Risk Radar

Protocol Exploit / critical

Moonwell Exploit 2026: How MAMO Price Manipulation Drained About $8.7M

Moonwell suffered an estimated $8.7M exploit on Base after an attacker manipulated the price of MAMO collateral and borrowed liquid assets. Here is how the attack worked, what Moonwell changed and what remains unresolved.

August 29, 2026Last updated 10:30 UTC6 min read

Moonwell is investigating a major exploit on Base after an attacker used the relatively illiquid MAMO token as the center of a collateral-price manipulation strategy.

Security firms including CertiK and PeckShield estimate that roughly $8.7 million in liquid assets was extracted. Moonwell responded by effectively disabling new borrowing across its Base Core Markets while it investigates the incident.

The attack is important beyond the dollar amount. It demonstrates how a lending protocol can remain vulnerable even without a stolen admin key or a straightforward smart-contract coding bug. If an asset can be manipulated cheaply relative to the value it can unlock as collateral, the economic design of the lending market becomes the attack surface.

What happened to Moonwell?

The incident affected Moonwell's MAMO Core Market on Base on August 27.

According to the available security analysis, the attacker acquired or controlled enough MAMO liquidity to push its market price sharply higher. Because MAMO was accepted as collateral, the inflated price increased the apparent value of the attacker's collateral position.

The attacker then borrowed more liquid and more readily monetizable assets, including cbBTC and other assets available through Moonwell markets.

The basic attack path was:

  1. obtain exposure to an illiquid collateral token;
  2. push the token's observed market price materially higher;
  3. deposit or maintain the inflated token as collateral;
  4. borrow higher-quality liquid assets against the overstated collateral value;
  5. convert or consolidate the borrowed assets before the collateral price normalizes.

This is a classic economic failure mode in lending protocols: the cost to manipulate collateral must remain higher than the amount of value that can be borrowed against it.

If that relationship breaks, the protocol can inherit bad debt even if every smart contract performs exactly as coded.

How large was the loss?

The strongest public estimates converge around $8.7 million.

That should still be treated as an estimated incident figure rather than a final audited loss.

Several numbers can diverge after a lending exploit:

  • gross assets borrowed or transferred;
  • the attacker's realized proceeds;
  • remaining collateral value;
  • bad debt left in individual markets;
  • recoveries, freezes or returned funds;
  • losses ultimately borne by suppliers, reserves, insurance or protocol treasury.

Moonwell has not yet published a final post-mortem establishing the definitive economic loss and loss-allocation framework.

CEXVia therefore treats approximately $8.7 million as the best current estimate, not a settled accounting number.

Why MAMO's liquidity matters

The core problem is not simply that MAMO's price moved.

Crypto assets move sharply all the time. A lending market becomes dangerous when its risk parameters allow a comparatively shallow market to support a much larger amount of borrowing.

An oracle can report a technically valid market price while the market behind that price remains economically fragile.

That creates a mismatch between price observability and price robustness.

A secure collateral system therefore needs more than a functioning price feed. It needs controls that account for market depth, price deviation, liquidation capacity and the speed at which risk parameters can be reduced.

What did Moonwell do after the attack?

Moonwell moved quickly to restrict additional borrowing.

The protocol said borrow caps for Base Core Markets were set to 1 wei, effectively preventing new borrowing. Supply caps for MAMO and WELL were also reduced to 1 wei, while other supply caps remained unchanged.

That response is a containment measure.

It stops new positions from expanding the same risk while the protocol investigates the incident, but it does not by itself answer how much bad debt remains, which suppliers or markets absorb the loss, whether attacker funds can be recovered or when normal borrowing will resume.

Was this an oracle hack?

"Oracle attack" is a useful shorthand, but it can be misleading if it implies that the oracle software itself was necessarily compromised.

The available evidence points to price manipulation of the market feeding the collateral valuation, not necessarily to an attacker taking control of the oracle infrastructure.

If the oracle correctly reports a manipulable market price, the vulnerability sits partly in asset-selection and risk-parameter design rather than solely in the oracle code.

Potential remediation includes stronger liquidity thresholds, lower collateral factors for thin assets, tighter borrow caps, price-deviation circuit breakers, multi-source pricing and isolated markets for higher-risk collateral.

What happens to Moonwell users?

Moonwell's response focused on preventing new borrowing in affected Core Markets. That does not automatically mean every user position or every Moonwell deployment suffered the same loss.

However, lending-protocol exploits can create indirect effects even for users who never held the manipulated asset.

If an attacker borrows assets supplied by other users and leaves insufficient collateral behind, the resulting shortfall becomes protocol bad debt. How that shortfall is absorbed depends on reserves, market structure and any remediation plan approved by governance.

Moonwell has not yet published a final loss-allocation plan.

What should the post-mortem explain?

A useful Moonwell post-mortem should explain:

  • the exact price source used for MAMO;
  • the attacker's manipulation cost;
  • the peak collateral valuation;
  • assets and quantities borrowed;
  • final bad debt by market;
  • whether any funds were frozen or recovered;
  • whether protocol reserves are sufficient;
  • whether suppliers will be made whole;
  • what risk limits failed;
  • which permanent oracle or collateral changes will be implemented.

CEXVia assessment

Risk level: Critical

The classification reflects a confirmed multimillion-dollar exploit with likely protocol bad debt and a failure in collateral-risk controls.

The incident is not yet closed.

Moonwell's emergency cap reductions appear to have contained additional borrowing through the same path, but the protocol still needs to establish the final loss, loss allocation and permanent remediation.

What to watch next

  • Moonwell's official post-mortem;
  • final bad-debt amount;
  • supplier compensation or recapitalization plan;
  • attacker-wallet movements;
  • exchange or stablecoin freezes involving stolen assets;
  • permanent MAMO market treatment;
  • changes to collateral factors, oracle design and borrow caps;
  • reopening of Base Core Market borrowing.

FAQ

How much did Moonwell lose in the 2026 exploit?

Security firms currently estimate approximately $8.7 million was extracted. The final economic loss may differ after collateral value, bad debt and any recoveries are accounted for.

How did the Moonwell exploit work?

The attacker manipulated the price of the relatively illiquid MAMO token, used the inflated collateral value to borrow more liquid assets and extracted value before the manipulated price normalized.

Was Moonwell's oracle hacked?

The available evidence is more consistent with manipulation of the market price used to value collateral than with a confirmed compromise of the oracle infrastructure itself.

Is Moonwell borrowing still open?

Moonwell responded by setting Base Core Market borrow caps to 1 wei, effectively preventing new borrowing while the incident is investigated.

Will Moonwell users be reimbursed?

No final compensation or loss-allocation framework had been published at the time of this review.

*This article is for informational purposes only and does not constitute financial, legal or investment advice.*

See this event in the August 29 risk brief

Read the daily brief →