Moonwell, a decentralized lending protocol operating on Base, suffered an exploit on August 27 that drained an estimated $8.7 million in assets. Security researchers linked the incident to manipulation of MAMO, a relatively illiquid token used as collateral in one of Moonwell’s lending markets.
The attack highlights a recurring DeFi risk: using thinly traded assets to determine collateral values can allow attackers to create artificial borrowing power.
MAMO Price Manipulation Drives Exploit
According to security researchers, the attacker manipulated MAMO’s collateral price and then used the inflated valuation to borrow more liquid assets from Moonwell. Those assets reportedly included cbBTC, USDC, wstETH and ETH.
Early blockchain monitoring identified more than $4 million worth of cbBTC moving from the protocol during the attack. Subsequent tracking placed the estimated overall loss near $8.7 million.
The incident appears to involve an oracle or pricing weakness rather than a conventional smart-contract code theft. By pushing the market value of MAMO higher, the attacker could make relatively inexpensive collateral appear substantially more valuable inside the lending system.
Moonwell Responds to the Incident
Moonwell began investigating the affected MAMO Core Market and took precautionary measures to limit additional borrowing. The response reflects the importance of isolating compromised collateral markets before further funds can leave a lending protocol.
The incident also raises questions about risk controls for low-liquidity assets. Lending platforms generally calculate borrowing capacity from collateral values and collateral factors. If a price feed can be moved sharply through limited market liquidity, attackers may exploit that valuation before the system can react.
The $8.7 million estimate could change as blockchain investigators trace additional transactions and determine the final amount extracted. The stolen assets were reportedly consolidated into DAI, while security teams continued monitoring the associated addresses.
The Moonwell exploit adds to growing scrutiny of DeFi lending protocols and their reliance on market pricing. For users, the incident underscores how quickly weaknesses involving collateral valuation can translate into losses of otherwise liquid assets.