
Lending protocol Moonwell lost an estimated $8.7 million to an exploit on Thursday, marking the latest in a series of pricing-related incidents affecting the protocol. According to reports from security firm Blockaid, no smart contract was broken during the attack - instead, an attacker manipulated MAMO collateral pricing to drain assets. The exploit involved pumping MAMO, a small Base token, to artificially inflate its perceived value, allowing the attacker to borrow real assets including Coinbase Wrapped Bitcoin (cbBTC) and USD Coin (USDC). The stolen funds were consolidated at an address linked to the attacker, as reported by multiple sources. Moonwell has now implemented immediate security measures, with the team setting borrow caps for all Core Markets on Base to 1 wei - the smallest possible unit - preventing new borrowing and limiting potential further impact.
The exploit relied entirely on price manipulation rather than code vulnerabilities, with security firm CertiK confirming the attacker manipulated the relatively illiquid MAMO token's collateral price before borrowing real cbBTC from Moonwell's mCBTC market. According to Blockaid's report, MAMO is the token of Mamo, a yield tool built on Base, with every MAMO worth approximately $7.6 million combined and trading near $0.011366. The attacker pumped MAMO on the thin market, posted it as collateral at the inflated price, and borrowed assets with real value. Moonwell's oracle, which feeds prices to the protocol, accepted the manipulated pricing data as legitimate. Supply caps for MAMO and WELL, Moonwell's governance token, also fell to one wei, while supply limits for other assets remained unchanged during the investigation.
Security firm PeckShield later confirmed the total losses at $8.7 million, exceeding the market value of every MAMO token in existence. As reported by Blockaid, the attacker's first estimate showed 50.6 cbBTC gone, worth more than $4 million. The attacker consolidated the stolen funds into DAI at a single address, as reported by PeckShield. Moonwell responded by implementing immediate security measures, with the team setting borrow caps for all Core Markets on Base to 1 wei - the smallest possible unit - preventing new borrowing and limiting potential further impact. The incident highlights risks in DeFi protocols relying on illiquid collateral and may impact Moonwell's user trust and token value. The protocol has not yet disclosed whether the $8.7 million estimate represents its final loss or whether any affected assets can be recovered.
This incident represents the latest in a series of pricing failures affecting Moonwell. Previous incidents included a wrsETH oracle malfunction that created around $3.7 million in bad debt in November 2025, and a cbETH oracle misconfiguration that added $1.78 million more in February. According to PeckShield, pricing failures have now cost the protocol over $14 million in ten months. The wider DeFi sector shows similar vulnerabilities, with Term Labs losing roughly $8.5 million to a governance exploit on Sunday, as analysts increasingly blame economic design failures rather than broken code for DeFi's biggest losses. The sector experienced elevated exploits during April 2026, with crypto protocols losing more than $606 million across at least 12 incidents, including the $292 million Kelp DAO exploit.
Price pressure returned following Thursday's security incident, with Moonwell's WELL token down about 13% over the preceding 24 hours according to CoinGecko data, while MAMO had fallen roughly 9% over the same period according to DEX Screener. The restrictions imposed by Moonwell cover borrowing across its Base Core Markets, not only the MAMO market where the issue was identified. The protocol indicated that another update is coming, with two key metrics to monitor: the final bad debt once MAMO's price settles, and how much cbBTC and USDC remains for suppliers seeking to withdraw their funds. The funds are currently held in the DAI stablecoin at a wallet beginning with 0xD71d. Moonwell has not yet published a detailed post-mortem identifying the exact contracts, oracle structure or transaction sequence involved, with the investigation remaining active and further information to be released when available.