Moonwell has restricted new borrowing on its Base markets after an attacker used manipulated MAMO prices to extract an estimated $8.7 million from the lending protocol. According to the reported findings, the incident did not involve a smart contract bug or direct code breach.
Instead, the attacker appears to have inflated the value of MAMO, a lightly traded token on Base, then used that overstated collateral value to borrow assets with established liquidity, including Coinbase Wrapped Bitcoin and USD Coin. Security firms Blockaid and PeckShield tracked the activity, while Moonwell moved within hours to limit further damage.
How the exploit worked
The reported attack relied on price distortion rather than a flaw in Moonwell’s contracts. Blockaid said the attacker manipulated the pricing of MAMO collateral, allowing borrowing against an artificial valuation from Moonwell’s mCBTC market.
Blockaid’s initial estimate showed 50.6 cbBTC drained, worth more than $4 million at the time of its alert. The source article said Moonwell’s pricing oracle accepted the inflated market signal, enabling the attacker to pledge MAMO at a price far above its normal trading level and withdraw real assets in return.
MAMO is the token tied to Mamo, a yield product built on Base. The article described it as a very small market, with the token trading around $0.011366 and a total value of roughly $7.6 million, making it comparatively inexpensive to move on thin liquidity.
Loss estimates and where funds went
PeckShield later raised the estimated damage to $8.7 million, suggesting the impact extended well beyond the initially observed cbBTC outflow. The stolen value reportedly included both cbBTC and USDC borrowed from Moonwell markets.
According to the source report, the funds were later sitting in DAI at a wallet beginning with 0xD71d. No further recovery outcome was confirmed in the article, and the final size of the loss had not yet been definitively settled.
Moonwell’s emergency response
Moonwell said it was investigating an issue affecting the MAMO Core Market on Base and took precautionary steps to prevent further borrowing. The protocol set borrow caps for all Core Markets on Base to 1 wei, effectively stopping new loans while leaving withdrawals untouched.
The team also reduced supply caps for MAMO and WELL, Moonwell’s governance token, to 1 wei. In practice, that means the protocol sharply constrained additional exposure while it evaluates the incident and the remaining state of market liquidity and debt.
A broader pattern of oracle-related losses
The exploit adds to a series of Moonwell incidents linked to pricing failures rather than broken contract logic. The source article said a wrsETH oracle malfunction created about $3.7 million in bad debt in November 2025, followed by a cbETH oracle misconfiguration that added another $1.78 million in February.
Taken together, those events and the latest exploit have cost the protocol more than $14 million over roughly ten months, according to the article. It also placed the attack in a wider DeFi pattern, noting that analysts are increasingly focused on economic design weaknesses and oracle dependence as major sources of losses.
What remains unresolved
Moonwell said another update was forthcoming. Two issues remain central to assessing the full impact: the final amount of bad debt after MAMO’s price normalizes, and how much cbBTC and USDC remains available for suppliers seeking to withdraw.
Until those figures are confirmed, the total damage and any recovery path remain uncertain. What is clear from the initial response is that Moonwell has chosen to halt new borrowing on Base while it works through the aftermath of the manipulation.
Source: beincrypto.com