Real-capital social-engineering persona
Morpho V1 (Morpho Blue + MetaMorpho)'s assessment for RD-F-184 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No curator flag or OSINT evidence of any 'contributor' or 'external integrator' persona with >=1M USD attributed deposits used to build credibility ahead of a social-engineering attack. Neither of the two Morpho incidents (Oct 2024 oracle misconfiguration, Apr 2025 frontend SDK) involves a social-engineering persona.
Detail #
F184 references the Drift Protocol UNC4736 class (real-capital deposits >$1M as part of 6-month conference/in-person build-up). No analogous pattern flagged for Morpho. The two known incidents are: (1) Oct 2024 PAXG/USDC oracle SCALE_FACTOR error by unknown market creator (~$230K) — oracle misconfiguration, not social engineering; (2) Apr 2025 frontend SDK configuration error — internal Morpho team error, not social engineering. P1 M-only factor; absence of adverse signal is the finding.
Sources #
- URLMorphoBlue Hack Analysis — SolidityScanMorpho Blue incident Oct 2024 — oracle misconfiguration (not social engineering)retrieved 2026-04-27
- Morpho App Incident April 10, 2025 — Morpho blogMorpho App incident Apr 2025 — frontend SDK config error (not social engineering)retrieved 2026-04-27
Methodology #
Determine whether a curator-flagged "team contributor" or "external integrator" persona has ≥$1M of attributed real-capital deposits to the target protocol or peer protocols, potentially used to build credibility ahead of a social-engineering attack.
See the full factor methodology and distribution across all protocols →