Decentralized lending protocol Moonwell suffered an estimated $8.7 million exploit on August 27 after an attacker manipulated the price of MAMO collateral on Base and used its inflated value to borrow higher-quality assets from the protocol. Blockchain security firms PeckShield and CertiK separately estimated losses at approximately $8.7 million. The attacker targeted Moonwell’s MAMO Core Market, exploiting the relatively limited liquidity of MAMO to increase the token’s apparent collateral value before borrowing assets from Moonwell’s lending markets.
CertiK initially identified the attacker borrowing Coinbase Wrapped Bitcoin, or cbBTC, from the mCBTC market. PeckShield subsequently reported a broader $8.7 million loss, with the stolen value eventually consolidated into DAI at an attacker-controlled address. The figure remains preliminary. Moonwell has not yet released a complete post-mortem establishing its final unrecoverable loss or detailing the precise oracle and transaction mechanics involved.
Manipulated MAMO Price Enabled Overcollateralized Borrowing
Initial security analysis indicates the exploit centered on price manipulation rather than an identified vulnerability in Moonwell’s core smart-contract code. MAMO is a relatively illiquid Base ecosystem token. That limited liquidity made its market price easier to move substantially with concentrated trading activity. By artificially increasing MAMO’s quoted price, the attacker increased the value Moonwell assigned to the tokens being supplied as collateral. That enabled the attacker to borrow considerably more valuable assets than the collateral could realistically support once MAMO returned toward its genuine market value. Blockaid initially detected more than 50.6 cbBTC being drained from Moonwell’s mCBTC market, worth more than $4 million at the time. That represented only an early portion of the attack.
Subsequent tracking indicated the attacker also extracted assets including USDC, wrapped staked Ether and ETH before converting and consolidating proceeds. The incident illustrates a fundamental risk for decentralized lending protocols that accept thinly traded tokens as collateral. Even when lending contracts function as designed, manipulated external prices can cause the protocol to calculate an artificially high borrowing capacity. If the borrowed assets are substantially more liquid than the collateral, the resulting position can leave lenders with unrecoverable bad debt.
Moonwell Effectively Halts New Borrowing on Base
Moonwell responded by sharply restricting its Base lending markets while investigating the attack. The protocol reduced borrow caps for all Base Core Markets to 1 wei, effectively preventing users from initiating additional borrowing and limiting the possibility of further losses. Supply caps for MAMO and Moonwell’s WELL governance token were also reduced to 1 wei. Supply caps for other assets remained unchanged. The latest incident follows earlier pricing-related problems for Moonwell. A November 2025 oracle issue involving wrsETH generated approximately $3.7 million of bad debt, while a separate cbETH pricing error in February 2026 produced another approximately $1.78 million.
The February incident resulted from an incorrect scaling calculation that caused cbETH, then worth around $2,200, to be valued at approximately $1.12. Liquidators were consequently able to repay loans at distorted prices and seize collateral. The August attack differs because early analysis indicates an external actor deliberately manipulated the market price of accepted collateral rather than exploiting an accidental pricing calculation inside the protocol. Moonwell’s WELL token fell approximately 13% over 24 hours following disclosure of the latest incident, while MAMO declined around 9% as the market assessed the potential losses. The attack also arrives during an unusually damaging period for decentralized-finance security. Multiple protocols have suffered major exploits since April, including the approximately $292 million Kelp DAO incident.
For Moonwell, the immediate priority is determining whether any of the $8.7 million can be recovered and calculating the resulting bad debt. The longer-term question is whether another pricing-related loss forces changes to Moonwell’s collateral standards and oracle protections. With three significant pricing incidents reported since November, the latest exploit highlights that lending-protocol security depends not only on secure smart-contract code, but also on whether the prices used to value collateral can withstand deliberate market manipulation.
