Morpho
Maximum reward
$2,500,000
Severity
Max. Reward
Critical$2,500,000
High$50,000
Medium$10,000
Low$3,000
Deposit required
$30
Findings submitted
1,681
Start date
27 Mar 2024
Please sign in as a researcher to join the bounty.
Log inMorpho is an open lending network that connects lenders and borrowers to the best opportunities globally. Businesses integrate Morpho's neutral infrastructure to power lending or borrowing products at scale, including embedded crypto-backed loans and earn products. Morpho network is powered by multiple protocols:
- Morpho Midnight: a non-custodial fixed-rate lending protocol.
- Morpho Blue: a non-custodial variable rate lending protocol.
- Morpho Vault V2: non-custodial vaults that can allocate to any protocol via adapters.
- Morpho Vaults V1 (previously known as MetaMorpho): non-custodial vaults that can allocate to Morpho Blue markets.
For more information about Morpho, please visit https://morpho.org/ Morpho provides rewards in USDC on Ethereum, denominated in USD. Reward ranges per severity are listed for each asset group on the Scope tab.
Scope
WepApps in scope:
- https://app.morpho.org/
- https://curator-v1.morpho.org/
- https://curator.morpho.org/
- https://fallback.morpho.org/
- https://liquidation.morpho.org/
- https://morpho.org/
- https://markets.morpho.org/
- https://github.com/morpho-org/sdks
Smart Contracts in Scope
The in-scope smart contracts, with their deployed addresses on every supported chain, are listed on the Morpho contract addresses page. That page is the source of truth for scope.
Severity Classification
| SeverityLevel | Impact: Critical | Impact: High | Impact: Medium | Impact: Low |
|---|---|---|---|---|
| Likelihood: High | Critical | High | Medium | Low |
| Likelihood: Medium | High | High | Medium | Low |
| Likelihood: Low | Medium | Medium | Low | Informational |
Details on Bounty severity classification: https://docs.cantina.xyz/cantina-docs/cantina-bounties/bounty-severity-classification
Eligibility:
To participate in this program, security researchers must comply with the rules of engagement and must not:
- Be listed on OFAC's SDN list
- Have been an official contributor, either past or present
- Be employees or individuals closely associated with the project
- Be security auditors who directly or indirectly participated in the audit review
Morpho will require KYC information for processing payments on successful bug submissions. The following details must be provided:
- Full name
- Date of birth
- A copy of your passport or other government-issued ID
To be eligible for a reward under this Program, you must:
- Discover a previously-unreported, non-public vulnerability that is not previously known by the Morpho team and is within the scope of this Program
- Be the first to disclose the unique vulnerability, in compliance with the disclosure requirements.
- Not submit a vulnerability caused by an underlying issue that is the same as an issue on which a reward has been paid under this Program.
- Provide sufficient information to enable our engineers to reproduce and fix the vulnerability.
- Not exploit the vulnerability in any way, including through making it public or by obtaining a profit (other than a reward under this Program).
- Not publicize or exploit a vulnerability in any way, other than through private reporting to us
- Refrain from any privacy violations, destruction of data, interruption or degradation of any of the assets in scope.
- Not engage in any unlawful conduct when disclosing the bug, including through threats, demands, or any other coercive tactics.
- Comply with all the rules of the Program, including but not limited to, refraining from engaging in any Prohibited Actions.
Prohibited Actions
- Live testing on public chains, including public mainnet deployments and public testnet deployments.
- We recommend testing on local forks, for example using foundry.
- Public disclosure of bugs without the consent of the Morpho team.
- Conflict of Interest: any individual who is or has ever been employed by Morpho may not participate in the Bug Bounty. Additionally, any individual who has been involved in or contributed to the development of the code of the bug in question may not participate in the Bug Bounty.
Disclosure
The vulnerability must not be disclosed publicly or to any other person, entity or email address before Morpho has been notified, has fixed the issue, and has granted permission for public disclosure.