Moonwell halts borrowing on Base after $8.7M MAMO price-manipulation attack Moonwell has frozen new borrowing across its Core Markets on Base after what security firms describe as a collateral-price manipulation attack on the MAMO market drained roughly $8.7 million from the protocol. What happened - On Aug. 27 Moonwell announced it was investigating “an issue affecting the MAMO Core Market” and, as a precaution, lowered borrow caps for all Core Markets on Base to 1 wei — effectively preventing anyone from opening new loans. Supply caps for MAMO and Moonwell’s native WELL token were also reduced to 1 wei; supply limits for other assets were left unchanged. - Blockchain security firms PeckShield and CertiK estimated losses at about $8.7 million. Blockaid traced the activity to manipulation of MAMO’s collateral price and initially reported 50.6 cbBTC (more than $4 million) drained from Moonwell’s mCBTC market. - According to CertiK and Blockaid, the attacker artificially inflated the market price of MAMO — a thinly traded token — then used the overvalued MAMO collateral to borrow liquid, higher-value assets (cbBTC). PeckShield later said the attacker consolidated proceeds into DAI at a single address. Why the attack worked Security firms point to MAMO’s low liquidity and prior volatility as the attack vector: by pushing up MAMO’s market price, the attacker increased the protocol’s valuation of that collateral, enabling outsized borrow capacity against deeper-liquidity assets. MAMO has shown sharp swings before — after its Coinbase listing in August 2025 the token hit an all-time high of $0.227 before falling nearly 20% amid selling pressure. Market impact and response - Token prices reacted: CoinGecko and DEX Screener data cited in early reports showed Moonwell’s WELL down about 13% and MAMO roughly 9% over the most recent 24 hours. - Moonwell’s restrictions apply to borrowing across all Base Core Markets, not just the MAMO market, while the team continues its investigation. The protocol said further updates will follow when more information is available. Context: a year of security headaches This is the latest in a string of Moonwell incidents in 2026. In February an oracle mispricing left cbETH valued at roughly $1.12 while the market price was near $2,200, producing about $1.78 million in bad debt; Moonwell said an incorrect scaling factor in an oracle calculation — code that reportedly included output from Anthropic’s Claude Opus 4.6 model — was the cause. In March an attacker used a small MFAM token purchase (~$1,800) to push a malicious governance proposal that could have seized control of several markets; Moonwell’s Break Glass Guardian multisig stopped the attack before execution. Broader DeFi backdrop The Moonwell incident arrives after a damaging second quarter for DeFi. April 2026 alone saw a string of large exploits — CertiK warned of growing AI misuse and infrastructure weaknesses — and by mid-April protocols had reportedly lost more than $606 million across over a dozen incidents. Notable April cases included Kelp DAO, which lost roughly $292 million in rsETH, an event that LayerZero later tied to compromised RPC infrastructure and flagged connections to groups historically linked to North Korea. What’s next Security firms characterize the Aug. 27 incident as active market manipulation rather than a simple oracle bug, but Moonwell has not yet published a detailed post-mortem identifying the specific contracts, oracle flows, or transaction sequence used in the exploit. The protocol has not confirmed whether the $8.7 million estimate is final or whether any funds can be recovered. Moonwell’s investigation remains active and the team said it will release more information as it becomes available. Read more AI-generated news on: undefined/news
