Close Menu
    Facebook X (Twitter) Instagram
    Thursday, August 27
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » Moonwell MAMO exploit drains $8.7M from Base lending market
    Crypto

    Moonwell MAMO exploit drains $8.7M from Base lending market

    James WilsonBy James WilsonAugust 27, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Moonwell has halted new borrowing across its Core Markets on Base after an apparent MAMO collateral price manipulation exploit drained about $8.7 million from the decentralized lending protocol.

    Summary

    • Moonwell has restricted new borrowing across its Base Core Markets after an apparent MAMO collateral price manipulation exploit drained about $8.7 million.
    • CertiK said the attacker manipulated the relatively illiquid MAMO token’s collateral price before borrowing real cbBTC from Moonwell’s mCBTC market.
    • Moonwell lowered all Base Core Market borrow caps to 1 wei and also set MAMO and WELL supply caps to 1 wei while it investigates the incident.
    • PeckShield estimated losses at roughly $8.7 million and said the attacker consolidated the stolen funds into DAI at a single address.

    Moonwell said in an Aug. 27 post on X that it was investigating an issue affecting the MAMO Core Market and had lowered borrow caps across all Core Markets on Base to 1 wei as a precaution, effectively preventing users from opening new borrowing positions while the investigation continues.

    “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact,” Moonwell said.

    Supply caps for MAMO and WELL were also reduced to 1 wei, while supply limits for other assets were left unchanged, according to the protocol. Moonwell said it would provide further updates once more information became available.

    Blockchain security firms PeckShield and CertiK separately estimated that approximately $8.7 million had been taken, while Blockaid traced the apparent attack to manipulation of the MAMO token’s collateral price.

    Moonwell exploit used MAMO collateral price to borrow cbBTC

    According to CertiK, the attacker manipulated the collateral value of MAMO, a relatively illiquid token, before using the inflated collateral to borrow real cbBTC from Moonwell’s mCBTC market.

    Blockaid identified the same mechanism, initially reporting that 50.6 cbBTC worth more than $4 million had been drained as it monitored the transactions. PeckShield later estimated total losses at about $8.7 million and said the attacker had consolidated the proceeds into DAI at a single address.

    The use of a thinly traded asset as collateral was central to the attack described by the security firms. By changing MAMO’s market price, the attacker was able to increase the value assigned to the collateral position before borrowing assets with deeper liquidity.

    MAMO has previously experienced sharp price swings. The token fell after its Coinbase debut in August 2025 after gaining more than 120% during the preceding week. At the time, crypto.news reported that MAMO had reached an all-time high of $0.227 before losing nearly 20% as selling activity increased.

    Price pressure returned following Thursday’s security incident. Moonwell’s WELL token was down about 13% over the preceding 24 hours, according to CoinGecko data cited in the initial report, while MAMO had fallen roughly 9% over the same period, according to DEX Screener.

    The restrictions imposed by Moonwell cover borrowing across its Base Core Markets, not only the MAMO market where the issue was identified. Existing supply caps for assets other than MAMO and WELL remained unchanged while the team investigated the incident.

    Moonwell has faced previous oracle and governance problems

    Thursday’s incident follows other security problems at Moonwell during 2026, including a pricing failure that left its lending markets with about $1.78 million in bad debt.

    In February, an oracle calculation error mispriced Coinbase Wrapped ETH, or cbETH, at roughly $1.12 when the asset was trading near $2,200. The incorrect price allowed liquidators and automated bots to repay positions at the distorted valuation and seize cbETH collateral, according to the protocol’s disclosure cited by crypto.news.

    The faulty oracle logic reportedly included code generated with Anthropic’s Claude Opus 4.6 model. Moonwell said at the time that an incorrect scaling factor in the calculation caused the large difference between the oracle value and the market price.

    Another Moonwell security issue surfaced the following month when an unknown party acquired about $1,800 worth of MFAM tokens and used the holdings to push a malicious governance proposal through quorum on the protocol’s Moonriver deployment.

    The March proposal sought control of seven lending markets, Moonwell’s comptroller and its oracle through an attacker-controlled contract, putting about $1.08 million of assets at risk. Moonwell’s Break Glass Guardian multisig provided an emergency mechanism capable of stopping the proposal before execution, while subsequent votes moved against it.

    Unlike the February pricing failure, security firms assessing the Aug. 27 incident have described the latest attack as active manipulation of the market price used for MAMO collateral. Moonwell has not yet published a detailed post-mortem identifying the exact contracts, oracle structure or transaction sequence involved.

    DeFi exploits have remained elevated since April

    The Moonwell exploit comes after a series of large DeFi attacks during the second quarter of 2026, with April accounting for several of the year’s biggest losses.

    CertiK warned in April that AI misuse and infrastructure weaknesses were becoming significant parts of crypto security risk. The firm said attackers were using social engineering, infrastructure vulnerabilities and more advanced automated tools, including AI-assisted phishing, deepfakes and exploit techniques.

    By April 18, crypto protocols had lost more than $606 million across at least 12 incidents during the month, according to DefiLlama data cited by crypto.news. The total exceeded losses recorded during the entire first quarter of 2026.

    Kelp DAO accounted for one of the largest incidents after attackers drained roughly 116,500 rsETH worth about $292 million from its cross-chain setup on April 18.

    LayerZero later said the Kelp DAO exploit involved compromised RPC infrastructure used by its decentralized verifier network and affected Kelp DAO’s single-DVN rsETH configuration. The company said preliminary evidence pointed to North Korea-linked TraderTraitor, which it associated with the Lazarus Group.

    The incident also affected lending markets holding rsETH. Aave experienced large withdrawals and was left with substantial bad debt after stolen rsETH was used as collateral to borrow other assets, while SparkLend and Fluid restricted affected markets.

    In June, Binance Research said April’s DeFi exploits had contributed to about $13 billion in total value locked outflows from on-chain protocols. Its May market report put DeFi TVL at $82.7 billion at the end of April, down 10.7% from the previous month, while exploit losses for the month totaled $635.24 million.

    Moonwell has not yet disclosed whether the $8.7 million estimate represents its final loss from the MAMO Core Market incident or whether any of the affected assets can be recovered. The protocol said its investigation remains active and that further information will be released when available.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIs retail back or is MicroStrategy only pumping the price of bitcoin?
    Next Article Earn Rewards with our New Swaps Quest!
    James Wilson

    Related Posts

    Truflation calls for Fed rate cut after PCE forecast

    August 27, 2026

    Ethereum price holds $2,500 as bulls target $3,000 next

    August 27, 2026

    Bitcoin price eyes $83K after clearing 200-day SMA

    August 27, 2026
    Leave A Reply Cancel Reply

    Don't Miss

    Truflation calls for Fed rate cut after PCE forecast

    Mexican crypto trading bot scheme disappears with 3,000 users’ funds

    Earn Rewards with our New Swaps Quest!

    Moonwell MAMO exploit drains $8.7M from Base lending market

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    Truflation calls for Fed rate cut after PCE forecast

    August 27, 2026

    Mexican crypto trading bot scheme disappears with 3,000 users’ funds

    August 27, 2026

    Earn Rewards with our New Swaps Quest!

    August 27, 2026
    Lithosphere News Releases
    Copyright © 2026

    Type above and press Enter to search. Press Esc to cancel.