Moonwell loses about $8.7 million on Base after attacker bypasses supply-cap check

Moonwell loses about $8.7 million on Base after attacker bypasses supply-cap check

N
News Editor
2026-08-28 10:36:16
Moonwell lost about $8.7 million on Base on Thursday after an attacker used a route that did not enforce the protocol’s MAMO supply cap, according to onchain records cited by Unchained. Security firms CertiK and Blockaid linked the incident to price manipulation involving MAMO, a thinly traded token accepted by Moonwell as collateral, while PeckShield estimated the loss at $8.7 million. The attacker first used Moonwell’s standard deposit flow to supply 7.1 million MAMO at 09:12:59 UTC, receiving 346 million shares. Minutes later, the same address stopped minting shares and instead sent 34,910,397 MAMO directly to the market contract at 09:19:59 UTC, followed 70 seconds later by another 18,482,894 MAMO. Those transfers each consumed 120,017 gas, emitted only two events, and created no new shares. Because Moonwell uses Compound v2 logic, adding tokens to the pool without increasing shares raised the stored exchange rate from 0.0205 to 0.0755, about 3.7x. That made the attacker’s 346 million shares worth roughly 26 million MAMO on paper, allowing loans against inflated collateral in cbBTC, USDC, and wstETH. Moonwell said it is investigating and has set borrow caps for all Core Markets on Base to 1 wei, freezing new borrowing across those markets.

Moonwell lost about $8.7 million on Base on Thursday. By early Friday, the proceeds were sitting in a single Ethereum address that held about 8.73 million DAI.

CertiK and Blockaid attributed the exploit to price manipulation involving MAMO, a thinly traded token that Moonwell accepted as collateral. PeckShield separately put the loss at $8.7 million.

The route used by the attacker did not enforce the supply cap

Onchain records show the attacker never had to defeat Moonwell’s supply limit. The path they used simply did not check it.

Moonwell limits how much MAMO can be supplied through its normal deposit route, and that check happens when a depositor mints shares. At 09:12:59 UTC, the attacker supplied 7.1 million MAMO through that route and received 346 million shares. They did not continue depositing after that step.

At 09:19:59 UTC, the attacker sent 34,910,397 MAMO directly to the market contract. Seventy seconds later, they sent another 18,482,894 MAMO.

Each transaction burned 120,017 gas and emitted exactly two events: an interest accrual and a token transfer. Neither transaction created any shares.

How the transfers changed the share value

Moonwell runs on Compound v2 code, which values a share as the pool’s holdings divided by shares outstanding. That means adding roughly 53 million tokens to the pool without issuing new shares lifts the value of every existing share at once.

The market’s stored exchange rate was 0.0205 in the block before the first transfer. After both transfers landed, it stood at 0.0755, about 3.7 times higher.

As a result, the 346 million shares that had been acquired with 7.1 million MAMO could now claim roughly 26 million MAMO. Against that inflated collateral, the attacker borrowed cbBTC, USDC, and wstETH.

Moonwell froze new borrowing on Base Core Markets

In a post on X, Moonwell said it was investigating the incident. The protocol added that borrow caps for all Core Markets on Base had been set to 1 wei, blocking new borrowing and limiting the potential for further impact.

New borrowing is now frozen across those markets.

Forum records point to repeated pricing issues

Moonwell’s forum documents pricing trouble going back to October 2025, when a crash left bad debt. Its risk adviser partly attributed that episode to gaps between its price feeds and the market.

Weeks later, an oracle fault left wrsETH drastically overvalued and allowed an attacker to borrow millions. Moonwell said at the time that the same user was responsible for the 10/10/25 exploit.

In February, a cbETH configuration contained a critical error that priced the token near $1.

A June proposal had outlined automated safeguards

On June 8, a contributor proposed automated protections, including a circuit breaker under which the affected market would pause automatically if an oracle price moved beyond a defined threshold relative to a secondary reference or an established historical range.

The forum thread drew three replies and no vote. On June 15, the author agreed to implement an earlier phase first.

Whether that design would have caught this attack remains unclear. The proposal was never specified in enough detail to settle that question.

TVL dropped from about $73 million to about $45 million

By early Friday, Moonwell’s total value locked had fallen from about $73 million before the attack to about $45 million, while borrowing increased.

The amount taken is several times larger than the roughly $1.9 million in protocol revenue that DefiLlama records for the past year.

Aave said in May that it would add security reviews to its listing process after April’s $293 million KelpDAO exploit.

At least one depositor from February is still waiting. On August 23, four days before this attack, that user wrote on the forum that they had simply supplied cbETH and were still unable to withdraw it.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.