Decentralized lending protocol Moonwell is investigating a security incident affecting the MAMO Core Market on Base after blockchain security firms flagged what they described as a multi-million-dollar exploit. CertiK and PeckShield estimated losses at roughly $8.7 million, while Moonwell said it had imposed emergency limits across Base Core Markets as a precaution.
According to Moonwell’s statement on X, all borrowing caps for Core Markets on Base have been set to 1 wei. The protocol also reduced the supply caps for MAMO and WELL to 1 wei. PeckShield said the attacker consolidated the stolen funds into an address holding the DAI stablecoin.
CertiK said the exploit involved manipulation of the collateral price for the low-liquidity MAMO token, after which the attacker borrowed real cbBTC from the mCBTC market. Blockaid identified the same attack pattern. Following the incident, WELL fell about 13% over 24 hours and MAMO dropped about 9%. The report also placed the case within a broader wave of DeFi exploits since April, a period in which more than $600 million has been stolen across protocols, with the largest single incident cited as Kelp DAO’s $292 million exploit.
Moonwell is investigating an issue affecting the MAMO Core Market on Base after security firms flagged what they described as a multi-million-dollar exploit with estimated losses of about $8.7 million.
In a post on X, Moonwell said it had set the borrowing caps for all Core Markets on Base to 1 wei as a precaution. The protocol also set the supply caps for MAMO and WELL to 1 wei.
Security firms outlined the attack route
PeckShield said the attacker consolidated the stolen funds into an address associated with the DAI stablecoin. CertiK said the attacker manipulated the collateral price of the low-liquidity MAMO token, then borrowed real cbBTC from the mCBTC market to carry out the exploit. Blockaid identified the same attack mechanism.
Token prices moved lower after the incident
Following the exploit, WELL fell about 13% over 24 hours, while MAMO dropped about 9%.
Part of a broader run of DeFi exploits since April
The incident was described as part of a stretch of frequent DeFi exploits since April. During that period, more than $600 million was stolen from multiple protocols, with the largest case cited as Kelp DAO’s $292 million exploit.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.