Moonwell Suffers $8.7 Million Exploit on Base After MAMO Price Manipulation
Key Takeaways
- •Security researchers say the attack used MAMO price manipulation to inflate collateral value and unlock larger borrowings.
- •The assets reportedly taken from Moonwell included cbBTC, USDC, wstETH, and ETH.
- •Early monitoring showed more than $4 million in cbBTC leaving the protocol, and later estimates put total losses near $8.7 million.
- •Moonwell began investigating the affected MAMO Core Market and took steps to restrict further borrowing.
- •The stolen assets were reportedly consolidated into DAI, and investigators are still tracing the funds and reviewing the pricing mechanism that failed.

Moonwell, a decentralized lending protocol built on Base, the Ethereum layer-2 network developed by Coinbase, was exploited on August 27 in an attack that drained an estimated $8.7 million in assets. Security researchers tied the incident to the manipulation of MAMO, a thinly traded token accepted as collateral in one of Moonwell's lending markets.
The attack underscores a recurring risk in decentralized finance: when collateral values are derived from low-liquidity assets, attackers can manufacture artificial borrowing power. Price-oracle manipulation is a well-documented exploit class; the 2022 Mango Markets incident followed a similar playbook of inflating a thinly traded token's value to borrow more liquid assets against it.
How the Attack Unfolded
According to security researchers, the attacker manipulated MAMO's collateral price and then borrowed more liquid assets from Moonwell using the inflated valuation. The assets taken reportedly included cbBTC (Coinbase Wrapped Bitcoin), USDC, wstETH (a wrapped form of staked Ether), and ETH.
Early blockchain monitoring detected more than $4 million worth of cbBTC leaving the protocol during the attack. Subsequent tracking placed the estimated total loss near $8.7 million.
The incident appears to stem from an oracle or pricing weakness rather than a conventional smart-contract code theft. By driving MAMO's market value higher, the attacker made relatively inexpensive collateral appear substantially more valuable within the lending system. Because a thin market can be pushed to extreme prices with relatively little capital, such a valuation gap can open before risk parameters or market participants can respond.
Moonwell's Response
Moonwell began investigating the affected MAMO Core Market and took precautionary measures to limit additional borrowing. The response highlights the importance of isolating compromised collateral markets before further funds can exit a lending protocol; isolating one affected market, rather than pausing an entire protocol, is a common containment approach for lending platforms.
The incident also raises questions about risk controls for low-liquidity assets. Lending platforms typically calculate borrowing capacity from collateral values and collateral factors. If a price feed can be moved sharply through limited market liquidity, attackers may exploit the inflated valuation before the system can react. Incidents of this type have historically prompted lending protocols to revisit which collateral they list and to tighten caps, collateral factors, and oracle configurations.
The $8.7 million figure could change as blockchain investigators trace additional transactions and determine the final amount extracted. The stolen assets were reportedly consolidated into DAI, MakerDAO's dollar-pegged stablecoin, and security teams continue to monitor the associated addresses. Open questions now include which pricing mechanism failed, how Moonwell will treat the affected MAMO market and its suppliers, and whether on-chain tracing links the funds to any exchange or service able to freeze them.
The Moonwell exploit adds to growing scrutiny of DeFi lending protocols and their reliance on market pricing. For users, the incident illustrates how quickly weaknesses in collateral valuation can translate into losses of otherwise liquid assets. Because borrowed assets in lending protocols come from shared pools, depositors in an affected market are typically the parties most exposed in such drains; in past comparable hacks, some protocols have repaid affected users, as Euler Finance did after its 2023 exploit, making any reimbursement plan from Moonwell a key point to watch.