VERSE PRESS

Crypto News, Global First.

Moonwell Loses $8.7M on Base After Attacker Pumps Obscure Token to Borrow Real Assets

A price manipulation attack on Moonwell's Base lending market drained approximately $8.7 million on August 27, exploiting a thinly traded token rather than any flaw in the protocol's code.

|

The attacker targeted Moonwell's MAMO Core Market on Base, Coinbase's Ethereum Layer 2 network, by artificially inflating the price of the low-liquidity MAMO token and depositing it as overvalued collateral. From there, the attacker borrowed real liquid assets, including cbBTC (Coinbase Wrapped Bitcoin), USDC, wstETH (Wrapped Staked Ether), and ETH, before converting the proceeds to DAI stablecoin and consolidating them at a single Ethereum wallet: 0xD71dD9B6e634412713c47fe7aE02c628e338C384. Security firms CertiK, PeckShield, and Blockaid all independently confirmed the exploit. Blockaid's initial estimate flagged roughly $4 million in cbBTC losses, including approximately 50.6 cbBTC, before the final confirmed total across all stolen assets reached $8.7 million, illustrating how rapidly the picture shifted during the incident.


How the Attack Worked

Oracle manipulation attacks follow a consistent playbook. An attacker acquires a large position in a low-liquidity token, forces its price upward on decentralized exchanges, and then deposits that token into a lending protocol as collateral. Because the protocol's price feed (its "oracle") reflects the inflated market rate, the attacker can borrow far more in real assets than their collateral is actually worth. No code is broken. The economic logic is simply tricked.

MAMO had a total market cap of roughly $7.6 million before the incident, making it an easy target. Its pre-attack price sat around $0.0105. CoinGecko recorded a peak of $0.43 at 09:35 AM UTC on August 27, a roughly 40x spike in a short window. CertiK's own estimate cited an approximately 8x move, a variance that reflects the chaotic, fast-moving DEX pricing characteristic of these attacks. CertiK, which flagged the attack independently, described the mechanics plainly: "Attacker manipulated relatively illiquid MAMO's collateral price, then borrowed real cbBTC."

Moonwell moved quickly once the attack was identified. The protocol set borrow caps for all Core Markets on Base to 1 wei, the smallest unit of ether, effectively halting all new borrowing. Supply caps for MAMO and WELL were also reduced to 1 wei. Moonwell confirmed it preserved the ability for existing users to withdraw funds and stated it was "actively investigating" the incident.


A Pattern, Not an Isolated Failure

This is the third significant oracle-related incident involving Moonwell in roughly ten months. In November 2025, a Chainlink price feed malfunction caused Moonwell to dramatically overvalue wrsETH, a wrapped restaked ether token from Kelp DAO, resulting in approximately $1 million extracted from the protocol and roughly $3.7 million in bad debt.

In February 2026, a governance upgrade misconfigured Moonwell's cbETH oracle, pricing the asset at around $1.12 instead of its actual value near $2,200. That error triggered the liquidation of over 1,000 cbETH in under four minutes, leaving $1.78 million in bad debt.

That February incident also drew attention because the associated code pull request listed Claude Opus 4.6 as a co-author, reigniting an ongoing industry debate about "vibe coding" and the risks of AI-assisted work in high-stakes DeFi environments.

Moonwell holds around $74.39 million in total value locked across five blockchains, a figure measured at the time of the attack, with Base accounting for 94.6 percent of that activity. The protocol has processed more than $2.8 billion in cumulative transaction volume since its 2021 launch.


Broader Context: A Damaging August for DeFi

Moonwell's loss fits a wider pattern in August 2026. Just four days earlier, Term Finance lost $8.5 million after an attacker acquired a governance token majority and used it to drain protocol vaults.

BounceBit lost $3 million to a blockchain stack flaw around the same period. The damage extended beyond the immediate loss: Evmos, the underlying chain powering BounceBit, was permanently retired in the aftermath.

According to TRM Labs, the first half of 2026 saw roughly $972 million stolen across 207 incidents, with approximately 44 percent of those losses tied to operational or infrastructure failures rather than smart contract code bugs. PeckShield puts cumulative 2026 crypto theft at $1.65 billion year to date.

OWASP's 2026 Smart Contract Top 10 ranks price oracle manipulation third among the most critical vulnerability classes in DeFi, noting that "The contract implicitly trusts that the price it receives reflects real-world or on-chain market conditions."


Why This Matters Beyond the US

Base's lower transaction fees have made it a meaningful entry point for retail crypto users in cost-sensitive markets. India, currently ranked first in overall crypto adoption by the 2026 Global Crypto Adoption Index, and Nigeria, ranked second, are both countries with large, active crypto user bases increasingly engaging with Ethereum L2 networks.

Stablecoin adoption across Sub-Saharan Africa grew 180 percent year over year.

The FSCA, South Africa's financial regulator, found that 48 percent of domestic DeFi participants engage with lending and borrowing protocols, and explicitly named price manipulation as a primary risk in its recent market study. That finding carries added weight given South Africa's regulatory trajectory: the country was removed from the FATF grey list in 2025, and its regulators are now working to build on that progress through tighter oversight frameworks.

For regulators in FATF-compliant jurisdictions working to tighten DeFi oversight, attacks that end with rapid conversion to stablecoins and consolidation into a single wallet are consistent with the patterns FATF's 2026 DeFi report flags as justification for stricter oversight of decentralized protocols.

In markets where regulatory tolerance for DeFi is already fragile, analysts broadly expect incidents like this one to accelerate that process.

Moonwell had not released a full post-mortem or stated whether it plans to compensate affected users as of publication on August 27.

The WELL governance token fell roughly 13 percent in the 24 hours following the attack, reversing a brief 25 percent surge that followed the initial announcement.