Skip to content

✨ adapter: use morpho flash loans - #817

Open
patitonar wants to merge 1 commit into
mainfrom
morpho-flashloan-adapter
Open

patitonar wants to merge 1 commit into
mainfrom
morpho-flashloan-adapter

Conversation

@patitonar

@patitonar patitonar commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • New Features
    • Flash loans now use Morpho, supporting single-token loans and integration with debt rolling.
    • Added Morpho deployment addresses for Base and Optimism.

@changeset-bot

changeset-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 8695ffc

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@exactly/protocol Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f8608601-8652-45c9-b08f-1b108cc35f5d

📥 Commits

Reviewing files that changed from the base of the PR and between 4b5fec7 and 8695ffc.

📒 Files selected for processing (8)
  • .changeset/brave-lions-swim.md
  • .gas-snapshot
  • contracts/periphery/FlashLoanAdapter.sol
  • deploy/FlashLoan.ts
  • deployments/base/Balancer3Vault.json
  • deployments/base/Morpho.json
  • deployments/optimism/Morpho.json
  • test/FlashLoanAdapter.t.sol
💤 Files with no reviewable changes (1)
  • deployments/base/Balancer3Vault.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

FlashLoanAdapter replaces its Balancer V3 integration with Morpho flash loans. Deployment configuration adds Morpho addresses for Base and Optimism. Tests cover loan handling, callback authorization, and a DebtRoller integration.

Changes

Morpho Flash-Loan Adapter

Layer / File(s) Summary
Implement Morpho-backed loans
contracts/periphery/FlashLoanAdapter.sol, .changeset/brave-lions-swim.md
The adapter requests a single-token loan from Morpho, forwards the borrowed amount to the recipient callback, and approves Morpho for repayment. It also exposes the token balance held by Morpho through available.
Wire Morpho deployments
deploy/FlashLoan.ts, deployments/base/Morpho.json, deployments/optimism/Morpho.json, deployments/base/Balancer3Vault.json
The deployment script now uses Morpho and skips deployment when Morpho is absent or the network is sunset. Morpho addresses are added for Base and Optimism, and the Balancer vault address file is removed.
Validate loans and integration
test/FlashLoanAdapter.t.sol, .gas-snapshot
Tests cover USDC and WETH loans, request validation, callback authorization, and rolling a fixed USDC borrow through DebtRoller. The gas snapshot records the updated measurements.

Priority: ⚪ Not assessed

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Caller
  participant FlashLoanAdapter
  participant Morpho
  participant Recipient
  Caller->>FlashLoanAdapter: Request a single-token flash loan
  FlashLoanAdapter->>Morpho: Request token and amount with encoded payload
  Morpho->>FlashLoanAdapter: Call onMorphoFlashLoan
  FlashLoanAdapter->>Recipient: Transfer borrowed token
  FlashLoanAdapter->>Recipient: Call receiveFlashLoan with zero fee
  FlashLoanAdapter->>Morpho: Approve repayment
Loading

Merge Risk: ⚪ Minimal · up to 8695f

No actionable issue remains from the reviewed changes. The Morpho deployment path replaces the former Balancer configuration without an identified break in the supported workflow.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 8695f

The new loan flow has callback protections and integration tests, but an existing Base deployment may remain on the old provider unless the adapter and its dependent DebtRoller are migrated together. The deployed provider’s behavior has not been independently verified.

Retained concerns

  • Medium · reliability · inferred: An existing Base installation can retain its Balancer adapter by default; moving DebtRoller to the new provider requires a separately controlled upgrade of its immutable adapter binding. An incomplete migration could leave the intended Morpho flow unused or interrupt debt rolls.
Security review details

Security Blast Radius

  • inferred — The new trusted-provider boundary is each deployed adapter’s immutable Morpho address. A wrong registry binding would affect loans routed through that adapter; the supplied source does not independently establish deployed contract identity at both network addresses.

Security Findings and Attack Paths

  • inferred — No introduced authorization exploit is established: arbitrary callers could already request loans for arbitrary recipients, and DebtRoller checks both its configured adapter and active callback data. Whether other deployment states or provider behavior change effective exposure remains unresolved.

Trust Boundaries and Controls

  • observed — The adapter authenticates the callback sender but does not independently compare the callback’s amount argument with the encoded request. Its settlement relies on Morpho collecting the approved repayment after the recipient returns.

Resilience and Maintainability Implications

  • observed — DebtRoller consumes its active callback hash before changing market state. The Optimism-fork test asserts that Morpho is repaid and its adapter allowance is consumed, but does not prove those properties for every deployment or adversarial provider behavior.

Hardening Proposals

  • proposed — Verify the provider code and repayment semantics at each configured address, then plan and check the adapter and DebtRoller migration together, including recovery if only one deployment step completes.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: replacing the flash-loan adapter with a Morpho-based implementation.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8695ffc69e

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread contracts/periphery/FlashLoanAdapter.sol
@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.81%. Comparing base (4b5fec7) to head (8695ffc).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #817      +/-   ##
==========================================
- Coverage   94.82%   94.81%   -0.01%     
==========================================
  Files          31       31              
  Lines        2724     2702      -22     
  Branches      457      351     -106     
==========================================
- Hits         2583     2562      -21     
+ Misses        140      139       -1     
  Partials        1        1              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant