Moonwell just got rekt for $8.7M on Base.

Attacker manipulated $MAMO price (illiquid collateral) → artificially pumped borrowing power → drained $cbBTC, $USDC, ETH.

This wasn't a contract exploit. Classic oracle manipulation + thin liquidity play.

Moonwell paused borrowing/supply on Base markets.

The alpha: Low-liq collateral + weak oracles = exit liquidity for attackers. If your DeFi protocol accepts random tokens as collateral without deep liquidity or robust price feeds, you're ngmi.

Oracle security isn't optional. Collateral caps aren't optional. Liquidity depth isn't optional.