Moonwell DeFi, a lending protocol operating on the Base network, suffered an exploit on August 27, 2026, resulting in losses estimated between $8.7 million.
Blockchain security firm CertiK reported that an attacker manipulated the price of the relatively illiquid MAMO token, which served as collateral in the protocol’s markets. The inflated valuation reportedly allowed the attacker to borrow substantial amounts of more liquid assets, including cbBTC, USDC, wstETH, and ETH.
Stolen funds were later consolidated on Ethereum at address 0xD71d…C384, where they were converted into DAI.
The attack vector shows that this incident did not involve a direct breach of Moonwell’s smart contracts. Instead, it exploited thin liquidity in the MAMO market and the protocol’s reliance on price oracles that could be influenced by trading activity.
Price Manipulation Enabled Large Unbacked Loans
The attacker first acquired large quantities of MAMO tokens and executed trades that pushed its price sharply higher—from around $0.01 to levels reported as high as $0.43 at 09:35 AM UTC—as shown on CoinGecko.

With the token’s apparent value inflated, the holdings were deposited as collateral on Moonwell. This created borrowing power far exceeding the token’s true market depth.
Onchain transaction data from Basescan showed withdrawals including more than 50 cbBTC in early reports, later revised higher, alongside millions in stablecoins and wrapped Ethereum assets. Additional mechanics, such as direct token transfers into the market contract, further increased the exchange rate of existing mTokens and amplified the position.
Independent analysts further reported that the attack concluded when remaining liquidity in certain markets, such as AERO, became insufficient. Liquidators later recovered a portion of the position, but substantial bad debt remained.
Protocol Response and Unexpected Token Rally
Moonwell acknowledged the issue affecting the MAMO Core Market and took immediate precautionary steps. Borrow caps across all Core Markets on Base were reduced to 1 wei, effectively pausing new borrowing. Supply caps for MAMO and the protocol’s native WELL token were similarly restricted.
The team stated it was investigating and would provide further updates. “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged,” the team said.
Despite the unfolding losses, WELL briefly surged approximately 25% in the hour surrounding the exploit, a reaction observers attributed to heightened attention rather than protocol strength.
The episode adds to Moonwell’s recent history of oracle-related incidents, including issues in late 2025 and early 2026.
This is a developing story and more information will be added as the event unfolds.
Also read: Nigerian Court Grants $371K Bail in Alleged Crypto Investment Fraud
