Morpho Vault V2 exposes the standard ERC‑4626 interface for tokenized vaults. Understanding these mechanics is essential for building robust Earn integrations.
The ERC‑4626 standard defines four core functions for deposits and withdrawals.
Assets are the underlying token (e.g., USDC, WETH). Shares represent proportional ownership of the vault and typically appreciate as yield accrues.
Vault performance is reflected in the price:
Inflation Attack Protection
ERC4626 vaults are susceptible to inflation attacks , where an attacker manipulates the price to cause rounding losses for subsequent depositors. This affects all ERC4626-compliant implementations.
The Protection Mechanism
Before interacting with a vault, verify that a dead deposit has been made to address 0x000000000000000000000000000000000000dEaD . This initial deposit establishes a baseline supply that makes inflation attacks economically unfeasible.
Why 1e9 shares? This threshold ensures that the cost to manipulate the price exceeds any potential gain from the attack. The specific value (1e9 shares) is a conservative standard that works across different asset decimals and price points.
For assets with less than 9 decimals, the recommended minimum is 1e12 shares to prevent rounding issues (non-critical).
Implementation Notes:
The dead deposit does not need to be made atomically with your interaction
Once established, it cannot be withdrawn (by design)
Morpho Vault V2 integrations should verify that this protection is in place
Curators and vault deployers are responsible for ensuring this protection exists
Additional Considerations: Slippage
ERC4626 functions do not include built-in slippage checks. While not a security requirement (when dead deposit protection is in place), slippage checks can improve user experience by preventing unexpected exchange rate movements between transaction simulation and execution.
When to consider slippage protection:
price may shift due to interest accrual or other vault activity between simulation and inclusion
User-facing applications benefit from showing expected vs. actual amounts received
Implement min-received checks around ERC4626 operations for direct integrations
See the Assets Flow tutorial for integration examples.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
