A governance attack on Moonwell unfolded rapidly on March 26. The attacker acquired 40 million MFAM tokens at a minimal cost, then completed the entire sequence — token purchase, proposal creation, and quorum reaching — within just 11 minutes, threatening to take over the protocol's critical smart contracts.
How Cheap Tokens Posed a Protocol Takeover
MFAM serves as Moonwell's core governance token, determining control over key decisions. The attacker exploited this mechanism, buying a large stake cheaply and quickly submitting a proposal to transfer control of the oracle, comptroller, and seven lending market smart contracts to an attacker-controlled wallet. These contracts oversee fund movement and core operations; if seized, protocol assets would be directly at risk.
The entire operation took just 11 minutes: acquiring tokens, crafting the proposal, and hitting the quorum needed to activate the vote. Moonwell briefly teetered on the edge of malicious takeover.
Community Rallies to Vote No — Outcome Uncertain
Voting on the controversial proposal remains open until March 27, 2026. In the hours after the attack, community members voted heavily against the measure, buying time and slowing the compromise. A Moonwell spokesperson said in an official statement: The recent governance proposal has prompted immediate community action and ongoing monitoring, reflecting both the strengths and weaknesses of on-chain decision-making.
The vote's outcome is still unclear. Community vigilance remains crucial. Moonwell's reliance on decentralized voting means vulnerabilities aren't limited to smart contract code — governance itself can be manipulated through coordinated or opportunistic token purchases.
Not the First Security Incident
Moonwell has faced security issues before. In November 2025, an oracle pricing error valued a small token deposit at over $116,000, allowing a trading bot to drain funds from liquidity pools on Base Network and Optimism. The DAO responded with contract upgrades, new safety measures, and governance fixes.
Despite earlier improvements and active community engagement, this latest incident highlights persistent risks in DeFi governance models. Unlike code-based exploits targeting technical flaws, governance attacks exploit proposal and voting mechanisms — a pressing challenge for many decentralized protocols.

