Sherlock's May 2026 Morpho Blue curator audit identified a high-severity front-running window during pending withdrawals. Curators with access to vault parameter updates should declare a 24h timelock; users with active redemptions should avoid vaults without timelocked curator roles.
// findings · 1
- [HIGH]
Curator role can update vault parameters during a pending withdrawal, allowing front-running of redemptions.
MorphoVault.curatorUpdateredemption queueCurator role can update vault parameters during a withdrawal, front-running a redemption to extract value.
ref: H-01affects:morpho-curatorvault-supply