Moonwell loses up to $9M on Base after attacker inflates MAMO collateral
0
0

An attacker manipulated the price of MAMO on Moonwell’s Base lending market on Wednesday and used the inflated collateral to borrow real assets that it never repaid.
The losses are estimated to be in the range of about $4 million to $9 million. The attack drained cbBTC, USDC, wstETH and ETH out of real depositor liquidity.
Who attacked Moonwell?
Moonwell, a decentralized lending protocol, has suffered its third security incident in nine months.
An attacker manipulated the price of the illiquid MAMO token on Moonwell’s Base lending market, driving its value up about eightfold from around $0.0105 to nearly $0.088 and allowing them to borrow real crypto assets like cbBTC, USDC, wstETH, and ETH against inflated collateral that was never repaid.
The security firm ExVul says the attacker spent about $7 million buying MAMO to force the price up, then sold roughly $3.2 million of it back, taking a loss of close to $3.8 million on the token trades alone.
The loss was a calculated cost that let the attacker borrow around $10 million in real assets from Moonwell, leaving a net haul of roughly $6 million.
The Blockaid security firm first flagged suspicious activity against the mCBTC market, reporting an initial drain of 50.6 cbBTC, worth over $4 million. The attacker’s wallet then moved most of the stolen funds, holding just over $4,600 hours later.
Because the exploit was still unfolding, loss estimates shifted in real time. Blockaid’s early estimate was just over $4 million, the lowest figure, while ExVul put the loss at roughly 71.36 cbBTC, worth about $5.7 million. CertiK said the attacker’s address had collected close to $8.7 million, while others reported that $9 million had already been drained.
Meanwhile, Moonwell’s native governance token, WELL, initially spiked about 25% but later corrected downward by roughly 13% to around $0.0032. The company has about $72.77 million in total value locked according to DeFiLlama, making the attack a significant blow to both the protocol and depositors.
Moonwell’s team acted quickly after the attack, cutting the MAMO market’s borrowing limit to the smallest possible amount (1 wei), which basically stops anyone from borrowing more against that token. They also lowered the supply limits for both MAMO and WELL. The attack is currently under investigation.
Is this Moonwell’s first security problem?
Prior to this incident, Moonwell had suffered two oracle-related failures. The first occurred in November 2025, when a spot-price manipulation classified as oracle manipulation occurred.
On February 15, 2026, a separate $1.78 million bad-debt event occurred due to a misconfigured cbETH oracle that reported the asset at about $1.12 instead of roughly $2,200.
The second incident drew more attention because the relevant code changes listed Anthropic’s Claude Opus 4.6 as a commit co-author and that sparked a debate over AI-assisted “vibe coding” in DeFi.
If you're reading this, you’re already ahead. Stay there with our newsletter.
0
0
Securely connect the portfolio you’re using to start.






