Moonwell Loses Over $9M in Base Exploit After MAMO Price Oracle Manipulation

Security monitoring screens showing a blockchain exploit alert after Moonwell's $9M Base hack

Moonwell, a decentralized lending protocol, lost more than $9 million in real crypto assets on August 27, 2026, after an attacker manipulated the price of the MAMO token on the Base network and used the inflated value as collateral to borrow cbBTC, USDC, wstETH, and ETH. Blockchain security firm CertiK flagged the incident, noting that the attacker pushed MAMO’s price from roughly $0.0105 to $0.088 — an increase of nearly eight times — before draining funds from the platform’s lending markets.

How the Attacker Exploited MAMO’s Thin Market

According to CertiK’s alert, the exploit did not stem from a direct vulnerability in Moonwell’s smart contract code. Instead, the attacker targeted a price oracle that could be influenced by trading activity in the relatively illiquid MAMO market. By pushing the token’s price upward, the attacker made their MAMO holdings appear far more valuable than their actual market worth, allowing them to borrow significant amounts of real assets against the inflated collateral.

Also read: Seven Altcoins to Watch as the Crypto Clarity Act Vote Nears: ETH, SOL, LINK, ZEC, HYPE, XRP, ONDO

Blockchain monitoring firm ExVul SkyEye reported that the largest single transaction in the attack moved 14.34 cbBTC, valued at approximately $1.15 million. The total loss was initially reported at around $8.7 million by CertiK, but other tracking sources quickly pushed the figure past the $9 million mark as more transactions were identified.

The incident highlights a persistent risk in DeFi: price oracles that rely on trading data from thin, low-liquidity markets can be manipulated with relatively small capital. This type of attack, often called an oracle manipulation or price-feed exploit, has been used against numerous lending protocols in recent years.

Also read: Ripple's RLUSD Stablecoin Surpasses $2 Billion Market Cap as XRP Climbs 25%

Moonwell’s Second Major Security Incident in Six Months

This is not the first security problem Moonwell has faced in 2026. On February 18, 2026, the protocol suffered a major incident on Base after a faulty smart contract caused a severe pricing error. That issue stemmed from MIP-X43, a governance proposal that enabled Chainlink Oracle Extractable Value (OEV) wrapper contracts. The contract, partly written with Anthropic’s Claude AI, missed an important calculation step, causing cbETH — worth around $2,200 at the time — to be priced at just $1.12. The error left Moonwell with approximately $1.78 million in bad debt.

The recurrence of security issues raises questions about the protocol’s risk management and oracle design. While Moonwell has not yet released a full official update on the latest exploit, the market has already reacted: the protocol’s native token dropped 3% to trade at around $0.003407.

What This Means for DeFi Users and the Base Ecosystem

The exploit is a reminder that even well-established lending protocols can be vulnerable to market manipulation when they accept low-liquidity tokens as collateral. For users, the key takeaway is the importance of understanding which assets a protocol accepts and how its price oracles are sourced. Lending platforms that rely on spot price feeds for illiquid tokens are inherently exposed to this class of attack.

For the Base ecosystem, which has been positioning itself as a hub for DeFi activity, this incident could slow momentum. Base has seen significant growth in lending and trading volumes throughout 2026, and security incidents on major protocols can prompt users to move funds to more battle-tested networks. The Moonwell team’s response in the coming days — including whether they will reimburse affected users or adjust their oracle infrastructure — will be closely watched.

CertiK said the attacker’s funds have been aggregated at its Vigilant platform, which tracks stolen assets across chains. The security firm has not yet identified the attacker’s identity or provided details on recovery efforts. Moonwell’s official communication has been limited so far, and the final confirmed loss amount may still change as investigations continue.

As DeFi protocols increasingly integrate cross-chain collateral and AI-assisted smart contract development, the Moonwell incident underscores a broader lesson: code audits and governance proposals are only part of the security equation. Market dynamics, liquidity depth, and oracle design are equally critical — and often the weakest link in the chain.

This article is for informational purposes only and does not constitute financial advice. Cryptocurrency markets are highly volatile and uncertain; readers should conduct their own research before making any investment decisions.

Moris Nakamura

Written by

Moris Nakamura

Moris Nakamura is the editor-in-chief at CryptoNewsInsights, overseeing coverage of Bitcoin, altcoin markets, and the broader cryptocurrency industry.

Leave a Reply

Your email address will not be published. Required fields are marked *