On March 22, 2026, the Resolv USR exploit exposed gaps in our rating framework - gaps we documented in our Framework Update article and closed with three targeted changes to v0.1-beta. With the updated framework in hand, we re-rated all eight Morpho vaults. Here's what changed.
Six out of eight vaults dropped. The Frontier V1 vault - the only one with direct Resolv exposure - fell the hardest, dropping three grade notches from BB- to CCC+. Even vaults with no direct Resolv exposure saw one-notch downgrades from the framework's new structural requirements.
Three framework changes affected all Morpho vaults equally:
1. Monitoring Verification Principle
The old framework gave credit for naming a monitoring provider. The updated framework requires demonstrated automated protective actions - claiming to use Hypernative or Chainalysis isn't enough if monitoring can't trigger a halt when it matters. All Morpho vaults were downgraded on this question because none have monitoring connected to automated on-chain protections.
The one exception is Smokehouse USDC, which initially retained its score based on demonstrated rapid response times (4-minute rollback in April 2025). This was later aligned downward for platform consistency, since the underlying Morpho architecture still lacks automated protection capabilities regardless of curator response speed.
2. New Question: Automated Exposure Increase
This question didn't exist before. It was added specifically because the Resolv exploit showed that permissionless functions (like Morpho's Public Allocator) can increase vault exposure without human approval. Most vaults scored Mid Risk (caps exist but no automatic kill-switch). The Frontier V1 vault scored High Risk because the Public Allocator's supplyOnBehalf function was exploited to inject capital into compromised markets.
3. Circuit Breaker Scope Expansion
The updated framework requires circuit breakers to cover all automated capital flows, not just protocol-level pause mechanisms. Morpho Blue is immutable by design and has no automatic circuit breakers. Vaults with manual Sentinel roles or Guardian veto scored Mid Risk; those without any mechanism scored High Risk.
These three changes alone account for the one-notch downgrades seen across vaults that had no other issues.
Steakhouse Vaults (USDC, USDT, ETH)
The three Steakhouse vaults were the least affected beyond the common changes. No vault-specific scoring changes were needed - these vaults had no Resolv exposure, no exotic collateral failures, and a clean operational track record. Steakhouse USDT and ETH held their BB+ grades; Steakhouse USDC dropped one notch from BBB- to BB+.
The re-rating also updated two question texts (on oracle correction capability and protocol mechanics scope) to match the expanded v0.1-beta wording. Neither text change affected scores.
Smokehouse USDC
Same pattern as the Steakhouse vaults - common framework changes only, dropping one notch from BB to BB-. The gap between Smokehouse and Steakhouse USDC remains entirely in Strategy, reflecting Smokehouse's exotic collateral exposure (sUSDe, syrupUSDC, mF-ONE, Pendle PT tokens). This gap predated the framework update and was unaffected by it.
Gauntlet USDC Prime
Gauntlet Prime was completely unaffected by the Resolv exploit itself - its blue-chip-only collateral mandate (wstETH, cbBTC, WBTC) prevented any USR exposure. But the framework update still hit it harder than the Steakhouse vaults (BBB- to BB+, same as Steakhouse USDC on the surface, but with additional question-level downgrades) because of ripple effects from Gauntlet's involvement with the Frontier vault:
VaultBridge WBTC
VaultBridge WBTC followed the same pattern as Gauntlet Prime - common framework changes plus the same Gauntlet-specific ripple effects. It dropped one notch from B+ to B. VaultBridge remains the lowest-scoring non-Frontier Morpho vault due to its heavy WBTC custody risk and 100% wrapped asset concentration, which predated the framework update.
Gauntlet USDC Frontier V2
Frontier V2 is a new vault deployed after the Resolv exploit, designed to address V1's failures. It dropped one notch from B+ to B, with additional downgrades beyond the common changes:
V2 also inherits the Gauntlet-specific incident response and manager loss history penalties. Despite this, V2 grades significantly above V1 (B vs CCC+), reflecting its improved architecture: adapter-based allocation with caps, no permissionless supplyOnBehalf, and clean exploit history on the vault itself.
Gauntlet USDC Frontier (V1) - The Outlier
Frontier V1 was the only vault directly impacted by the Resolv exploit. Its three-notch drop from BB- to CCC+ dwarfs every other re-rating because the exploit didn't just trigger framework penalties - it created new facts on the ground:
Strategy was the hardest-hit category, with 14 of 32 strategy questions now scoring High Risk. Security also dropped below all other Morpho vaults because the exploit history question was downgraded pending compensation verification. Operations fell as Gauntlet's first confirmed bad debt was recorded.
Every re-rated vault was run through our automated validator. Key findings:
The v0.1-beta framework changes were targeted: three new or updated questions, each motivated by a specific failure mode exposed by the Resolv exploit. The impact was proportional to exposure:
No vault was upgraded. The framework got stricter, and every vault's grade reflected that.
Morpho Steakhouse USDC — BBB- → BB+
Morpho Gauntlet USDC Prime — BBB- → BB+
Morpho Steakhouse USDT — BB+ → BB+
Morpho Steakhouse ETH — BB+ → BB+
Morpho Smokehouse USDC — BB → BB-
Morpho Gauntlet USDC Frontier V2 — B+ → B
Morpho VaultBridge WBTC — B+ → B
Morpho Gauntlet USDC Frontier (V1) — BB- → CCC+
Full ratings, validation results, and the updated framework are available in the Staking Rewards DeFi Rating Framework.
Join 12,000 institutional allocators worldwide. No spam, unsubscribe anytime.
