Skip to content
Critical Vulnerability in Morpho Vault V1 Exposes Users to Inflation Attacks

Critical Vulnerability in Morpho Vault V1 Exposes Users to Inflation Attacks

First seen 30 Sep 2026, 09:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 09:36 UTC
  • •Morpho Vault V1 is vulnerable to inflation attacks via faulty oracles.
  • •Attackers can drain assets by inflating vault prices through donations.
  • •Curators must implement automated monitoring and careful oracle selection.

Morpho Vault V1 has a critical vulnerability that allows attackers to exploit faulty oracles, leading to potential asset loss. The attack method involves manipulating the vault's price by donating assets on a broken market and withdrawing inflated positions. Curators and advanced users are particularly affected, as the vulnerability can drain assets from the vault. The maximum loss is calculated based on the total debt that can be taken using collateral acquired below the oracle price. Recommendations include careful oracle selection and deploying automated monitoring systems. Vault V2 is not affected by this issue when using the correct adapters. The situation is urgent as the vulnerability remains and exploitable.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-30
Security considerations published
Morpho released a document outlining critical security considerations for Vault V1 curators, highlighting vulnerabilities related to faulty oracles.
docs.morpho.org

More articles in this cluster (2)