Euler:
the rarest story in this series — a $197M hack, a full recovery, and a genuine rebuild.
We tore apart Euler, a modular lending protocol rebuilt from the ground up after one of DeFi's most severe early incidents, across the same lending-adapted scorecard we've used throughout this series. From a genuinely extraordinary, well-documented recovery, 100% of the roughly $197-240 million stolen in the March 2023 exploit was returned within three weeks through direct negotiation with the attacker, to one of the most extensive security investments we've found anywhere in this project: a $4 million dedicated security budget, 45-50+ audits by 13 named firms, a $1.25 million audit competition that found zero high or medium-severity issues, and a $3.5 million live Capture The Flag challenge that whitehats failed to breach. We also found a real, honest structural risk that Euler's own documentation names directly: its modular Vault Kit architecture means a position's actual safety depends on the specific vault's live configuration, not just the reviewed base components, the same "risk shifts to the specific market" theme we found reviewing Morpho. And we found a real, disclosed irony worth centering precisely: the 2023 exploit traced back to a vulnerability introduced by a fix for an earlier, smaller bug that auditors had missed. Since relaunching as V2 in September 2024, Euler's TVL climbed from roughly $3.5 million to $1.5 billion within seven months; and landed on a score the marketing page won't show you.
Our take, up front: Euler is one of the rarest stories in this entire series: a DeFi lending protocol that was catastrophically hacked, fully recovered the stolen funds, and rebuilt from scratch into what may be the most heavily security-tested protocol we've reviewed. Real, genuinely well-documented, extraordinary recovery: on March 13, 2023, Euler V1 was exploited for roughly $197-240 million (sources vary on the exact scope); over the following three weeks, the Euler Labs team negotiated directly with the attacker, navigating real complications including interest from the Lazarus Group, red herrings, and frontrunning bots, and ultimately recovered 100% of the stolen assets. Real, disclosed, precise irony worth naming directly: the exploited vulnerability traced back to a function, donateToReserves, that had been introduced specifically to fix an earlier, smaller "first depositor" bug that every previous auditor had missed. Real, genuinely extraordinary V2 security investment following the incident: a $4 million dedicated security budget, described as unprecedented for an app-layer DeFi protocol, 45-50+ audits by 13 named security firms, a $1.25 million audit competition with Cantina that found zero high or medium-severity issues, and a $3.5 million live Capture The Flag challenge with Hats Finance that whitehats attempted and failed to breach. Real, disclosed genuinely distinctive modular architecture: the Euler Vault Kit (EVK) and Ethereum Vault Connector (EVC) let each vault independently select its own collateral relationships, oracle routes, interest-rate models, caps, hooks, and governance, rather than sharing one pool. What we can't set aside: Euler's own documentation directly and honestly states that a position's actual safety depends on the specific vault's live configuration, not just the reviewed base components, the same "risk shifts to the specific market" structural theme we found reviewing Morpho. Real, disclosed institutional backing from Wintermute (also connected to Bebop, reviewed earlier in our DEX aggregator series) and a risk-management partnership with Gauntlet. Real, disclosed strong recovery trajectory: TVL grew from roughly $3.5 million shortly after V2's September 2024 relaunch to $1.5 billion by April 2025. Real, disclosed, honest ongoing consideration from a detailed third-party source: the 2023 exploit remains "a lasting trust and diligence overhang" even years later, despite the genuinely extensive V2 security investment. We weighted all of it below.
Real, severe, well-documented Mar 2023 exploit: ~$197-240M drained from Euler V1 via a vulnerability traced back to donateToReserves, a function introduced to fix an earlier, smaller bug that every previous auditor had missed. Real, genuinely extraordinary recovery: 100% of stolen assets returned within three weeks via direct negotiation with the attacker. Real, genuinely extraordinary V2 security investment: a $4M dedicated security budget, 45-50+ audits by 13 named firms, a $1.25M audit competition with zero high/medium findings, and a $3.5M live Capture The Flag challenge that whitehats failed to breach. No confirmed hack of V2 found in our research since its September 2024 relaunch. What tempers this: Euler's own documentation directly states that a position's safety depends on the specific vault's live configuration, not just the reviewed base components, the same "risk shifts to the specific market" theme found in our Morpho review.
Pros
- 100% of the ~$197-240M stolen in 2023 was recovered via direct negotiation
- $4M security budget; 45-50+ audits by 13 firms; a $3.5M live CTF whitehats failed to breach
- No confirmed hack of V2 found since its September 2024 relaunch
Cons
- Mar 2023: one of the more severe exploits in DeFi lending history, caused by a prior security fix itself
- Modular vault design means real risk assessment shifts onto users per-vault, per Euler's own disclosure
- A detailed third-party source describes the 2023 incident as "a lasting trust and diligence overhang"
Real, disclosed strong, well-documented recovery trajectory: TVL grew from roughly $3.5 million shortly after the September 2024 V2 relaunch to $133M (Jan 2025), $671M (Mar 2025), and $1.5 billion (Apr 2025). Real, disclosed multichain expansion across Base, Swell, Sonic, BOB, Berachain, and Avalanche.
Pros
- TVL grew roughly 400x from post-relaunch lows to $1.5B within seven months
- Multichain expansion across six additional networks
Cons
- Still smaller in absolute scale than the category's largest incumbents
Real, disclosed functioning EUL governance token. Real, disclosed institutional risk-management partnership with Gauntlet, and backing from Wintermute. Real, genuinely transparent, publicly-told recovery story, with named team members speaking openly and in detail about the 2023 incident rather than minimizing it.
Pros
- Genuinely transparent, detailed public account of the 2023 incident and recovery from named team members
- Institutional risk partnership with Gauntlet; backing from Wintermute
Cons
- Thin traditional/enterprise-style review coverage outside crypto-native sources, per a detailed source
Real, disclosed genuinely modular, flexible vault system supporting diverse, specialized markets, including Resolv's delta-neutral USR stablecoin, Usual's fixed-rate USD0++ lending, and Alchemix's alAsset cross-borrowing integration.
Pros
- Modular vault system enables specialized markets (Resolv, Usual, Alchemix) not easily replicated on pooled protocols
Cons
- Specialized markets mean asset quality and risk vary meaningfully vault to vault
Real, disclosed strong user-retention signal: monthly active users climbing and outpacing the growth of larger-TVL competitors, described directly as users "keep returning" to Euler's interface. Real, disclosed streamlined "Multiply" feature for leveraged positions.
Pros
- Disclosed user retention outpacing larger-TVL competitors
- Streamlined Multiply feature for leveraged positions
Cons
- Modular vault selection adds real complexity relative to a single-pool interface
Real, disclosed capital-efficient design with a disclosed ~43% utilization rate, and competitive stablecoin yields via specialized partner markets. Our sources disclosed less specific, universally-quoted rate figures than for some other protocols in this series.
Pros
- Disclosed ~43% utilization; competitive specialized-market yields
Cons
- Less specific, universally-quoted rate figures disclosed than some competitors in this series
Real, genuinely extensive, distinctive feature set: EulerSwap (an integrated AMM), Euler Earn, the Multiply leverage feature, and deep specialized-market integrations with Resolv, Usual, and Alchemix.
Pros
- EulerSwap, Euler Earn, and Multiply form a genuinely extensive, distinctive feature suite
- Deep, specialized integrations with Resolv, Usual, and Alchemix
Cons
- Breadth of features adds to the modular complexity flagged in the security category
Access only through Euler's official app, and review the specific vault's configuration before depositing.
Given that Euler's own documentation directly advises checking each vault's collateral links, oracle routes, caps, LTVs, and governance before depositing, take that advice seriously: a vault built on Euler's audited base components is not automatically as safe as the base components themselves if its specific configuration is aggressive or poorly parameterized.
A genuine second chance, earned the hard way, that we still can't score as if the first chance never happened.
We don't think many teams could have done what Euler Labs did after March 2023: not just patch the bug, but negotiate the full return of the stolen funds, and then spend the next year and millions of dollars building something more heavily tested than almost anything else we've reviewed in this entire project. The $3.5 million live Capture The Flag challenge that whitehats failed to breach is a genuinely rare, credible form of evidence, not just a marketing claim. That effort deserves to be recognized on its own terms, and we've tried to do that. But we also don't think a thorough rebuild retroactively erases the fact that a real, severe exploit happened, caused in part by a fix that introduced a new problem while solving an old one, a reminder that even careful, well-intentioned changes carry real risk. And Euler's own honesty about its modular design, that your safety depends on the specific vault's configuration and not just the audited base layer, is a real, ongoing responsibility it's asking users to share. We think that combination, genuine redemption plus a genuinely ongoing, disclosed risk, is the fairest way to read this score.
The scorecard above is deliberately general. Whether Euler is right for you depends heavily on which of these you already are.
The user who wants access to specialized, modular markets (Resolv, Usual, Alchemix) not easily replicated on pooled protocols
This is exactly where Euler's genuinely distinctive, modular architecture delivers real, demonstrated value.
The security-conscious user who wants to see a protocol's response to a real crisis, not just its marketing before one
Euler's transparent, detailed public account of its 2023 recovery and V2 rebuild is a genuinely rare, credible data point.
The depositor who reviews a specific vault's collateral links, oracles, and caps before depositing meaningful funds
Given Euler's own direct advice on this point, this specific habit genuinely matters here more than on single-pool protocols.
Anyone who wants a lending protocol with no history of a major exploit
Aave, Compound, Kamino, and SparkLend, all reviewed earlier in this series, don't carry a comparable past incident of this scale.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the 2023 exploit and recovery timelined precisely, the V2 security investment broken down, the "risk shifts to the vault" structure explained, and our ninth lending-protocol comparison entry.
March 2023, timelined
| Date | Event |
|---|---|
| Mar 13, 2023 | An attacker exploits a vulnerability in donateToReserves, a function originally introduced to fix an earlier, smaller "first depositor" bug that had been missed by all previous auditors |
| Mar 13, 2023 | Roughly $197-240 million (sources vary on exact scope) is drained from Euler V1 |
| Following ~3 weeks | Euler Labs negotiates directly with the attacker, navigating interest from the Lazarus Group, red herrings, and frontrunning bots |
| ~Early April 2023 | 100% of stolen assets are returned |
| Sept 2024 | Euler V2 launches, rebuilt from the ground up around the Euler Vault Kit and Ethereum Vault Connector |
We want to highlight the precise irony directly: the vulnerability that caused a ~$200M+ loss originated in a fix meant to close a smaller, earlier gap, a reminder that even well-intentioned patches carry real risk.
The V2 security investment, broken down
| Investment | Detail |
|---|---|
| Security budget | $4 million, described as unprecedented for an app-layer DeFi protocol |
| Audits | 45-50+ audits by 13 named security firms |
| Audit competition | $1.25 million with Cantina; zero high or medium-severity issues found |
| Capture The Flag | $3.5 million with Hats Finance; whitehats attempted and failed to breach live contracts |
| Additional measures | Formal verification, dedicated fuzz testing, and a bug bounty program |
This is one of the more extensive, well-documented security investments we've found across every review in this project, DEX, aggregator, or lending protocol alike.
Why your specific vault matters
| What it means | |
|---|---|
| Base components (EVK, EVC) | Reviewed, audited, and extensively tested at the protocol level |
| A specific vault's configuration | Independently set by whoever deploys it: collateral links, oracle routes, caps, LTVs, governors |
| What Euler's own docs recommend | Review deployed addresses, oracles, caps, and pending governance actions for the specific vault you use |
This is structurally similar to the permissionless-market risk we found reviewing Morpho: a well-audited base layer doesn't guarantee a well-configured individual market or vault built on top of it.
Lending protocols, side by side (series continues)
| Aave | Compound | CoinRabbit | Kamino | Binance Loans | Morpho | Nexo | SparkLend | Euler | |
|---|---|---|---|---|---|---|---|---|---|
| Model | Non-custodial | Non-custodial | Custodial CeFi | Non-custodial | Custodial CeFi | Non-custodial | Custodial CeFi | Non-custodial (Aave fork) | Non-custodial (modular) |
| Most severe disclosed history | $292M bridge exploit | $161.7M governance bug | Transparency gaps | None found | $4.3B DOJ settlement | $18M vault loss | $500K CA penalty | None found | $197-240M exploit (2023), 100% recovered |
| Distinctive model | Multi-network V3/V4 | Isolated Comet markets | Fixed-rate, no-KYC | Curator-managed markets | Tiered CeFi products | Immutable core + vaults | Loyalty-tier CeFi | Aave fork, blue-chip only | Modular EVK/EVC vaults |
Euler is the only protocol in this series with a full, negotiated recovery of a nine-figure exploit; that single fact shapes both the real caution and the real credit in our score.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've excluded Euler's own blog post recounting the recovery from this comparison, treating it as a primary source we weighted directly rather than an independent review.
Our score lands moderately below the aggregated industry average; most general reviews we found emphasize the comeback narrative and the extensive V2 security investment without weighting the original 2023 severity or the disclosed per-vault risk-shifting structure as heavily as our methodology does.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes. On March 13, 2023, Euler V1 was exploited for roughly $197-240 million. Over the following three weeks, Euler Labs negotiated directly with the attacker and recovered 100% of the stolen assets. No confirmed hack of V2 has been found since its September 2024 relaunch.
A vulnerability in a function called donateToReserves, which had originally been introduced to fix an earlier, smaller "first depositor" bug that every previous auditor had missed. The fix itself created the exploitable condition.
Through direct negotiation with the attacker over roughly three weeks, a process complicated by apparent interest from the Lazarus Group, red herrings, and frontrunning bots. The full amount was ultimately returned voluntarily by the attacker.
The modular framework underlying Euler V2, paired with the Ethereum Vault Connector (EVC). Rather than one shared lending pool, each vault independently sets its own collateral relationships, oracle routes, interest-rate models, and caps.
A disclosed $4 million security budget, 45-50+ audits by 13 named firms, a $1.25 million audit competition with zero high or medium findings, and a $3.5 million live Capture The Flag challenge that whitehats attempted and failed to breach.
No. Euler's own documentation states directly that a position's safety depends on both the reviewed base components and the live configuration of the specific vault you use, including its collateral links, oracles, caps, and governance.
TVL grew from roughly $3.5 million shortly after the September 2024 V2 relaunch to $1.5 billion by April 2025, a roughly 400x increase within seven months.
Gauntlet serves as a risk-management partner, and Wintermute, the same market maker behind Bebop (reviewed in our DEX aggregator series), has provided backing.
More Reviews
Ledn – Crypto Lending & Borrowing Review
Score: 75/100. Highest CeFi score in this series: 10 straight PoR attestations, explicit no-re-lending pledge, never lost customer funds.
Read MoreAave – Crypto Lending & Borrowing Review
Score: 69.5/100. Category leader hit hardest by the Apr 2026 KelpDAO crisis: $124-230M bad debt, its largest liquidity event yet.
Read MoreCompound – Crypto Lending & Borrowing Review
Score: 63.25/100. Pioneer whose 2021 self-inflicted $161.7M COMP bug remains its scar, though its caution spared it in Apr 2026.
Read MoreCoinRabbit – Crypto Lending & Borrowing Review
Score: 50.5/100. Fast, no-KYC lending with a great product, but no named founder, no PoR, and vague licensing behind it.
Read More



