/introduced in Q4 2023; on-chain launch is Not verifiable as of 2026-09-03.
  • Chains: Public sources consistently show Morpho Blue live on Ethereum mainnet and Base; some references mention plans/framework for multi-chain, but direct confirmation for Arbitrum, OP, Polygon or the long-tail chains in your list is Not verifiable as of 2026-09-03.
  • Native token: The broader Morpho protocol has the MORPHO token (governance/points system discussion in docs and governance). Whether Morpho Blue has a distinct native token beyond MORPHO is Not verifiable as of 2026-09-03. ### Main contract addresses & verification Because Dune MCP and direct on-chain queries are unavailable, all on-chain details are non‑verified:
  • The literature and explorer references clearly indicate a core Morpho Blue factory / main contract on Ethereum, but exact addresses and their explorer verification status are Not verifiable as of 2026-09-03 (no consistent ≥2-source cross-check without direct explorer access).
  • Likewise, addresses on Base and other chains are Not verifiable as of 2026-09-03. ### Fork lineage & design origin
  • Morpho Blue is not a simple fork of Aave or Compound; it is described as a ground‑up design that reuses general DeFi concepts (isolated markets, risk parameters) but with a minimal core and externalized risk management.
  • The protocol explicitly moves away from Morpho’s earlier “overlay” model (which sat on top of Aave/Compound) to a base-layer lending primitive, with clear separation between risk managers, liquidity providers, and borrowers. ### Audits and fork‑risk history
  • Morpho Blue has undergone formal audits by multiple well-known auditors (e.g., trail-of-bits / other firms referenced in docs and audit pages). Precise audit report dates and coverage details are Not verifiable as of 2026-09-03.
  • I found no documented malicious-modification incidents in Morpho Blue forks or copies; the existence of significant forks and any abuse history is Not verifiable as of 2026-09-03. Given tool constraints, any specific addresses, chain deployments beyond Ethereum/Base, and TVL-style figures must be treated as Not verifiable as of 2026-09-03 and rechecked directly on explorers and Dune when available.
Evidence (4)

maturity

two sources

Morpho Blue appears to be a real product portal, not just a marketing landing page: the documentation exposes live integration paths for deposits and withdrawals, SDK flows, and app ecosystem references, including an app entry for app.morpho.org and guides for vault deposits/withdrawals and Blue market interactions. The docs also describe an SDK surface for Blue markets and a developer API/docs area, which is a strong sign of operational product maturity and an open developer interface. There is evidence of live app functionality, but the exact real-world deposit/withdrawal success rate is not verifiable here; the docs explicitly support deposit, withdraw, borrow, repay, and collateral actions, while the app ecosystem page says the app is for depositing, managing, and exiting positions.

The presence of a minimal open-source interface in GitHub also suggests the product is beyond a static landing page. I did not find reliable evidence of fake metrics, broken links, or template-site fingerprints in the available sources, so those remain Not verifiable as of 2026-09-03. The main website itself publishes headline counters, but without on-chain verification here they should be treated cautiously as unverified marketing claims.

Open API: yes, at least for developers. The docs expose a developer section, SDKs, and API-oriented resources for accessing user, market, vault, and position data, indicating an open integration surface rather than a closed consumer-only app.

Evidence (6)

Security

bug bounty

unverified

Morpho Blue has an active bug bounty program run on Cantina. The program page shows a maximum reward of $2,500,000, with severity-based payouts of Critical $2,500,000, High $50,000, Medium $10,000, and Low $3,000; the page also lists a $30 deposit requirement and 1,674 findings submitted. The program start date shown is 27 Mar 2024.

Reported results on the bounty page are not fully summarized in the available data, but the program records 1,674 submissions, and a separate Morpho security blog notes the bounty was being raised to $2.5M in June 2024. The legacy Morpho bug bounty page is a different program and is not the current Morpho Blue bounty.

Active
Yes
Platform
Cantina
Max payout
$2.5M
Since
2024-03-27
Evidence (3)

counterparty risks

unverified

As of September 5, 2026, Morpho Blue’s counterparty risk is primarily market-specific rather than a single protocol-wide dependency. Markets are isolated, permissionless, and immutable; each embeds its own collateral, loan asset, oracle, LLTV, and interest-rate model. Therefore, failure of one market’s collateral, oracle, bridge, issuer, or custodian should principally create losses in that market, but shared assets and correlated liquidity can transmit stress across markets. Oracles/manipulation — high structural risk. Morpho is oracle-agnostic; curators or market creators select the oracle, which cannot be changed after deployment.

Thin DEX liquidity, stale feeds, NAV/issuer-controlled pricing, feed composition errors, or depeg-driven price gaps can cause under-liquidation or bad debt. Morpho’s own guidance specifically warns that an overvalued oracle can make supplied liquidity insolvent, particularly in Vault V1 configurations. External protocols and assets. Markets can use stablecoins, LST/LRT or restaking tokens, bridged assets, and RWA tokens; these introduce issuer, redemption, custodian/SPV, bridge, sanctions, and insolvency risk. Any CEX, market-maker, or institutional borrower exposure is market- and asset-specific, not an inherent Morpho Blue liability.

Exact dependency composition and exposure by the 12 supplied chains: Not verifiable as of September 5, 2026 (Dune MCP unavailable; no on-chain substitute used). Failure scenarios: (1) collateral depeg or issuer default → liquidations fail or produce bad debt; (2) oracle manipulation/staleness → excessive borrowing; (3) bridge halt or custodian freeze → collateral becomes illiquid; (4) stablecoin insolvency/redemption suspension → lenders face impaired withdrawals; (5) correlated liquidation across shared collateral/loan assets → liquidity shortfall. Morpho’s status page reports no September 2026 incident, but this does not establish that every external dependency is healthy. Contradiction callout: No quantified protocol-wide exposure can be reconciled against prior claimed figures because on-chain verification was unavailable. Not verifiable as of September 5, 2026. Assessment: high tail risk at individual-market level; low direct custody/counterparty risk at the core-contract layer; material indirect risk through curated markets and vault allocations.

Evidence (4)

crypto custody

two sources

Morpho Blue’s custody is organized as a noncustodial smart-contract system: users keep control of their assets through their own wallets and private keys, and Morpho states it does not hold, manage, or control users’ digital assets. For the product layer, Morpho Vaults are also described as noncustodial; the curator configures risk parameters and allocation rules but cannot take custody of user funds, and users can deposit and withdraw from a vault at will subject to available liquidity. No withdrawal pause is indicated in the retrieved materials; the docs explicitly say the curator cannot pause withdrawals, so withdrawal_paused is set to false.

Assets are not described as segregated in the legal sense; instead, deposits are pooled in vault contracts and allocated across approved markets, so segregated_assets is set to false.

Withdrawal paused
No
Segregated assets
No
Evidence (7)

incident

two sources

13 October 2024 — Ethereum, LeadBlock-curated PAXG/USDC Morpho Blue market. Cause: oracle configuration error in the decimal SCALE_FACTOR overstated PAXG collateral by 10^12; an attacker borrowed approximately 230,002 USDC against about $350 of PAXG. Affected: the isolated market, its vault allocation, and a direct lender.

The curator reported the borrow was repaid outside Morpho, that no user funds were lost, and that the market should not be used. LeadBlock implemented additional market-creation and oracle-testing controls. Contradiction: independent incident analyses describe the event as a ~$230k loss, while LeadBlock reported full reimbursement; the repayment cannot be independently verified without on-chain tooling.

Current status: remediation_in_progress; the faulty market is no longer an active lending venue. Reimbursement: claimed by LeadBlock; current repayment status is Not verifiable as of September 4, 2026.

Date
2024-10-13
Cause
Oracle manipulation
Loss
$230K
Attacker proceeds
$230K
Status
remediation in progress
Recovered
$230K
Reimbursed
Yes
Evidence (3)

incident

one source

Morpho Blue’s only clearly documented incident since launch was the April 10, 2025 Morpho App frontend vulnerability. Independent reporting and Morpho’s own incident post say a white-hat interceptor stopped a user transaction, no malicious attacker was involved, and the core Morpho Protocol contracts were unaffected. The event is best classified as a frontend_infra_hack rather than a smart-contract exploit.

Date
2025-04-10
Cause
Frontend / infrastructure hack
Loss
$0
Status
resolved
Recovered
$2.6M
Reimbursed
Yes
Evidence (2)

incident

two sources

Morpho Blue has a documented critical vulnerability incident reported on 2025-04-11: a user-initiated transaction in the Morpho App was intercepted by a white hat, but Morpho stated this was not a hack/exploit, no malicious actor was involved, the protocol contracts were unaffected, no user funds were lost, and the returned amount was reportedly reimbursed to the user via the white hat/responsible-disclosure process. The issue was limited to the frontend app layer, and Morpho said the user funds were returned in full and the researcher received a bounty. A separate June 2023 vulnerability report also shows the project has previously paid a bounty of USD 285,000 for a disclosed issue, but that predates Morpho Blue and is an ecosystem security reference rather than a Morpho Blue incident.

For the October 2024 Morpho Blue PAXG/USDC oracle-related exploit claim and the 2025 April interception claim, the web results conflict; the safer reading is that the April event was a frontend/security demonstration rather than a confirmed on-chain loss event.

Date
2025-04-11
Cause
Frontend / infrastructure hack
Loss
$0
Evidence (3)

incident

unverified

25 May 2025, 23:29 UTC — Base, Aerodrome cUSDO/USDC AMM-LP collateral market. Cause: a custom LP oracle valued raw AMM reserves using a hardcoded USDO price and external USDC pricing, allowing flash-loan-driven reserve manipulation. The attacker overborrowed, self-liquidated, and repeated the maneuver.

Realized lender bad debt was 49,303.14 USDC; the post-mortem’s net loss after the attacker’s own supplied liquidity was 40,303.47 USDC. Affected: lenders to the isolated market and the Clearstar OpenEden USDC Vault. Response: the curator covered the full shortfall within hours, switched the market to close-only, set vault allocation to zero, and allowed borrowers to close positions.

Morpho’s core contracts were not the root cause; the custom oracle/market curation was. Current status: resolved. Users were reimbursed in full and no external lenders reportedly incurred losses.

Date
2025-05-25
Cause
Oracle manipulation
Loss
$49K
Attacker proceeds
$13K
Status
resolved
Recovered
$49K
Reimbursed
Yes
Evidence (1)

incident

two sources

4 November 2025 — Stream Finance disclosed an approximately $93 million loss at an external fund manager, causing xUSD to depeg. xUSD-backed Morpho markets used fixed or stale pricing, preventing timely liquidation and leaving lenders exposed to bad debt. Multiple Morpho vaults and downstream positions were affected. Curators and integrated protocols began pausing allocations, reducing exposure, and pursuing liquidations or recovery claims.

The realized Morpho-specific loss, amount recovered, and reimbursement outcome are not independently established: Not verifiable as of 2026-09-05. Current status: unresolved.

Date
2025-11-04
Cause
Depeg / collateral
Status
unresolved
Event id
stream-xusd-2025-11-04
Evidence (3)

incident

two sources

22 March 2026 — Resolv USR private-key compromise caused approximately 80 million unbacked USR to be minted and USR to depeg. The resulting stale/hardcoded wstUSR collateral pricing on Morpho enabled borrowing against impaired collateral. Fifteen Morpho vaults were affected; approximately $6.2 million of liquidity was routed into the affected markets, with an independent analysis attributing about $5.95 million to Gauntlet vaults and $0.25 million to other vaults.

Morpho core contracts were not compromised. Response: curators set caps to zero, exited or isolated affected markets, and disabled relevant allocator flows; Resolv paused operations, burned or blacklisted illicit tokens, and introduced staged recovery/redemption programs. No independent evidence verifies that Morpho vault users were fully reimbursed.

Exact final realized loss remains subject to curator-level reconciliation: Not verifiable as of 2026-09-05. Current status: remediation_in_progress.

Date
2026-03-22
Cause
Key compromise
Loss
$6.2M
Attacker proceeds
$25.0M
Status
remediation in progress
Event id
resolv-usr-2026-03-22
Evidence (4)

incident

two sources

18 April 2026 — Kelp DAO's LayerZero bridge incident minted approximately 116,500 unbacked rsETH. Morpho markets had limited exposure to rsETH-related collateral. Curators rapidly set rsETH supply caps to zero, exited affected markets, emptied supply queues, and disabled allocator flows.

Available independent curator reporting states that the affected Morpho vaults incurred no user losses or bad debt. Attacker proceeds are not reliably established. Current status: resolved.

Date
2026-04-18
Cause
Bridge / third-party collateral failure
Loss
$0
Status
resolved
Recovered
$0
Event id
kelp-rseth-2026-04-18
Evidence (3)

incident

one source

A March/April 2026 report says Morpho had about $1 million in ETH lending exposure during the Kelp DAO rsETH bridge incident, but the available source only states Morpho had minimal exposure and does not document a direct loss at the protocol level. The incident is therefore not verifiable as a Morpho Blue loss event from the available evidence.

Date
2026-04-19
Cause
Liquidity issue
Status
status unknown
Evidence (1)

incident

two sources

Bug bounty coverage is active and material: Morpho docs say there is an ongoing Cantina bounty of $2.5M for Morpho Blue, Morpho Midnight, and Morpho Vaults, and Immunefi’s program page says critical web/app issues can pay up to $50k, with KYC required for payout. Historic docs also show the legacy bug bounty covered smart contracts and frontend, with reports requiring a PoC.

Date
2026-08-26
Cause
Other
Evidence (3)

key management

two sources

Morpho Blue’s key management is organized as a layered, role-separated system rather than a single custodian holding user assets. At the base layer, Morpho Blue is governance-minimized: governance cannot halt a market, control funds on users’ behalf, or dictate a specific oracle implementation, so most risk decisions are pushed outward to market configuration and higher-layer vaults. On top of Blue, MetaMorpho/Vaults provide the main risk-management layer, where deposits are routed into Blue markets by designated roles such as the owner, curator, guardian, and allocator.

The vault curator handles market selection and allocation, while users remain noncustodial and can withdraw subject to underlying market liquidity. Operationally, this means key decisions are split by function: Blue defines the immutable market primitive, while vault governance keys/roles manage which markets are enabled, how capital is allocated, and when allocations are rebalanced. This separation is intended to reduce trust concentration: the protocol layer is minimal and immutable, and the strategy layer is managed by curators and related roles rather than by the core protocol itself.

Not verifiable as of 2026-09-03: chain-by-chain differences in key-management setup across Arbitrum, Base, Ethereum, Hyperliquid L1, Katana, Monad, OP Mainnet, Polygon, Robinhood Chain, Stable, Tempo, and Unichain, because the provided sources do not establish a per-chain key-management inventory.

Evidence (4)

smart-contract

one source

Assessment (as of September 5, 2026; Dune unavailable): Morpho Blue core is deployed as a direct, non-proxy Morpho contract; the repository source has no proxy, delegatecall, pause, emergency-withdrawal, or upgrade function. Explorer/source links are published for each deployment. Core addresses: Ethereum 0xBBBBBbbBBb9cC5e90e3b3Af64bdAF62C37EEFFCb; Arbitrum 0x6c247b1F6182318877311737BaC0844bAa518F5e; Base 0xBBBBBbbBBb9cC5e90e3b3Af64bdAF62C37EEFFCb; Hyperliquid L1 0x68e37dE8d93d3496ae143F2E900490f6280C57cD; Katana 0xD50F2DffFd62f94Ee4AEd9ca05C61d0753268aBc; Monad 0xD5D960E8C380B724a48AC59E2DfF1b2CB4a1eAee; OP Mainnet 0xce95AfbB8EA029495c66020883F87aaE8864AF92; Polygon 0x1bF0c2541F820E775182832f06c0B7Fc27A25f67; Robinhood Chain 0x9D53d5E3bd5E8d4Cbfa6DB1ca238AEA02E651010; Stable 0xa40103088A899514E3fe474cD3cc5bf811b1102e; Tempo 0x10EE9AAC980A180dd4DcFc96C746d60B0EA88f97; Unichain 0x8f5ae9CddB9f68de460C77730b018Ae7E04a140A. Admin surface: An owner exists—contrary to the previously recorded “no admin keys” finding.

The owner can setOwner, whitelist new IRMs and LLTVs, change existing-market fees, and set the fee recipient. Governance documentation states the fee is capped at 25% of borrower interest. Existing market parameters (oracle, IRM, LLTV, assets) remain immutable; new markets are permissionless but require enabled IRM/LLTV.

Users can call withdraw, subject to market liquidity; there is no admin withdrawal of user principal. Key compromise worst case: malicious future markets/IRM/LLTV whitelisting, maximum fee extraction, fee redirection, and ownership transfer. Direct draining or freezing of all core funds is not supported by the reviewed code. Oracle/IRM contracts and vaults/periphery are separate trust domains and require separate review. Timelock, owner implementation, renouncement, and current role state: Not verifiable as of September 5, 2026.

Dune decoded-event/on-chain checks were unavailable. Architecture: Users → Morpho Blue singleton (immutable core) → ERC-20 tokens ↑ owner: whitelist IRM/LLTV; fee controls Markets → external Oracle + IRM (market-selected, immutable after creation) Vaults/periphery → separate contracts; not part of core immutability claim

Admin can drain
No
Audited deployment
Yes
Upgradeable
No
Evidence (5)

audit

one source

Security review / competition for Morpho Blue

Auditor
Cantina
Report date
2023-09-28
Scope
Morpho Blue (commit hash referenced in review summary)
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (1)

audit

one source

Interest Rate Module Audit for Morpho Blue

Auditor
Cantina
Report date
2024-02-23
Scope
Interest Rate Module for Morpho Blue
Findings
Medium: 1 fixed; Informational: 2 total with 1 fixed and 1 acknowledged
Fix status
Fixed items reported as fixed; one informational acknowledged
Evidence (1)

audit

two sources

Cantina public competition; report publication date: 2024-01-05. Scope: morpho-org/morpho-blue; competition period 2023-11-13 to 2023-12-04. Covers deployed code: Not verifiable as of 2026-09-04; no bytecode-match analysis was performed for deployed Morpho Blue instances.

Auditor
Cantina Competition
Report date
2024-01-05
Scope
Morpho Blue core repository
Findings
0 critical; 1 high; 8 medium; 151 low; 36 gas optimizations; 163 informational (359 total).
Fix status
High: 0 fixed, 1 acknowledged. Medium: 0 fixed, 8 acknowledged. Low: 0 fixed, 151 acknowledged. Gas: 0 fixed, 36 acknowledged. Informational: 0 fixed, 163 acknowledged in the published competition summary.
Evidence (2)

audit

two sources
  • Scope: Morpho Blue core contracts via an open security competition hosted by Cantina (Jan 2024). • Date: Competition from Nov 16–Dec 7 (report dated 2025-06; Infrared labels this the Jan 2024 Cantina competition for Morpho Blue). • Link: Morpho audits page references “Morpho Blue – Cantina competition”; PDF report is mirrored by third-party hosting showing detailed findings distribution. • Severity findings (from competition report): 0 Critical, 1 High, 8 Medium, 151 Low, 36 gas optimizations, 163 informational. • Fix status: The competition report lists issues but does not give a definitive resolved/acknowledged matrix for each severity; fix status is Not verifiable as of 2026-08-27. • Bytecode / deployed-code match: Competition evaluated source code repositories at the time; explicit bytecode-matching to mainnet deployments is not documented in public excerpts – Not verifiable as of 2026-08-27. • Covers deployed code: Strong indication this targeted the main Morpho Blue implementation intended for deployment; chain-specific deployments beyond Ethereum (Arbitrum, Base, etc.) are not covered explicitly. • Risk inference: Given absence of critical issues and only one high-severity finding, residual known risk from this round centers on medium findings whose disposition is unknown.
Auditor
Cantina competition (multi-hunter)
Report date
2024-01-15
Scope
Morpho Blue core – security competition
Evidence (3)

audit

one source
  • Scope – SpeedJump IRM (interest rate module): Security review of the SpeedJump IRM implementation used by Morpho Blue markets; classified findings: 2 High (1 fixed, 1 acknowledged), 1 Medium (acknowledged), 1 Low (fixed), 5 informational (2 fixed, 3 acknowledged). • Date – SpeedJump IRM: 2023-09-28. • Scope – Fixed-rate IRM: Separate audit focused on Morpho Blue’s fixed-rate interest rate module; findings: 1 Medium (fixed) and 2 informational (1 fixed, 1 acknowledged). • Date – Fixed-rate IRM: 2024-02-23. • Links: Both reports hosted on Cantina portfolio pages. • Fix status: As above; all medium and low findings in these IRM modules are marked fixed, with some high and informational issues explicitly acknowledged rather than changed. • Bytecode / deployed-code match: Cantina reports identify repositories/files, not deployed bytecode; no explicit on-chain matching – Not verifiable as of 2026-08-27. • Covers deployed code: These audits directly cover Morpho Blue’s IRM periphery that influences yield and rate dynamics for all chains using SpeedJump or fixed-rate IRMs; however, which specific markets on Arbitrum, Base, OP, Polygon, etc., use these exact audited IRMs versus other configurations is Not verifiable as of 2026-08-27.
Auditor
Cantina (IRM audits – SpeedJump & fixed-rate modules)
Report date
2023-09-28
Scope
Morpho Blue Interest Rate Modules (SpeedJump IRM, fixed-rate IRM)
Evidence (3)

audit

two sources

Morpho Blue has been audited by ChainSecurity, a Swiss security firm repeatedly used by Morpho Labs for major upgrades of Morpho Aave and Morpho Blue. The available reports focus on the core lending and risk engine contracts of Morpho Blue on Ethereum; some audits pre‑date deployment of all currently listed chains (Arbitrum, Base, OP, Polygon, etc.), and cross‑chain deployments are not individually covered in public reports.

Auditor
ChainSecurity
Report date
2023-07-31
Scope
Core Morpho Blue lending protocol contracts on Ethereum (risk engine, markets, interest rate logic); exact contract list and bytecode match vs. currently deployed addresses Not verifiable as of 2026-09-03
Findings
Not verifiable as of 2026-09-03 (detailed issue list, severities, and per‑finding descriptions are not publicly summarized in accessible sources)
Fix status
Not verifiable as of 2026-09-03 (per‑finding remediation status, including whether all critical/high issues were fixed, cannot be confirmed from public sources)
Evidence (2)

audit

one source

Code Assessment of the Morpho Vault V2 Smart Contracts

Auditor
ChainSecurity
Report date
2025
Scope
Morpho Vault V2 smart contracts
Findings
Critical: 1 resolved during engagement; High: 0; Medium: 4 resolved during engagement
Fix status
Code corrected during the course of the engagement
Evidence (1)

audit

one source

New report identified: Spearbit review of Morpho Blue Periphery Pre-Liquidation. The report file is dated 2024-10-29 and the audit registry identifies the same publication date.

Auditor
Spearbit
Report date
2024-10-29
Scope
Morpho Blue Periphery — PreLiquidation; repository morpho-org/pre-liquidation
Findings
0 critical; 0 high; 0 medium; 0 low; 3 informational, plus 1 gas optimization reported by secondary audit-directory indexing. The primary accessible summary confirms 3 informational findings.
Fix status
Gas optimization: fixed. Informational findings: acknowledged. No critical, high, medium, or low findings reported.
Report url
https://github.com/morpho-org/pre-liquidation/blob/main/audits/2024-10-29-pre-liquidation-spearbit.pdf
Report id
doc:0b12372012d80ec6
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

New report identified: Cantina managed review of Morpho Blue Public Allocator. The Morpho audit registry lists publication date 2024-03-11; the engagement reviewed commit 1cdcee8d during 2024-02-19–2024-02-23.

Auditor
Cantina
Report date
2024-03-11
Scope
Morpho Blue Periphery — Public Allocator; repository morpho-org/public-allocator, commit 1cdcee8d
Findings
0 critical; 0 high; 1 medium; 4 low; 7 informational; 12 total findings.
Fix status
Medium: 0 fixed, 1 acknowledged. Low: 2 fixed, 2 acknowledged. Informational: 5 fixed, 2 acknowledged. The report documents follow-up remediation, including PR 28 for allocator market-validation issues.
Report url
https://github.com/morpho-org/public-allocator/blob/main/audits/2024-03-11-morpho-public-allocator-cantina-managed.pdf
Report id
doc:d2568c09e2becc44
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

New report identified: ABDK Consulting review of Morpho Blue Periphery Pre-Liquidation, dated 2024-11-01 in the audit registry and report filename.

Auditor
ABDK Consulting
Report date
2024-11-01
Scope
Morpho Blue Periphery — PreLiquidation
Findings
Not verifiable as of 2026-09-05
Fix status
Not verifiable as of 2026-09-05
Report url
https://github.com/morpho-org/pre-liquidation/blob/main/audits/2024-11-01-pre-liquidation-ABDK-consulting.pdf
Report id
doc:f610f6e7aa3b0fc8
Covers deployed code
No
Evidence (2)

audit

one source

metamorpho cantina managed review audit report; file audits/2023-11-14-metamorpho-cantina-managed-review.pdf in morpho-org/metamorpho (protocol audit catalog).

Auditor
metamorpho cantina managed review
Report date
2023-11-14
Scope
protocol
File
2023-11-14-metamorpho-cantina-managed-review.pdf
Catalog only
Yes
Evidence (1)

audit

one source

morpho blue and speed jump irm open zeppelin audit report; file audits/2023-10-13-morpho-blue-and-speed-jump-irm-open-zeppelin.pdf in morpho-org/morpho-blue (protocol audit catalog).

Auditor
morpho blue and speed jump irm open zeppelin
Report date
2023-10-13
Scope
protocol
File
2023-10-13-morpho-blue-and-speed-jump-irm-open-zeppelin.pdf
Catalog only
Yes
Evidence (1)

audit

one source

morpho blue cantina competition audit report; file audits/2024-01-05-morpho-blue-cantina-competition.pdf in morpho-org/morpho-blue (protocol audit catalog).

Auditor
morpho blue cantina competition
Report date
2024-01-05
Scope
protocol
File
2024-01-05-morpho-blue-cantina-competition.pdf
Catalog only
Yes
Evidence (1)

audit

one source

morpho blue cantina managed review audit report; file audits/2023-11-13-morpho-blue-cantina-managed-review.pdf in morpho-org/morpho-blue (protocol audit catalog).

Auditor
morpho blue cantina managed review
Report date
2023-11-13
Scope
protocol
File
2023-11-13-morpho-blue-cantina-managed-review.pdf
Catalog only
Yes
Evidence (1)

audit

one source

morpho blue periphery open zeppelin audit report; file audits/2023-11-16-morpho-blue-periphery-open-zeppelin.pdf in morpho-org/metamorpho (protocol audit catalog).

Auditor
morpho blue periphery open zeppelin
Report date
2023-11-16
Scope
protocol
File
2023-11-16-morpho-blue-periphery-open-zeppelin.pdf
Catalog only
Yes
Evidence (1)

audit

two sources
  • Scope: Morpho Blue core smart contracts (lending market, interest rate logic, liquidations). The Infrared Trading security page explicitly lists an OpenZeppelin review of Morpho Blue core. • Date: October 2023. • Link: Listed on Morpho’s official audits page under Morpho Blue; exact URL not reproducible here. • Severity findings: Not detailed publicly in the Infrared summary; it states no critical vulnerabilities reported at time of audit. • Fix status: Infrared notes the reviews as part of production-hardening; individual issue status not broken out. • Bytecode / deployed-code match: Not verifiable as of 2026-08-27 (no public statement that the audited commit hash was matched against mainnet bytecode). • Chain coverage: This is a core-protocol audit, primarily relevant to Ethereum mainnet deployment; extension of coverage to other listed chains (Arbitrum, Base, OP, Polygon, etc.) cannot be confirmed from the report alone. • Finding coverage for current deployments: Whether later deployments (e.g., additional chains, new markets) still run the audited version is Not verifiable as of 2026-08-27.
Auditor
OpenZeppelin
Report date
2023-10-01
Scope
Morpho Blue core smart contracts
Evidence (3)

audit

unverified

Audit of Morpho Blue and the SpeedJump IRM (Interest Rate Model)

Auditor
OpenZeppelin
Report date
2023-10-13
Scope
Morpho Blue and SpeedJump IRM
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (2)

audit

unverified

Several secondary sources and community posts assert additional audits for Morpho Blue (e.g., incremental reviews for new markets or integrations), but they either lack direct links to auditor‑hosted reports or cannot be matched unambiguously to the currently deployed Morpho Blue contracts on the specified chains.

Auditor
Other / unspecified firms
Report date
2024-01-01
Scope
Alleged supplementary audits for Morpho Blue or related integrations; specific scope and bytecode coverage Not verifiable as of 2026-09-03
Findings
Not verifiable as of 2026-09-03 (claims of further audits cannot be tied to concrete reports or issue tables)
Fix status
Not verifiable as of 2026-09-03
Evidence (1)

audit

one source

periphery cantina competition audit report; file audits/2024-01-05-periphery-cantina-competition.pdf in morpho-org/metamorpho (protocol audit catalog).

Auditor
periphery cantina competition
Report date
2024-01-05
Scope
protocol
File
2024-01-05-periphery-cantina-competition.pdf
Catalog only
Yes
Evidence (1)

audit

two sources

Morpho Labs engaged Runtime Verification to audit components of the Morpho lending stack, including formal methods review of core protocol logic. Publicly accessible information confirms involvement but not the exact report for Morpho Blue specifically, and no full issue list is available.

Auditor
Runtime Verification
Report date
2023-10-01
Scope
Formal‑methods based review of Morpho protocol components; whether this precisely covers current Morpho Blue deployments on all listed chains is Not verifiable as of 2026-09-03
Findings
Not verifiable as of 2026-09-03 (no public enumeration of critical/high/medium findings specific to Morpho Blue)
Fix status
Not verifiable as of 2026-09-03 (no public confirmation per finding or statement that all issues were resolved prior to deployment)
Evidence (2)

audit

unverified

Morpho Blue core smart contract security review

Auditor
Spearbit
Report date
2023-06
Scope
Morpho Blue smart contract
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (1)

audit

one source

Spearbit/Cantina managed review; publication date: 2023-10-16 per Morpho’s audit registry. Scope: Morpho Blue core at commit 11e69…810c53; review period was 2023-09-28 to 2023-10-16. Covers deployed code: Not verifiable as of 2026-09-04; bytecode matching across the listed deployment chains was not performed.

Auditor
Spearbit
Report date
2023-10-16
Scope
Morpho Blue core
Findings
0 critical; 4 high; 1 medium; 4 low; 1 gas optimization; 17 informational issues (27 total).
Fix status
Report-level remediation status for each finding is Not verifiable as of 2026-09-04 from the accessible publication metadata; subsequent repository releases indicate fixes were applied, but not every finding can be mapped reliably.
Evidence (2)

audit

two sources
  • Scope: Morpho Blue core smart contracts; described as a Cantina/Spearbit-managed review of the core protocol. • Date: November 2023 (per Infrared’s chronology: core reviews in Oct–Nov 2023). • Link: Listed on Morpho audits page as “Morpho Blue – Cantina-managed review”; report URL not reproducible here. • Severity findings: External summaries (Defi-intel, Infrared) state no critical issues remained at the time of deployment, but do not enumerate high/medium/low counts. • Fix status: Described as part of the pre-launch hardening; given the live deployment and lack of reported core exploits, material findings are implied fixed or mitigated, but exact per-issue status is Not verifiable as of 2026-08-27. • Bytecode / deployed-code match: Not verifiable as of 2026-08-27. • Covers deployed code: All public descriptions state this was a review of the production-intent core; however, whether every chain’s deployment (Arbitrum, Base, OP, Polygon, etc.) uses the exact audited bytecode is Not verifiable as of 2026-08-27.
Auditor
Spearbit (Cantina-managed review)
Report date
2023-11-01
Scope
Morpho Blue core smart contracts (Cantina/Spearbit-managed review)
Evidence (3)

audit

one source
  • Scope: Vault-level and curator-level configurations for vaults interacting with Morpho Blue (and other protocols). This is not a core smart-contract audit; it focuses on configuration and governance risk at the vault/curator layer. • Date: 2026-05-08. • Link: Yelty “Vault-Level & Curator-Level Audit Report” for multiple protocols, including Morpho Blue. • Severity findings: Yelty describes this as an automated DeFi risk audit; the public summary does not break down findings by critical/high/medium categories for Morpho Blue specifically – Not verifiable as of 2026-08-27. • Fix status: Not stated; this is more a continuous-scan style assessment than a traditional targeted audit – Not verifiable as of 2026-08-27. • Bytecode / deployed-code match: Not applicable; focuses on vault/curator configuration rather than core bytecode. • Covers deployed code: Relevant for institutional use of Morpho Blue via MetaMorpho or other vault wrappers across all chains where such vaults exist, but exact chain-specific coverage is Not verifiable as of 2026-08-27.
Auditor
Yelty (automated vault/curator-layer scan)
Report date
2026-05-08
Scope
Vault-level & curator-level risk scan including Morpho Blue vaults
Evidence (1)

Team & Reputation

founders

two sources

Morpho Blue is built by Morpho Labs, founded in 2021 by Paul Frambot and Merlin Egalite; public sources also name Julien Thomas and Mathis Gontier Delaunay as co-founders in the broader Morpho Labs team. The most consistently documented public-facing leaders are Paul Frambot (co-founder/CEO) and Merlin Egalite, while the company’s hiring pages and speaker profiles indicate a real Paris presence and hybrid/remote staff model with an office in Paris. A later Blockworks transparency report states the project is organized through a French nonprofit, Morpho Association, which owns a Delaware subsidiary, Morpho Labs Inc., and says the original French Morpho Labs SAS is no longer active; that same report also says the DAO has no separate legal existence. Reality check: the team is *not* anonymous, and the project appears to have a real operating business rather than only a web front, given repeated evidence of Paris offices, hiring pages, and a disclosed legal structure.

On credibility, the founders’ profile is strengthened by documented university-based origins and repeated public identification, but the available material does not show a prior major hack by the founders or a large adverse incident attributable to them; *not verifiable as of 2026-09-03* from the sources gathered. The main caution is that some ownership/legal-structure details come from a later transparency report and company job pages, so they should be treated as disclosed claims unless independently cross-checked further.

Evidence (6)

general reputation

one source

Morpho Blue and its core team have a generally strong reputation in DeFi, with no credible fraud, rug, or insolvency allegations identified as of 2026‑09‑03. All on‑chain verification is Not verifiable as of 2026‑09‑03. Founders & team reputation

  • Morpho Labs was founded by CEO Paul Frambot and a team of Paris‑based developers and researchers; the project has been active since at least 2021 with Morpho Aave/Compound, then launched Morpho Blue in 2024 as a minimal, modular lending primitive.
  • The team is publicly visible, regularly speaking at major crypto conferences and publishing technical papers and blog posts, which supports reputational legitimacy. Investors & backers
  • Morpho Labs raised a $18 million seed round in 2022 led by a16z Crypto, with participation from Variant, Coinbase Ventures, and other recognized crypto VCs.
  • Institutional backing from a16z and Coinbase Ventures is widely viewed as a positive reputational signal, though not a guarantee of safety. Audits & security posture
  • Morpho Blue contracts have undergone audits by firms including Ledger Prime security and other auditors referenced in Morpho documentation and GitHub, but specific audit reports and coverage per chain are fragmented; comprehensive verification for each chain in the slug is Not verifiable as of 2026‑09‑03.
  • Morpho maintains a bug bounty program via Immunefi, offering rewards for critical vulnerabilities, indicating a proactive security stance. Sentiment & criticisms
  • Industry/media coverage and crypto research outlets generally describe Morpho Blue as an innovative or “next‑gen” lending primitive focused on efficiency and modularity, with positive sentiment around capital efficiency and isolating risk per market.
  • Criticisms are mostly technical/structural, including: complexity of risk configuration for isolated markets; dependence on external rate oracles; and concerns that highly customized markets could fragment liquidity and be harder for non‑expert users to understand.
  • No mainstream reports of user funds loss, protocol‑level insolvency, or major exploits specifically tied to Morpho Blue were found as of 2026‑09‑03. Legal / regulatory / sanctions
  • No listings or actions against Morpho Labs or Morpho Blue were found in U.S. OFAC sanctions lists or major regulator enforcement databases searched; Not verifiable as of 2026‑09‑03 for all jurisdictions.
  • Morpho appears to operate as a typical DeFi protocol without KYC/AML on‑chain, which could pose future regulatory risk, especially on U.S.‑facing chains, but this is a sector‑wide concern rather than a protocol‑specific allegation. Unresolved concerns
  • Multi‑chain deployment (Arbitrum, Base, Ethereum, OP, Polygon, and future chains like Monad/Unichain, etc.) increases the attack surface; systematic, per‑chain audit coverage and incident history are Not verifiable as of 2026‑09‑03.
  • Risk in Morpho Blue is highly market‑specific: the reputation of the core protocol is stronger than that of individual markets, whose collateral, oracle, and operator risks can vary significantly and require separate analysis.
Evidence (7)

Economy

TVL: $9.7B

model

one source

Economic model (as of September 5, 2026). Morpho Blue is a permissionless, peer-to-pool lending primitive: each isolated market pairs one collateral asset with one loan asset and fixes its oracle, LLTV, and interest-rate model at creation. Lenders supply the loan asset and earn borrower-paid variable interest; borrowers post collateral and borrow the loan asset. Collateral itself does not generate protocol yield. Assets / exposure. Assets in and out are market-specific ERC-20 collateral and loan tokens; examples include stablecoins, ETH derivatives, BTC derivatives, and restaked assets, but no universal asset list is implied.

Risk is primarily directional through collateral prices, oracle quality, liquidation discounts, and borrower defaults. Looping/leverage and restaking exposure are possible through external vaults, aggregators, or user transactions, but are not inherent to the Blue core. The protocol itself is not market-neutral. Yield sustainability. Base lender yield is organic borrower interest and varies with utilization and the market’s IRM.

Incentives/rewards may subsidize displayed APY. The organic/subsidized split, APY history, volatility, and sustainability are Not verifiable as of September 5, 2026. Liquidity / withdrawals. Lenders may withdraw principal plus accrued interest only when sufficient market liquidity exists. Borrowers must repay debt before withdrawing collateral if required by health-factor constraints.

Vault products can reallocate liquidity through the Public Allocator; illiquid vault exits may transfer Blue supply positions in kind rather than cash. Fees and revenue. Market state includes a fee field, but protocol revenue distribution and effective fee capture are Not verifiable as of September 5, 2026. DeFiLlama reports approximately $18.26m 30-day fees and $0 reported 30-day revenue, indicating a material fees-versus-revenue distinction. TVL cross-check (DeFiLlama, current page): $9.808bn total: Ethereum $4.377bn (44.6%), Base $4.033bn (41.1%), Robinhood Chain $517.3m (5.3%), Hyperliquid L1 $330.1m (3.4%), Monad $179.3m (1.8%), Arbitrum $23.0m (0.23%), Katana $49.7m (0.51%), Stable $30.2m (0.31%), Tempo $44.9m (0.46%), Polygon $3.9m, OP Mainnet $2.7m, Unichain $1.3m. DeFiLlama also lists additional chains not in the supplied scope.

Dune TVL, product-level TVL, trends, and contradiction testing: Not verifiable as of September 5, 2026. Controls: no protocol-level lock-up; liquidity, LLTV, oracle, utilization, and market-specific caps are the practical gates. Liquidation is permissionless when LLTV is breached.

Evidence (5)

reserves

one source

Scope. Morpho Blue is an immutable, non-custodial lending primitive; the relevant reserves are governance- and Association-controlled assets, not protocol-held user deposits. Governance can control the MORPHO treasury, token administration, fee switch (maximum 25% of borrower interest), and fee recipient. The fee switch was reported off as of June 17, 2026, with no fee-distribution, buyback, burn, or staking mechanism. Identified custody and control

  • DAO governance treasury: Ethereum and Base Safe 0xcBa28b38103307Ec8dA98377ffF9816C164f9AFa; 5-of-9 multisig. It controls DAO treasury actions and certain token-contract administration.
  • Morpho Association master Safe: Ethereum and Base 0x6abfd6139c7c3cc270ee2ce132e309f59caaf6a2; 3-of-8 multisig. It is the Association’s primary on-chain funds custodian. Additional operational Safes are listed in the transparency filing, including 0x4d2008931e86E97D676767c49A1089f5Dd90fd30, 0xD81E0983e8e133d34670728406d08637374e545D, and 0xd2C7eF9f4d30C476C135449949f124A4D3f14526. Composition / policy. Disclosed assets include MORPHO, cash, marketable securities, crypto-assets, prepaid expenses, receivables, and treasury-management positions such as term deposits, lending rewards, and financial participations. The 2026 whitepaper states that approximately 5.4% of total MORPHO supply remained in the Association’s wallet pending final disbursement at publication; it does not provide a USD reserve total. DAO and Association allocations are released through governance decisions and operational needs. No protocol-owned liquidity, token repurchases, or DAO/Association credit lines were reported. On-chain balances / liabilities. Not verifiable as of September 5, 2026. Dune MCP was unavailable for this run; no balance, valuation, chain-by-chain exposure, or latest-block snapshot is asserted. Off-chain liabilities are described qualitatively as mainly deferred token revenue, other payables, and FX/revaluation differences, but no current amount is disclosed. Attestations. The whitepaper says 2022–2024 Association accounts were prepared under French GAAP and approved unanimously; this is not an independent reserve attestation. Blockworks expressly states it does not verify or warrant Morpho’s disclosures.
Evidence (3)

tokenomics

two sources

Morpho Blue currently has no native token specific to the Blue product. The protocol uses the existing MORPHO token, which is a shared governance and incentive asset for the broader Morpho ecosystem (Morpho Optimizer, Morpho Blue, and future products). All token-related data below refers to MORPHO. > On-chain verification: Not verifiable as of 2026-09-03. **1.

Token identity & contracts**

  • Name / ticker: Morpho (MORPHO).
  • Primary chain: Ethereum; ERC‑20 token used for governance across Morpho products.
  • Exact contract address, and any deployments on Arbitrum, Base, OP Mainnet, Polygon, etc.: Not verifiable as of 2026-09-03. 2. Supply, market cap, FDV
  • Total and circulating supply, market cap, and fully diluted valuation: Not verifiable as of 2026-09-03 (requires live market/registry data and on-chain queries).
  • MORPHO is live, traded and listed on major DeFi venues according to analytics platforms (e.g., DeFiLlama, CoinGecko) but exact figures are outside the current data scope. 3. Utility & governance role
  • MORPHO is a governance token for the Morpho DAO, used to vote on protocol parameters, new markets, and upgrades across Morpho Optimizer and Morpho Blue.
  • Token is not required to use Morpho Blue; users interact with Blue pools using standard assets (ETH, stablecoins, etc.).
  • No credible sources describing revenue share, buybacks, burns, or staking rewards tied directly to MORPHO for Morpho Blue specifically: Not verifiable as of 2026-09-03. 4. Emissions, unlocks, allocations
  • Public, detailed tokenomics (emission schedule, team/investor/treasury/community allocations) are referenced in secondary analytics platforms but underlying allocations and vesting schedules cannot be validated on-chain here.
  • Whether specific unlocks occurred on-chain at announced times: Not verifiable as of 2026-09-03. 5. Concentration & contract controls
  • Top-holder concentration, insider wallets, and any mint/blacklist/fee‑switch admin rights for MORPHO token contract: Not verifiable as of 2026-09-03.
  • Governance and control are described as DAO-based with proposals and votes using MORPHO, but these are unverified marketing claims without on-chain confirmation in this run. 6. Listings & liquidity
  • MORPHO is reported listed on multiple DEXs and CEXs; main pairs are against ETH and stablecoins, but exact liquidity depth per chain (Arbitrum, Base, OP, etc.) is Not verifiable as of 2026-09-03.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A BTC move below $10,000 would be a severe stress event for Morpho Blue, but the impact is *market-specific*, not protocol-wide, because Morpho Blue markets are isolated and immutable once deployed. The main risk would be concentrated liquidation pressure and potential bad debt in BTC-collateral markets where collateral factors, oracle quality, and liquidation liquidity are weak; losses would not automatically contaminate unrelated markets. The highest-exposure venues appear to be BTC-markets on Base and Ethereum, which third-party analytics identify as the largest chains for Morpho Blue TVL and show substantial cbBTC/WBTC-style exposure on those chains.

A material BTC crash would therefore likely hit the largest BTC-backed vaults and curators first, especially if their markets are configured with aggressive risk parameters or thin on-chain liquidity. Key risk channels under this scenario:

  • Liquidation cascades: fast price decline can push borrowers below collateral requirements, creating auction pressure and slippage.
  • Oracle failure / lag: if a market’s oracle is slow or poorly chosen, liquidations may occur late or at distorted prices.
  • Vault curator loss transmission: MetaMorpho vault depositors can share losses if a curator allocates into a weak BTC market.
  • Bad debt concentration: isolated losses remain contained to the affected market, but they can still impair lenders in that market. What is not verifiable as of 2026-09-04 from the available web evidence alone:
  • exact BTC-collateral market share by chain,
  • current borrower leverage and liquidation buffers,
  • live bad-debt capacity under a $10k BTC scenario,
  • on-chain exposure totals by market. So the institutional view is: protocol-level contagion risk is limited, but chain-leading BTC markets could experience sharp localized losses if a $10k BTC price shock arrives faster than oracle updates and liquidation liquidity.
Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of the largest collateral in Morpho Blue is not verifiable as of 2026-09-03 from the available web results alone. The retrieved sources explain Morpho Blue’s liquidation mechanics and note that 20% depegs can generate rapidly growing losses in stress models, but they do not identify the current largest collateral across the requested chains or provide a protocol-wide 20% depeg loss estimate for Morpho Blue. What can be said from the sources is limited to mechanics: Morpho Blue liquidates unhealthy positions when collateral value falls below the market’s LLTV, and any shortfall after liquidation is socialized to suppliers as bad debt.

One external risk write-up also shows that at a 20% price drop, a sample Morpho borrower set would have about $5.5M of debt become liquidatable, but that is a single-analysis scenario, not a protocol-wide result for the current multi-chain Morpho Blue deployment. Because the prompt asks for the largest collateral across Arbitrum, Base, Ethereum, Hyperliquid L1, Katana, Monad, OP Mainnet, Polygon, Robinhood Chain, Stable, Tempo, and Unichain, the missing on-chain inventory means the stress loss cannot be computed reliably here.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Morpho Blue, if the top counterparty becomes insolvent, the loss is not mutualized across all markets; it is contained within the affected market, and any unrecovered debt is borne by that market’s lenders/suppliers through bad-debt socialization. Expected loss path: the borrower is liquidated first; liquidators seize collateral up to the position’s maximum liquidation incentive. If collateral is still insufficient, the residual becomes bad debt. Morpho’s docs say this residual is immediately recognized as a loss and distributed proportionally across lenders in that market, reducing each lender’s redeemable value rather than creating a separate insurance fund payout. Who absorbs it: the depositors/lenders in the same market absorb the loss pro rata.

Morpho’s documentation is explicit that bad debt in one market does not affect lenders in other markets. The effect is described as a reduction in the market’s total supply assets / lender credit, so the loss lands on suppliers, not on the liquidator or the borrower’s remaining collateral once exhausted. Compensation: there is no protocol-level compensation for the shortfall in the cited docs. Liquidators are compensated by receiving collateral at the liquidation incentive, but they do not cover the remaining bad debt.

Lenders are not compensated; instead, their claim on the market is reduced proportionally. Impact path through smart contracts: liquidation consumes collateral first; if debt remains after full seizure, the protocol records bad debt and updates market accounting so that total supply value is reduced alongside the bad debt recognition. That accounting change is what socializes the loss across lenders in the affected market. For the listed chains, this mechanism is the same wherever Morpho Blue markets are deployed; I cannot verify chain-by-chain exposure shares here, so Not verifiable as of 2026-09-03.

Evidence (6)

stress scenario - committed fraud by the DAO or owners

two sources

Morpho Blue is a lending protocol governed by the Morpho DAO; a stress scenario of DAO or owner-committed fraud focuses on governance capture, treasury misuse, or malicious upgrades. Not verifiable as of 2026-09-03 whether any such fraud has occurred on-chain. ## 1. Governance / Control Structure

  • Morpho Blue is designed as a minimal, risk-isolated lending primitive where markets are defined by a "Risk Curator" address that sets parameters and oracles.
  • Governance for Morpho products migrated to the Morpho DAO with on-chain voting via MORPHO token and delegated governance.
  • Smart contracts for Morpho Blue are upgradeable only through defined governance processes; core contracts are reported as non-custodial and without protocol-owned liquidity. *Risk implication (fraud scenario)*
  • A malicious or captured DAO vote could:
  • Change key parameters (e.g., collateral factors) to favor insiders.
  • Authorize a contract upgrade introducing a backdoor or draining mechanism.
  • Redirect protocol fees or treasury assets to attacker-controlled addresses. ## 2. Historical Incidents / Allegations
  • As of available public information, there are no reported cases of Morpho DAO or core team being accused by regulators or courts of fraud, misappropriation, or market manipulation.
  • No major exploit or governance attack specifically attributed to insider fraud on Morpho Blue is documented in mainstream crypto media or incident trackers. Because Dune MCP and direct on-chain investigation are unavailable in this run, any on-chain confirmation of treasury movements, governance votes, or ownership concentration is: Not verifiable as of 2026-09-03. ## 3. Stress Scenario Framing for Risk Analysis Under a hypothetical committed fraud by DAO/owners scenario, key exposures would be:
  • User deposits in Morpho Blue markets: could be impacted by malicious parameter changes or upgrades enabling bad debt creation and value extraction.
  • Oracle and Risk Curator abuse: insiders could set manipulated oracles or assign curator roles to entities that push self-serving, unsafe configurations.
  • Governance token concentration: if MORPHO voting power is highly concentrated, coordinated insider action could pass harmful proposals quickly (ownership distribution not verifiable as of 2026-09-03). Risk-mitigating factors (conceptual, not fully verifiable here): use of audits and formal verification, public governance, and non-custodial design reduce—but do not eliminate—the impact of DAO/owner fraud; ultimate protection still depends on governance integrity and tokenholder dispersion.
Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

In a scenario where the primary yield source on Morpho Blue turns negative over 30 days, you should assume rapid repricing of rates, liquidity flight from affected markets, and potential insolvency pressure on marginal borrowers. ### 1. How Morpho Blue generates yield (high‑level) Morpho Blue is a minimal, isolated‑pool lending protocol: yield to lenders comes from borrow interest, and the effective net yield is shaped by:

  • Borrow APY vs. supply APY (spread to reserve / protocol)
  • Oracle‑driven interest‑rate curves (LLTV, kink parameters per market)
  • External staking/LP yields *only if* a vault or strategy built on top of Morpho Blue is adding them (e.g., Morpho vaults, Yearn/Enzyme, Pendle, etc.) If you define “primary yield source” as borrow interest in a given Morpho Blue market, a 30‑day negative realized APY for suppliers typically reflects:
  • Very low utilization (fee drag > earned interest)
  • Adverse rate shifts from governance/market creators
  • Incentive program ending, exposing net negative economics in wrappers (vault tokens trading at discount) ### 2. Direct protocol‑level impacts If borrow demand collapses or rates invert for 30d in a major market (e.g., ETH or stables on Ethereum vs L2s):
  • Supplier exodus: Liquidity migrates to higher‑yield money markets (Aave, Compound, Spark), shrinking depth and worsening slippage for liquidations.
  • Utilization volatility: Remaining positions become more concentrated; a few large borrowers can drive utilization and rate spikes.
  • Liquidation quality risk: With thinner books, oracle shocks (e.g., unstable price feeds) can lead to under‑collateralized pockets before liquidators react. All of this is *Not verifiable as of 2026‑09‑03* from on‑chain data via Dune, because Dune MCP is unavailable and we cannot run protocol‑level utilization/yield queries. ### 3. System‑wide / cross‑chain considerations For Morpho Blue deployed across Ethereum, Arbitrum, Base, OP Mainnet, Polygon and other listed chains, risk concentration will differ per chain:
  • Ethereum: deepest liquidity; negative 30d yield in a core ETH/USDC market is systemically more relevant than on a fringe L2.
  • L2s (Arbitrum, Base, OP, Polygon): generally higher share of farming / mercenary liquidity; yield turning negative can trigger faster outflows but with lower absolute size.
  • Non‑EVM / emerging chains listed (Hyperliquid L1, Katana, Monad, Robinhood Chain, Stable, Tempo, Unichain): deployment status and TVL are Not verifiable as of 2026‑09‑03. ### 4. Risk‑management stance for an institutional allocator If the primary yield source on a monitored Morpho Blue market is negative for 30d:
  • De‑prioritize new supply into that market unless there is a strategic reason (e.g., directional borrow access).
  • Tighten position limits and counterparty/venue limits for that chain‑market pair.
  • Increase monitoring of:
  • Utilization and rate changes
  • Oracle sources and deviation thresholds
  • Concentration of top suppliers/borrowers and liquidation buffer. Without on‑chain analytics, all numeric TVL/rate impacts are Not verifiable as of 2026‑09‑03 and must be treated as qualitative scenario analysis only.
Evidence (3)

Governance & Legal

governance

unverified

Assessment as of September 13, 2026: Morpho Blue has hybrid, limited-scope governance rather than fully autonomous DAO control. Core Morpho Blue markets/contracts are immutable; governance cannot upgrade the core or directly drain user positions. MORPHO governance controls the treasury, ownership of the upgradeable MORPHO token contract, the fee switch (capped at 25% of borrower interest) and recipient, approved LLTVs/IRMs, and relevant ENS records.

Proposals are discussed on the Morpho forum, voted through Snapshot (proposal submission threshold: 500,000 MORPHO, adjustable), then implemented by the 5/9 governance Safe. This makes the DAO operationally real for defined parameters, but execution remains delegated to a multisig and core-contract upgrades are impossible; therefore it is not fully decentralized governance. The governance Safe is documented on Ethereum and Base at 0xcBa28b38103307Ec8dA98377ffF9816C164f9AFa.

Nine owners and their current independence were not independently verified; the latest located signer-change proposal replaced two signers with Morpho Association advisors, indicating material ecosystem/Association overlap rather than clearly independent control. Rewards are held separately in documented 3/5 multisigs on Ethereum and Base. No evidence was found that these multisigs can move user deposits from immutable Morpho Blue markets without protocol-level conditions.

Frontend, documentation, development support, and certain open-source IP are controlled or hosted by the Morpho Association. The current Terms identify it as a French association at 24 rue de Clichy, 75009 Paris; RNA number W751263773, SIREN 911 156 933, EU VAT FR 44911156933. Directors/legal representatives: Not verifiable as of September 13, 2026.

The Terms state that the Association does not custody or control user crypto-assets and does not operate the underlying protocol contracts. Dune/on-chain verification of voting concentration, top holders, current Safe owners, signer independence, execution history, and cross-chain exposure was unavailable in this run: Not verifiable as of September 13, 2026. The exact current governance timelock/delay and any emergency bypass were also not established from the available evidence; vault timelocks are separate from Morpho Blue governance.

Multisig threshold
5
Multisig owners
9
Admin can drain
No
Dao governance
No
Evidence (4)

legal & regulatory

unverified

Morpho Blue is associated with the Morpho Association, a French association governed by the law of 1 July 1901, with registered office at 24 rue de Clichy, 75009 Paris, France. The protocol’s terms state that services are governed by French law, disputes are governed by French law, and the Association may restrict access using onchain analytics and sanctions-screening tools. The terms also prohibit use from or for the benefit of restricted territories and prohibit money laundering, terrorist financing, tax evasion, sanctions evasion, and other illegal activity.

Morpho’s disclaimer says users are responsible for compliance with applicable laws and that nothing should be interpreted as an offer of regulated financial services or crypto-asset services/marketing under MiCA. I found no verified evidence in the gathered sources of regulator action, court proceedings, or sanctions specifically against Morpho Blue or the Morpho Association. Not verifiable as of 2026-09-03 for on-chain exposure, multi-chain regulatory reach, and any hidden enforcement beyond the cited materials.

Active enforcement
No
Sanctioned
No
Entity
Morpho Association
Jurisdiction
France
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'Morpho Association', 'Morpho Blue'. OFAC SDN screening of 'Morpho Association', 'Morpho Blue': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Morpho Association
  • Morpho Blue
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Morpho Blue does not issue its own stablecoin. It is a permissionless lending primitive where markets can use third-party loan assets such as USDC or PYUSD, so no Morpho-native stablecoin depeg can be verified from the available sources. A third-party incident involving Resolv USR depegging in March 2026 was reported as affecting some Morpho vault users, but the available sources do not support a protocol-wide depeg count, exact last depeg date, or max depeg percentage for Morpho Blue itself.

Not verifiable as of 2026-09-05: depeg_count, last_depeg_date, max_depeg_pct, stablecoin_ids.

Own stablecoin
No
Evidence (4)

Risks & Strengths

risks

one source

Morpho Blue’s core design contains market-level contagion, but shifts substantial risk selection to oracle designers, market creators, curators, and users. The highest residual risks are oracle failure, bad debt/liquidation shortfalls, asset and issuer risk, permissionless configuration risk, and latent smart-contract defects; chain-by-chain exposure and current bad-debt levels are Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle failure or manipulationA faulty, stale, or manipulable oracle can trigger unfair liquidations or leave bad debt. Oracle choice is fixed per market, so remediation may require migration rather than parameter change.HighMediumMarket-specific oracle selection, immutable market parameters, isolated markets, liquidation thresholds, and user due diligence.High loss potential remains for markets using weak, centralized, illiquid, or slow oracles.
Bad debt and liquidation shortfallFast collateral-price moves, thin collateral liquidity, or inadequate liquidation incentives can leave lenders under-repaid; losses are generally borne within the affected market.HighMediumOvercollateralization, immutable LLTVs, permissionless liquidations, liquidation incentives, and market isolation.High in volatile or illiquid markets; no protocol-wide insurance or socialized backstop is evidenced.
Collateral and borrower asset riskIssuer freezes, blacklisting, depegs, token-admin actions, wrapper failures, or concentrated ownership can impair collateral value or loan-asset redemption.HighMediumPermissionless asset selection, isolated markets, and documented counterparty due diligence expectations.High for centralized stablecoins, RWA tokens, thinly traded assets, and nonstandard ERC-20s.
Permissionless market and curator riskAnyone can create markets or build vault strategies, allowing unsuitable parameters, misleading interfaces, concentration, or poor monitoring to attract deposits.HighHighImmutable market rules, interface risk warnings/listing controls, externalized risk management, and vault timelocks where applicable.High because delisting is only a UI action and cannot stop direct on-chain interaction.
Core smart-contract vulnerabilityA coding, accounting, callback, or integration flaw could cause direct loss or freeze funds across affected deployments.HighLowOpen-source code, immutability, multiple audits, formal-verification work, testing, and an independent bounty program.Medium: immutable deployment limits patchability and does not eliminate undiscovered defects.
Evidence (5)

strengths

two sources

Morpho Blue’s top strengths are: capital efficiency from isolated markets, which lets each market set its own risk parameters without being constrained by a riskier asset basket; better rates for lenders and borrowers because the design reduces spread and improves capital utilization; low gas costs because the core is a very small singleton contract that minimizes execution overhead; permissionless market creation and flexible asset listing, which lets anyone deploy new markets quickly; and minimal governance / strong trust assumptions, since the core is immutable and governance-minimized rather than actively managing user funds or market operation.

Evidence (2)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 26 two independent sources, 23 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-27.