Moonwell Suffers Multimillion-Dollar Exploit Following Collateral Price Manipulation on Base

Attacker manipulated MAMO price from ~$0.0105 to ~$0.088, eightfold, leveraging a moved price oracle in the thin MAMO market to inflate collateral value used to borrow assets such as cbBTC, USDC, wstETH and ETH.
WELL's market price saw a brief spike during the incident, jumping to about $0.0045 from $0.00367 before retracing to around $0.0033, illustrating acute volatility in Moonwell's tokens amid the exploit.
The exploit appears to hinge on a price-oracle vulnerability rather than a direct bug in Moonwell's code, with the attacker using trading in a thin MAMO market to move the collateral value.
Stolen funds were reportedly consolidated in the DAI stablecoin at a single address, underscoring the attacker’s effort to centralize liquidity.
The incident is situated within a broader wave of DeFi exploits, with observers noting AI-assisted trading contributing to a tally of more than $600 million hacked since April, including high-profile cases like Kelp DAO.
Moonwell, a decentralized lending protocol, suffered an $8.7 million exploit on the Base blockchain after an attacker manipulated the price of MAMO, a thinly traded token used as collateral. The Defiant reported that the attacker inflated MAMO's price roughly eightfold—from about $0.0105 to $0.088—to fraudulently borrow real assets including cbBTC, USDC, wstETH, and ETH. In response, Moonwell paused new borrowing on Base and capped all Core Market borrows at 1 wei to contain further damage.
Security firms CertiK and PeckShield identified the attack as a price-oracle vulnerability rather than a bug in Moonwell's core code. The Block reported that stolen funds were consolidated into DAI stablecoins at a single address. The incident underscores a broader wave of DeFi exploits—more than $600 million has been stolen since April, with attackers increasingly targeting illiquid collateral in lending protocols.
The attacker exploited MAMO's thin trading market to artificially inflate its value. By trading heavily in low-volume pools, the attacker pushed MAMO's price from roughly $0.0105 to $0.088—an eightfold jump. Cryptopolitan noted that the attacker then used this inflated collateral value to borrow much larger amounts of real assets from Moonwell's lending pools, a classic price-oracle manipulation attack.
Price-oracle vulnerabilities occur when a protocol relies on market prices to determine collateral value. If an attacker can move the market price in a thin or illiquid trading pair, they can trick the protocol into thinking their collateral is worth far more than it actually is. Moonwell's use of MAMO as collateral on Base made it particularly vulnerable to this scheme.
Finance Feeds reported that Moonwell immediately halted new borrowing on Base and implemented strict caps to prevent further damage. All Core Market borrows were capped at 1 wei—the smallest possible unit. Supply for MAMO and WELL tokens was also capped at 1 wei to lock down the affected markets and stop the attacker from extracting more value.
The exploit triggered sharp volatility in Moonwell's tokens. WELL spiked to about $0.0045 from $0.00367 during the attack before retracing to around $0.0033, reflecting investor panic. Base remains Moonwell's largest market by value locked, making this exploit particularly damaging to the protocol's reputation and total assets under management.
HokaNews highlighted that this incident fits into a troubling pattern. More than $600 million has been stolen from DeFi protocols since April 2026, with high-profile cases like Kelp DAO also falling victim. Attackers are increasingly using AI-assisted trading bots to spot and exploit vulnerabilities in thinly traded assets and weak price oracles.
The Moonwell exploit reveals a critical weakness in multi-chain lending protocols: illiquid collateral can be weaponized by sophisticated attackers. As DeFi grows, protocols must strengthen price-oracle mechanisms and avoid accepting thinly traded tokens as collateral. Without better safeguards, similar exploits will likely continue.
Publishers
11
Articles
13
Reach
24