Moonwell lost about $8.7 million on Base on Thursday. By early Friday, the proceeds were sitting in a single Ethereum address that held about 8.73 million DAI.
CertiK and Blockaid attributed the exploit to price manipulation involving MAMO, a thinly traded token that Moonwell accepted as collateral. PeckShield separately put the loss at $8.7 million.
The route used by the attacker did not enforce the supply cap
Onchain records show the attacker never had to defeat Moonwell’s supply limit. The path they used simply did not check it.
Moonwell limits how much MAMO can be supplied through its normal deposit route, and that check happens when a depositor mints shares. At 09:12:59 UTC, the attacker supplied 7.1 million MAMO through that route and received 346 million shares. They did not continue depositing after that step.
At 09:19:59 UTC, the attacker sent 34,910,397 MAMO directly to the market contract. Seventy seconds later, they sent another 18,482,894 MAMO.
Each transaction burned 120,017 gas and emitted exactly two events: an interest accrual and a token transfer. Neither transaction created any shares.
How the transfers changed the share value
Moonwell runs on Compound v2 code, which values a share as the pool’s holdings divided by shares outstanding. That means adding roughly 53 million tokens to the pool without issuing new shares lifts the value of every existing share at once.
The market’s stored exchange rate was 0.0205 in the block before the first transfer. After both transfers landed, it stood at 0.0755, about 3.7 times higher.
As a result, the 346 million shares that had been acquired with 7.1 million MAMO could now claim roughly 26 million MAMO. Against that inflated collateral, the attacker borrowed cbBTC, USDC, and wstETH.
Moonwell froze new borrowing on Base Core Markets
In a post on X, Moonwell said it was investigating the incident. The protocol added that borrow caps for all Core Markets on Base had been set to 1 wei, blocking new borrowing and limiting the potential for further impact.
New borrowing is now frozen across those markets.
Forum records point to repeated pricing issues
Moonwell’s forum documents pricing trouble going back to October 2025, when a crash left bad debt. Its risk adviser partly attributed that episode to gaps between its price feeds and the market.
Weeks later, an oracle fault left wrsETH drastically overvalued and allowed an attacker to borrow millions. Moonwell said at the time that the same user was responsible for the 10/10/25 exploit.
In February, a cbETH configuration contained a critical error that priced the token near $1.
A June proposal had outlined automated safeguards
On June 8, a contributor proposed automated protections, including a circuit breaker under which the affected market would pause automatically if an oracle price moved beyond a defined threshold relative to a secondary reference or an established historical range.
The forum thread drew three replies and no vote. On June 15, the author agreed to implement an earlier phase first.
Whether that design would have caught this attack remains unclear. The proposal was never specified in enough detail to settle that question.
TVL dropped from about $73 million to about $45 million
By early Friday, Moonwell’s total value locked had fallen from about $73 million before the attack to about $45 million, while borrowing increased.
The amount taken is several times larger than the roughly $1.9 million in protocol revenue that DefiLlama records for the past year.
Aave said in May that it would add security reviews to its listing process after April’s $293 million KelpDAO exploit.
At least one depositor from February is still waiting. On August 23, four days before this attack, that user wrote on the forum that they had simply supplied cbETH and were still unable to withdraw it.

