Moonwell halts borrowing after $8.7M drain on Base; attacker exploited illiquid MAMO collateral Moonwell has paused new borrowing across its Core Markets on Base after an apparent price-manipulation attack on the MAMO market drained roughly $8.7 million from the protocol’s lending pools. In an Aug. 27 post on X, Moonwell said it was investigating the incident and immediately lowered borrow caps across all Base Core Markets to 1 wei — effectively blocking new borrows while the probe continues. “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact,” the team wrote. Supply caps for MAMO and WELL were also reduced to 1 wei; supply limits for other assets remain unchanged. Moonwell said it will share more details as its investigation progresses. How the exploit unfolded Security firms PeckShield, CertiK and Blockaid traced the exploit to manipulation of MAMO’s collateral price. According to CertiK and Blockaid, the attacker pushed up MAMO’s market price — an especially risky vector because MAMO is relatively illiquid — then used the inflated collateral value to borrow real cbBTC from Moonwell’s mCBTC market. Blockaid’s early monitoring showed about 50.6 cbBTC (just over $4 million at the time) moved out of the protocol; PeckShield and CertiK later estimated total losses at approximately $8.7 million. PeckShield reported the attacker consolidated proceeds into DAI at a single address. Why an illiquid token mattered All security teams emphasized the same structural weakness: using a thinly traded token like MAMO as collateral allows an attacker to distort its market price, artificially inflating borrowing power and draining deeper-liquidity assets. Unlike some prior Moonwell incidents that involved oracle failures, this event has been described as active market-price manipulation rather than a simple mispricing bug. Moonwell has not yet published a full post-mortem identifying the specific contracts, oracles or transaction chain involved. Market fallout Price pressure arrived quickly after the exploit. CoinGecko data cited in Moonwell’s initial disclosure showed the protocol’s WELL token fell about 13% over 24 hours, while DEX Screener reported MAMO down roughly 9% over the same period. MAMO’s history of sharp swings — including a volatile run around its Coinbase debut in August 2025 — left it vulnerable to this kind of attack. Context: repeated security scares and a risky DeFi landscape Thursday’s incident is the latest in a string of security problems for Moonwell in 2026. In February, an oracle calculation error mispriced Coinbase Wrapped ETH (cbETH) at about $1.12 while the market price was near $2,200, leaving Moonwell with roughly $1.78 million in bad debt. Moonwell said the faulty oracle logic included code generated by Anthropic’s Claude Opus 4.6 model and that an incorrect scaling factor produced the gross mispricing. In March, an unknown actor purchased ~$1,800 worth of MFAM tokens and used them to pass a malicious governance proposal on Moonwell’s Moonriver deployment, briefly threatening control of multiple lending markets and about $1.08 million in assets before emergency multisig and subsequent votes halted execution. The broader DeFi environment has also been turbulent. Security firm CertiK warned in April that AI misuse and infrastructure weaknesses — from social engineering to automated, AI-assisted attack techniques — were elevating crypto security risks. April alone saw more than $606 million lost across at least a dozen incidents, according to DefiLlama data cited by crypto.news, with Kelp DAO’s April exploit (roughly $292 million in drained rsETH) among the largest. Binance Research later tied these exploits to big TVL outflows in April and May 2026. What’s next Moonwell has not confirmed whether the $8.7 million figure is the final loss nor whether any funds can be recovered. The protocol’s investigation remains active, and it has pledged to release additional updates as more information becomes available. Security firms continue tracking on-chain movements tied to the incident. Read more AI-generated news on: undefined/news