DeFi Protocol Moonwell Loses Over $8.7M After MAMO Oracle Manipulation on Base
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Moonwell lost more than $8.7 million after MAMO collateral manipulation on Base.
- The attacker borrowed cbBTC, USDC, wstETH, and ETH using artificially inflated MAMO collateral.
- The protocol cut Base borrowing and MAMO and WELL supply caps to one wei.
DeFi lending protocol Moonwell has suffered an exploit on Base after an attacker manipulated the price of MAMO collateral. Blockchain security firm CertiK traced the attack to MAMO, which Moonwell accepted as collateral in its lending market. CertiK noted that the attacker exploited thin market liquidity instead of breaching smart contracts. The attacker then borrowed cbBTC, USDC, wstETH, and ETH against the inflated MAMO position. CertiK said about $8.7 million reached an Ethereum address linked to the exploiter. Meanwhile, other trackers placed the total loss above $9 million.
We have seen an exploit of @MoonwellDeFi lending market on Base.
Attacker manipulated relatively illiquid MAMO’s collateral price, then borrowed real cbBTC
eg. https://t.co/yOBrkzXzfn~$8.7M has now been aggregated athttps://t.co/7nIcZ59jpw
Stay Vigilant!
— CertiK Alert (@CertiKAlert) August 27, 2026
Moonwell Restricts Base Markets After MAMO Attack
Following the exploit, Moonwell restricted borrowing across its Base Core Markets. It cut borrow caps to 1 wei, effectively stopping new borrowing activity. The protocol also reduced supply caps for MAMO and WELL to 1 wei. Other supply caps remained unchanged during the initial response.
The protocol also confirmed that its team had started an investigation. They described the restrictions as precautionary measures to limit exposure. The initial update found no direct smart contract breach. Instead, evidence pointed to market and oracle manipulation involving MAMO pricing. At the end of the statement, the protocol said it would publish another update once it had more information.
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating.
As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and…
— Moonwell (@MoonwellDeFi) August 27, 2026
Moonwell operates lending markets across Base, Optimism, Ethereum, Moonbeam, and Moonriver. Users can supply crypto assets for variable yields or borrow against posted collateral. WELL supports governance, staking, and ecosystem incentives. Therefore, changes to borrowing limits can quickly affect activity across connected markets.
WELL Price Falls After Security Incident
Moonwell’s WELL token moved sharply after reports of the exploit reached traders. WELL first rose from about $0.00367 to $0.0045 before reversing lower. At the time of this writing, the token is trading around $0.002851, representing a 19% decline.

MAMO also saw unusual trading activity during and after the attack. Prices climbed during manipulation before pulling back from elevated levels. The token avoided the scale of collapse seen in some earlier DeFi exploits. However, the artificial increase drove the attacker’s borrowing strategy.
Earlier Moonwell Incident Raised Similar Concerns
The latest exploit follows another security event that affected the protocol on February 18, 2026. That incident involved a faulty pricing setup linked to the MIP-X43 governance proposal. The proposal introduced Chainlink Oracle Extractable Value wrapper contracts into the system. A calculation error later caused a pricing mismatch for cbETH on Base.
Reports noted that the faulty setup priced cbETH near $1.12 despite a market value around $2,200. The error created about $1.78 million in bad debt for the protocol. Parts of the contract code reportedly involved Anthropic’s Claude during development. The incident renewed debate around testing standards for automated code assistance in DeFi.
Moonwell’s exploit also follows another attack on Maya Protocol earlier this month. Maya halted MAYAChain after an attacker chained several software flaws and extracted about $1.7 million. The losses included roughly 20 Bitcoin and around $300,000 in other assets. The incident also triggered heavy losses across Maya liquidity pools and sent CACAO sharply lower.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







