Moonwell Suffers Estimated $9M Oracle Manipulation Attack on Base
Key Takeaways
- •An attacker inflated the thinly traded MAMO token from roughly $0.01 to nearly $0.47 through low-liquidity markets, artificially raising the collateral value recognized by Moonwell on Base.
- •Early estimates place total extraction near $9 million, including at least 50.6 cbBTC worth more than $4 million removed from the cbBTC market.
- •The attack required no stolen private keys or breach of Base consensus; losses came from shared lending pools funded by other Moonwell users' deposits.
- •Moonwell previously experienced a cbETH oracle misconfiguration earlier this year that produced incorrect valuations and forced liquidations on Base.
- •The exploit adds to a string of 2026 oracle attacks, including Bonzo Lend's roughly $9.05 million loss in July and a $915,000 exploit at 42DAO.

Moonwell was hit by an estimated $9 million oracle manipulation attack on Base, after exploiters inflated the price of the thinly traded MAMO collateral token and used the artificial valuation to borrow higher-value assets from the lending protocol, according to blockchain security analysis shared by Blockaid.
The attack pushed MAMO from roughly $0.01 to nearly $0.47 through low-liquidity markets before the elevated price fed into Moonwell's collateral calculations. Early transactions extracted cbBTC, USDC, wstETH and ETH-backed assets from the protocol's shared lending pools.
At least 50.6 cbBTC, worth more than $4 million, was removed from the cbBTC market during the attack. Additional borrowing across the affected markets pushed early estimates of the total extraction toward $9 million as investigators continued tracing the Base transactions.
For Base users and other lenders, the incident is a reminder that oracle inputs can matter as much as smart contract code: when a thin market is accepted as collateral, a sudden price move can change borrowing power before the protocol can react. In practice, that risk lands on shared liquidity pools, which is why the borrowed assets came from deposits supplied by other Moonwell users rather than from compromised wallets.
MAMO Price Spike Inflated Borrowing Power
Moonwell allows MAMO to be used as collateral on Base with a 50% collateral factor, a 20 million MAMO supply cap and a 3 million MAMO borrow cap, according to the protocol's published risk parameters.
That configuration meant a sharp increase in MAMO's oracle price immediately raised the dollar value assigned to the attacker's collateral. Once MAMO was valued near $0.47 rather than roughly $0.01, the same token position could support vastly larger loans.
The borrowed assets came from liquidity supplied by other Moonwell users. The attacker did not need to compromise private keys or break Base consensus; the extraction depended on manipulating the price used to value collateral and borrowing against that distorted valuation before the market could correct.
MAMO was already one of Moonwell's more heavily utilized Base markets. During the week ending August 20, MAMO borrowing averaged 84.86% of its 3 million-token cap, forum data showed.
Moonwell Has Faced Oracle Problems Before
Moonwell dealt with a separate pricing failure earlier this year, when a cbETH oracle configuration produced incorrect valuations and forced liquidations on Base. The protocol later restored its previous cbETH pricing model while discussing compensation for affected borrowers.
Oracle manipulation has also hit other lending markets in 2026. Bonzo Lend lost about $9.05 million in July after a manipulated SAUCE price allowed an attacker to borrow millions of dollars in USDC and wrapped HBAR against collateral worth only a few dollars.
A separate $915,000 oracle exploit at 42DAO used an abnormal BTCB price to trigger liquidations after the protocol accepted the value without sufficient deviation controls.
Base Lending Pools Absorb the Extraction
Moonwell is one of the largest lending applications on Base, with individual markets for USDC, WETH, cbBTC, wstETH and other collateral and borrowing assets. The attack affected liquidity available through those shared markets rather than user wallets directly.
The cbBTC leg alone removed more than $4 million of Bitcoin-backed liquidity, while the remaining transactions targeted USDC and Ethereum-linked assets as the manipulated MAMO valuation remained active.
The incident came four days after KiiChain halted its network following a separate EVM-module exploit, adding another major loss to a concentrated stretch of August protocol attacks.
Moonwell's published Base configuration lists the MAMO collateral factor at 50%, with the market capped at 20 million MAMO supplied and 3 million MAMO borrowed.
This article was first published by Crypto Adventure.