docs.morpho.org Critical Vulnerability in Morpho Vault V1 Exposes Users to Inflation Attacks
Article Content
- •Morpho Vault V1 is vulnerable to inflation attacks via faulty oracles.
- •Attackers can drain assets by inflating vault prices through donations.
- •Curators must implement automated monitoring and careful oracle selection.
Morpho Vault V1 has a critical vulnerability that allows attackers to exploit faulty oracles, leading to potential asset loss. The attack method involves manipulating the vault's price by donating assets on a broken market and withdrawing inflated positions. Curators and advanced users are particularly affected, as the vulnerability can drain assets from the vault. The maximum loss is calculated based on the total debt that can be taken using collateral acquired below the oracle price. Recommendations include careful oracle selection and deploying automated monitoring systems. Vault V2 is not affected by this issue when using the correct adapters. The situation is urgent as the vulnerability remains and exploitable.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…