Moonwell Exploit Drains $8.7M via MAMO Collateral Price Manipulation

iconCoincryptonewz
Share
AI summary iconSummary
Moonwell suffered a $8.7M exploit on August 27 via manipulated MAMO collateral pricing, per Coincryptonewz. PeckShield reported the attacker borrowed cbBTC, USDC, wstETH, and ETH. Moonwell limited new borrowing to 1 wei. Earlier oracle issues with wrsETH and cbETH caused $5.48M in bad debt. Traders are advised to monitor altcoins to watch amid ETH price volatility.
  • PeckShield estimates $8.7 million in losses after an attacker manipulated MAMO collateral pricing.
  • Moonwell cut borrowing caps across Base Core Markets to 1 wei, effectively stopping new loans.
  • Earlier wrsETH and cbETH pricing failures caused $3.7 million and $1.78 million in bad debt.

The Moonwell exploit drained an estimated $8.7 million from lending markets on Base on August 27, according to PeckShield. Security researchers linked the attack to inflated MAMO collateral prices.

Moonwell responded by restricting new borrowing across its Base Core Markets. The attacker reportedly borrowed cbBTC, USDC, wstETH, and ETH against the overvalued token, then consolidated proceeds on Ethereum.

Moonwell Exploit Uses Inflated MAMO Collateral on Base

Blockaid’s initial assessment of the Moonwell exploit identified 50.6 cbBTC moved from the protocol, worth more than $4 million. That early estimate did not cover every affected lending market.

MAMO trades in relatively thin markets, where concentrated buying can sharply move prices. Researchers said the attacker inflated its quoted value before using the tokens as collateral.

Oracles provide the external price data that lending protocols use to value collateral. Moonwell’s oracle accepted the higher price, increasing the amount the account could borrow. The collateral’s apparent valuation exceeded the liquidity available to support it.

Initial reports describe price manipulation, rather than an identified breach of the core smart contracts. PeckShield traced the proceeds to DAI at an Ethereum address beginning 0xD71d.

Borrowing Restrictions Follow Earlier Oracle Failures

After the Moonwell exploit, the team set borrowing caps across Base Core Markets to 1 wei. This effectively stopped new loans while investigators assessed the affected MAMO market.

Supply caps for MAMO and the WELL governance token also fell to 1 wei. Moonwell said other supply caps were unchanged and promised further updates.

The reported $8.7 million is a preliminary loss estimate, not a final accounting of unrecoverable debt. Any recovery and remaining collateral value will affect the protocol’s ultimate shortfall.

The Moonwell exploit follows two documented pricing incidents. A November 2025 wrsETH oracle malfunction produced about $3.7 million in bad debt. A cbETH pricing misconfiguration added $1.78 million in February 2026.

Separately, Term Finance vaults lost an estimated $8.5 million in a governance attack on August 23. Term Labs subsequently closed Meta Vaults to new deposits and revoked their DAO governance roles. At press time, Mamo is down 11.01% to $0.00929 in 24h.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.