In March 2023 an attacker exploited a flaw in Euler's liquidation path — a donation attack that manipulated internal accounting — and drained $197m, one of the largest DeFi losses ever. After weeks of on-chain negotiation the attacker returned almost all of it, and Euler chose to rebuild the protocol rather than redeploy the old one.
What v2 changed
The Euler Vault Kit is a different architecture: vaults are created with explicit parameters, risk is isolated per vault, and the liquidation mechanics that produced the original flaw were redesigned rather than patched. Audit coverage is extensive and the bug bounty is among the largest in DeFi — appropriate responses from a team that has been through the worst outcome.
Permissionless creation and its implications
Anyone can deploy a vault with any parameters. That flexibility supports genuinely useful configurations and guarantees that badly parameterised vaults exist. As with Morpho, the protocol is the machinery and the specific market is what you must evaluate: check the collateral, the LTV, the oracle and the caps before depositing.
Assessing the history fairly
An exploited protocol that recovered funds, rebuilt from scratch and has operated without incident since is not the same risk as one that patched and continued. It is also not the same as one that was never exploited. Both facts belong in the assessment, which is why security scores 8 rather than 9 or 5.
Who should use it
Users who want configurable isolated lending markets and will evaluate the specific vault. Conservative depositors have less to gain here than at Aave.