Moonwell Lending Protocol Hit by Multimillion-Dollar Exploit

8/28/2026
4min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert at Airdrops.com
8/28/2026
4min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert

Decentralized lending protocol Moonwell suffered an exploit on its Base market on Wednesday, with security researchers estimating losses between approximately $4 million and $9 million.

The attacker allegedly manipulated the price of the relatively illiquid MAMO token, pushing it from roughly $0.0105 to nearly $0.088. The sharp increase allowed the attacker to deposit MAMO as artificially inflated collateral and borrow valuable assets that were never repaid.

The drained liquidity reportedly included cbBTC, USDC, wstETH and ETH belonging to depositors. The incident marks Moonwell's third significant security-related problem in roughly nine months.

Attacker Spends Millions Manipulating MAMO

According to blockchain security firm ExVul, the attacker reportedly spent around $7 million purchasing MAMO, driving its market price approximately eight times higher.

The attacker then sold around $3.2 million worth of MAMO back into the market, reportedly accepting approximately $3.8 million in trading losses. However, researchers believe those losses were part of the strategy rather than an unsuccessful trade.

With MAMO's price temporarily inflated, the attacker could use the tokens as highly valued collateral on Moonwell and allegedly borrow around $10 million worth of more liquid crypto assets.

After accounting for the cost of manipulating MAMO, ExVul estimated that the operation could have produced a net profit of approximately $6 million.

Security Firms Report Different Loss Estimates

Blockchain security company Blockaid was among the first to identify suspicious activity involving Moonwell's mCBTC market, initially reporting that approximately 50.6 cbBTC worth more than $4 million had been drained.

Because the incident was still developing, estimates differed significantly between security researchers.

ExVul later estimated losses at approximately 71.36 cbBTC, valued around $5.7 million, while CertiK reported that the suspected attacker's address had accumulated close to $8.7 million. Other estimates placed the total amount drained at roughly $9 million.

The attacker's wallet subsequently moved most of the funds, according to blockchain monitoring reports. The wide range of estimates means the final financial impact remains under investigation.

Moonwell Restricts MAMO Borrowing

Moonwell responded by dramatically reducing the MAMO market's borrowing limit to one wei, effectively preventing additional meaningful borrowing against the token.

The protocol also lowered supply limits for MAMO and its native WELL governance token while investigating the incident.

Moonwell had approximately $72.77 million in total value locked, according to DeFiLlama data cited in reports, making a potential multimillion-dollar loss significant relative to the protocol's overall liquidity.

Meanwhile, WELL experienced unusual volatility around the incident. The token reportedly jumped approximately 25% before reversing course, later falling around 13% to roughly $0.0032.

The investigation is ongoing as Moonwell and blockchain security researchers work to determine the exact amount lost and how the manipulated collateral was able to support such substantial borrowing.

Third Security Incident in Nine Months

The latest exploit follows two previous oracle-related incidents affecting Moonwell, increasing scrutiny around the protocol's risk controls and price-feed infrastructure.

The first occurred in November 2025 and involved a spot-price manipulation incident classified as oracle manipulation.

Another incident followed on February 15, 2026, when a misconfigured cbETH oracle reportedly caused approximately $1.78 million in bad debt. The oracle incorrectly valued cbETH at roughly $1.12 when its actual market value was around $2,200.

That incident attracted additional attention because related code changes reportedly listed Anthropic's Claude Opus 4.6 as a commit co-author, triggering broader discussion about the risks of AI-assisted development, sometimes described as “vibe coding,” in decentralized finance.

The latest MAMO incident again highlights the importance of reliable oracle design and liquidity-aware collateral parameters in lending markets. Thinly traded tokens can be particularly vulnerable because relatively concentrated buying may substantially move their market price.

For Moonwell, the immediate priority will be determining the final losses and preventing further borrowing against manipulated collateral. With three security-related incidents within nine months, the latest exploit could also intensify questions about the protocol's broader risk-management framework.

Share with your friends on social media:

Join the community and don't miss a crypto giveaway.

Subscribe for updates by e-mail with the latest research reviews, airdrop news, reward programs, event updates about upcoming airdrops.

By entering your email address you are accepting our Terms & Conditions and Privacy & Cookie Policy.