New contract with similar bytecode to exploit template
Morpho V1 (Morpho Blue + MetaMorpho)'s assessment for RD-F-094 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No publicly flagged bytecode-similar exploit-template deployments targeting Morpho Blue markets as of 2026-04-27. However, permissionless market creation allows deployment of malicious oracle contracts, which is an architecturally distinct but related threat.
Detail #
Morpho Blue's oracle-agnostic design means a malicious oracle adapter can be deployed by any address and used in a permissionlessly created market. This is not standard exploit-template bytecode reuse but achieves similar effect. No public reports of exploit-template deployments in 2025-2026.
Sources #
- Docshttps://docs.morpho.org/learn/resources/risks/retrieved 2026-04-27
Methodology #
Detect whether a freshly deployed contract has high bytecode similarity to a known exploit template targeting this protocol class.
See the full factor methodology and distribution across all protocols →