Morpho vault risk: rated vs. unrated vaults during the Resolv exploit
BACK TO BLOG
April 3, 2026·5 min read

Morpho vault risk: rated vs. unrated vaults during the Resolv exploit

TL;DR

In March 2026, the Resolv exploit exposed a defining dimension of Morpho vault risk: vaults on the same protocol carry materially different risk profiles depending on their collateral configuration. Liquidity froze across several Resolv-exposed strategies while the rest of Morpho’s ecosystem operated normally. None of the 15 Morpho vaults publicly rated by Credora were among those affected.

In May 2025, Credora had assigned USR a junk-grade rating ten months before the exploit. The rated vaults held no USR exposure. That separation existed in the collateral configurations before the event, not because of it.

Risk ratings do not prevent events. They determine who is positioned to absorb them.

This is a case study of that separation.

What happened

On 22 March 2026, an attacker compromised the private key controlling Resolv’s minting authorization layer and used it to issue approximately $80 million in unbacked USR. The attacker deposited approximately $200,000 in USDC, manipulated the minting function, and received approximately $80 million in unbacked USR in return.

The depeg propagated beyond USR holders into lending markets that had accepted USR, wstUSR, and RLP as collateral. As USR’s market value collapsed, hardcoded oracles continued marking positions at $1.00, creating a window during which unpegged USR could be collateralized and borrowed against at par.

The result: undercollateralized positions across the affected Morpho markets and vaults. For depositors in Resolv-exposed strategies, the consequence was illiquidity. Utilization skyrocketed to 100% across most affected vaults. Markets were paused, positions isolated, and the recovery timeline remained uncertain at the time of this writing.

The rating that preceded it

In May 2025, ten months before the exploit, Credora assigned USR a junk-grade rating. The assessment flagged a short operating history, limited stress-tested performance, absent issuer-level licensing, and a thin reserve management track record: signals of elevated Probability of Significant Loss (PSL) and structural fragility, not certainty about a specific failure mode.

The junk-grade PSL reflected structural fragility. The specific failure mode was not yet known.

Morpho vault risk: rated vaults vs. unrated vaults

As of December 2025, Credora had publicly rated 15 Morpho vaults. None was among the affected.

The Credora-rated vaults (Gauntlet USDC Prime, Steakhouse USDC, Vault Bridge USDC, Steakhouse ETH, Gauntlet USDT Prime, and others) held no exposure to USR, RLP, or any of their derivatives at the time of the exploit. None experienced bad debt accumulation, liquidity disruption, or withdrawal restrictions.

The affected vaults (Gauntlet USDC Core, Gauntlet USDC Frontier, KPK USDC, Seamless USDC) were unrated.

This distinction was structural, not coincidental. Credora’s vault rating methodology performs a collateral risk assessment on each accepted asset alongside curator track record, concentration risk, and protocol-level parameters. Vaults that accept higher-risk collateral, including assets with elevated PSL scores, score accordingly. The 15 rated vaults had excluded exactly those assets. The ratings reflected that before the event.

Vaults operating on the same protocol, offered by the same curator, advertising comparable yields, can carry materially different Morpho vault risk profiles depending on what they hold as collateral and how that collateral has been independently assessed. The Resolv incident made that difference observable.

Vault isolation and its limits

Morpho’s vault architecture is built for isolation. Individual vaults have different allocation strategies into markets with different collateral profiles; a failure in one cannot directly cascade into another.

That design held. Of Morpho’s ~500 vaults, 15 had meaningful exposure to Resolv assets. Among the vaults that do not allocate into markets with USR as collateral, liquidity remained available at all times without material change.

Total impact: approximately $8M against $11B+ in total deposits. Under 0.2%.

Isolation is a necessary foundation for risk management to function. It is not risk management itself. Protocol-level due diligence is insufficient as a basis for risk evaluation. Assessments must extend to the vault, market, and collateral asset level. Independent DeFi risk ratings at each layer translate structural risk into quantifiable metrics before events make the distinction visible.

Key Takeaway

Vaults on the same protocol can carry materially different risk profiles. Credora’s Morpho vault risk rating process evaluated USR’s PSL at the asset level in May 2025 and found it junk-grade. No Credora-rated vault held it as collateral when the exploit occurred. Collateral liquidity depth, oracle configuration, liquidation thresholds, curator track record: none of this is visible in the APY figure. DeFi risk ratings make it legible. The incident tested the infrastructure. The rated vaults passed.

Frequently Asked Questions

What Morpho vault risk factors led to liquidity freezes during the Resolv exploit?

The primary factor was collateral acceptance. Affected vaults held USR, wstUSR, and RLP. When USR depegged, hardcoded oracles continued pricing these assets at par, generating undercollateralized positions and driving utilization to 100%. Withdrawal became impossible while markets were paused. All 15 Credora-rated Morpho vaults held none of these assets and experienced no liquidity disruption throughout the event.

How does Credora’s collateral risk assessment work when rating Morpho vaults?

Each accepted collateral asset is assessed individually. Credora assigns a PSL score reflecting the annualized probability that the asset causes significant loss to vault depositors. That score feeds into the vault’s overall DeFi risk rating alongside curator track record, concentration exposure, and protocol parameters. USR received a junk-grade PSL rating in May 2025. No Credora-rated Morpho vault held it as collateral before or during the exploit.

What is the difference between protocol-level and vault-level DeFi risk assessment?

Protocol-level assessment evaluates Morpho as a whole: smart contract architecture, governance, systemic parameters. Vault-level assessment examines what a specific vault holds, how it is managed, and what collateral has been accepted and at what PSL. Two vaults on the same protocol, managed by the same curator, can carry different Morpho vault risk profiles based entirely on collateral configuration. The Resolv incident is a direct demonstration of that gap.


The full USR post-mortem is available at link. Credora’s Documentation is available at https://docs.redstone.finance/docs/redstone-credora/.