defirisk.co
rubric v1.7.0

Permissionless-pool lending oracle

Stake DAO's assessment for RD-F-181 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Not applicable — Stake DAO's Morpho lending vault oracles use Chainlink push-oracle feeds (not permissionlessly-created DEX pools). Morpho Blue uses an immutable oracle-per-market model where the oracle is specified at market creation (governance-controlled), not from a permissionless pool factory. CurveCryptoswapOracle uses Chainlink hop chains and Curve's lp_price() — both are established, non-permissionless sources. No Uniswap v2/v3 factory without filters, no permissionless pool acceptance pattern detected. Green: architecture incompatible with permissionless-pool oracle acceptance.

Sources #

Methodology #

Determine whether the lending protocol accepts spot prices from a DEX where any user can permissionlessly create new pools, without requiring a TWAP window, liquidity floor, or token-age minimum on the venue side.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol stake-dao factor RD-F-181 score green collected_at 2026-05-16 12:29:20