Moonwell loses nearly $9 million on Base as latest exploit becomes its fourth pricing-related incident in under a year

Moonwell loses nearly $9 million on Base as latest exploit becomes its fourth pricing-related incident in under a year

N
News Editor
2026-08-27 12:58:38
Moonwell, a DeFi lending protocol on Coinbase’s Base network, was hit by an exploit that drained nearly $9 million in user deposits, according to Protos and on-chain security alerts from Blockaid. The attacker manipulated the price of MAMO, a relatively illiquid token accepted as collateral on Moonwell, then borrowed assets from the protocol’s mCBTC market. Blockaid said the attack was first flagged about an hour after it began, initially identifying 50.6 cbBTC, worth more than $4 million, as already drained. Protos reported that the losses later climbed as the attacker borrowed cbBTC, USDC, WETH, and wstETH, then swapped the proceeds into DAI. Of that amount, 8.7 million DAI was reported to be sitting in an Ethereum address funded via Tornado Cash. Moonwell said it responded by cutting all borrow caps, along with MAMO and WELL supply caps, to one wei to block new borrowing and contain any added damage. The incident is the protocol’s fourth pricing-related problem in less than a year, following earlier episodes involving an October 10 market-crash discrepancy, fallout tied to the Balancer hack, and a February contract error involving cbETH valuation.

DeFi lending platform Moonwell has lost nearly $9 million in deposits in an attack on Base, with the exploit centered on manipulated collateral pricing for MAMO. Blockchain security firm Blockaid flagged the incident about an hour after it started, and Moonwell later confirmed it had moved to contain the damage by setting all borrow caps, as well as MAMO and WELL supply caps, to one wei.

Moonwell loses nearly $9 million on Base as latest exploit becomes its fourth pricing-related incident in under a year 2

The exploit used inflated MAMO collateral values

According to Blockaid, its Exploit Detection system spotted suspicious activity targeting @MoonwellDeFi on Base. The firm said the attacker manipulated MAMO collateral pricing and used that inflated value to borrow cbBTC from the mCBTC market. In its initial alert, Blockaid said 50.6 cbBTC, worth more than $4 million, had been drained.

Protos described the exploit as a straightforward price-manipulation attack. The key step was pumping the price of MAMO, a relatively illiquid token that Moonwell accepts as collateral, and then borrowing against it. The attacker reportedly spent $7 million pushing up MAMO’s price and later sold the token after the attack, taking an estimated $3.8 million loss on that leg of the trade.

The borrowed assets included cbBTC, USDC, WETH, and wstETH. While Blockaid’s first estimate put the damage at more than $4 million, the losses continued to rise after the initial alert. Protos reported that the attacker converted the proceeds into the non-freezable stablecoin DAI, and that 8.7 million DAI was sitting in an Ethereum address funded through Tornado Cash.

Moonwell cut caps to one wei after the incident

Moonwell acknowledged the attack after Blockaid’s alert. In its user-facing update, the protocol said all borrow caps, along with MAMO and WELL supply caps, had been reduced to one wei, 「preventing new borrowing and limiting the potential for further impact」.

That response was aimed at stopping any new borrowing while the team assessed the extent of the exploit. No additional remediation details were included in the source text.

Fourth pricing-related problem in less than a year

Protos said the latest loss is Moonwell’s fourth incident in under a year, and all four were tied to pricing issues.

During the October 10 market crash, a price discrepancy triggered $12 million in liquidations and left the protocol with $1.7 million in bad debt. The following month, fallout from the Balancer hack caused problems with the wrsETH/ETH oracle, resulting in another $3.7 million of bad debt.

The most recent case before this week came in February. Protos said a Moonwell contract described as "vibe-coded" valued cbETH at $1.12 rather than 1.12 ETH, even though its actual value was around $2,200 at the time. That mistake caused sudden liquidations in cbETH-backed positions and left the market with $1.8 million in bad debt.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
30

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.