Summary
The most critical subjects covered in our audit are asset solvency, functional correctness, and precision of arithmetic operations. Asset solvency has been improved after the issues Assets Can Be Double Counted and Unallocated Vault Adapter Can Report Assets were fixed. Given our Trust Model, security regarding all the aforementioned topics is good.
In summary, we find that the codebase provides a good level of security.
It is important to note that security audits are time-boxed and cannot uncover all vulnerabilities. They complement but don't replace other vital measures to secure a project.
About Morpho Vault V2
Morpho Labs implements the second version of Morpho curated vaults. The vaults are ERC-4626 compliant and non-custodial thanks to timelocks and to the "in-kind redemption" mechanism. They allow for simultaneous investments into several protocols and markets. The design of the role system allows for reasonable resilience against corrupt administrators.