Logo Daily Crypto Briefs
Open menu

Moonwell Halts Base Borrowing After $8.7M MAMO Exploit

6 min read
Breaking News
Large official Moonwell white wordmark and crescent mark on a blue signboard beside a greyscale unbranded lending vault, price gauge and emergency stop lever on off-white and amber editorial panels.

TL;DR

  • Moonwell set borrow caps for every Base Core Market to 1 wei after an attacker used an inflated MAMO collateral price to borrow liquid assets.
  • PeckShield and CertiK estimated the loss at about $8.7 million, while public on-chain tracing shows 8.728 million DAI at the address identified in reporting.
  • WELL fell about 18.2% between the August 27 and August 28 UTC CoinGecko readings, with market capitalization near $13.6 million at the latter reading.
  • Moonwell has not released a final accounting, affected-wallet count, recovery plan or technical post-mortem.

CASABLANCA, August 28, 2026

Moonwell restricted new borrowing across all of its Base Core Markets after an attacker used an inflated MAMO collateral price to borrow liquid assets, with PeckShield and CertiK estimating the loss at about $8.7 million as of August 28.

The action leaves the decentralized lending protocol investigating its MAMO Core Market while it limits new risk across Base. Moonwell said borrow caps were set to 1 wei, the smallest Ethereum-compatible unit, and that MAMO and WELL supply caps were also reduced to 1 wei; it did not immediately release a final loss total, affected-wallet count or recovery plan.

WELL fell from $0.003672 at the August 27 UTC CoinGecko reading to $0.003003 on August 28, a decline of about 18.2%, while its reported market capitalization fell to roughly $13.6 million and daily volume reached about $1.66 million. The security event is more consequential for Moonwell users than the governance token’s move: borrowers cannot open new Core Market positions on Base until the caps change, while depositors are waiting for the protocol to clarify liquidity and bad-debt effects.

In its official incident statement, Moonwell said it was “actively investigating” an issue affecting the MAMO Core Market and described the 1-wei borrow caps as a precaution to limit further impact. Blockaid’s exploit alert said an attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market and initially observed 50.6 cbBTC, worth more than $4 million, leaving the protocol.

The later $8.7 million estimate changes the scale of the incident from a single-asset alert to a broader lending-market loss. It also highlights a familiar DeFi failure mode: if a protocol accepts a thinly traded asset as collateral at a distorted price, an attacker can borrow assets with deeper liquidity before the risk controls catch up. The evidence reviewed does not establish the attacker’s identity or whether every affected balance can be recovered.

Moonwell

WELL
July 29 to August 28, 2026
$0.003
-0.4%
Jul 29 - Aug 28 | High $0.0037 Low $0.0029

Moonwell Restricts Base Borrowing Across Core Markets

Moonwell’s emergency setting prevents new borrowing across Base Core Markets, not only the market that accepted MAMO collateral. The protocol said supply caps for MAMO and WELL were set to 1 wei, while other supply caps remained unchanged. A borrow cap determines how much of an asset can be borrowed, so reducing it to the minimum stops additional borrowing without itself explaining the position of current suppliers and borrowers.

The MAMO market was added to Moonwell’s Base Core Markets in October 2025, according to the project’s governance forum. Security firms’ account is that the attacker inflated the price of that comparatively illiquid collateral, supplied it and borrowed cbBTC and other liquid assets against a value that did not hold outside the manipulated market.

That sequence makes this a pricing and collateral-risk event, rather than evidence that an attacker broke every Moonwell smart contract. Still, an oracle is the mechanism a lending market uses to decide how much a posted asset is worth. If the price input does not adequately resist a fast move in a thin market, borrowers can leave suppliers exposed to bad debt.

The response resembles the first containment step taken after the Term Finance Meta Vault governance exploit, where the project later closed the affected product layer. Moonwell has not announced a comparable shutdown, reimbursement decision or timetable, so it would be premature to infer one.

Moonwell’s $8.7M Loss Estimate Has On-Chain Support

The dedicated loss-impact check found a consistent $8.7 million estimate from PeckShield and CertiK, cited in The Block’s incident report, and in DefiLlama’s hack database, which classifies the event as oracle manipulation and spot-price manipulation. These are security-research and tracking estimates, not a final protocol accounting.

There is also specific public transaction-level evidence. A chain review published August 28 reported that address 0xD71d…C384 received 8,728,318.997396 DAI on Ethereum, nearly matching the reported loss, and that the balance remained there at its investigation cutoff. The review was careful not to claim it had reconstructed every exploit call or proved every reported cbBTC transfer.

That distinction is important in a live incident. An address balance can corroborate an observed consolidation of funds, but it does not independently settle the amount of protocol bad debt, the number of lenders affected, or whether assets will be frozen or returned. Moonwell has not identified an attacker publicly or said whether it has contacted exchanges, issuers or law enforcement.

The incident follows a wider run of lending and oracle-related security failures. In an earlier balance-coin oracle exploit, distorted collateral valuation likewise created a path from a price input to an asset loss. The shared mechanism does not establish the same root cause, but it shows why caps, liquidity assumptions and price-source design remain central to lending-market risk.

Depositors Await Scope, Liquidity and Recovery Details

For users, the most material unanswered question is whether the assets borrowed against the manipulated collateral leave a shortfall in the affected markets. The reported DAI at the identified address is evidence of a possible recovery target, but the protocol has not confirmed that it controls the address, that the funds are frozen or that suppliers will be made whole.

Moonwell’s announcement did not state that withdrawals are paused, nor did it publish a market-by-market liquidity table after the attack. That means users should not treat the cap change alone as proof that their particular deposit, borrowing position or vault exposure is unaffected. The project’s dashboard and subsequent official updates are the relevant places to verify a specific position.

The market backdrop remained risk-on even as the incident became public. CoinGecko’s Moonwell page showed the token’s one-day dislocation and elevated activity, while Alternative.me’s Crypto Fear and Greed Index read 73, or Greed, on August 28. Neither metric measures whether a lending pool has sufficient assets to honor withdrawals.

Fear & Greed Index

August 28, 2026
73 Greed

The next evidence that can turn the provisional $8.7 million figure into a clearer user-impact assessment is a Moonwell post-mortem: the affected contracts and markets, a transaction-level reconciliation, the amount of any bad debt, the number of wallets affected and a recovery decision. Until then, the strongest supported account is a MAMO price-manipulation incident that prompted a protocol-wide Base borrowing restriction, with a large but not yet final loss estimate.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

What happened in the Moonwell MAMO exploit?

Security firms said an attacker manipulated the price of thinly traded MAMO collateral in Moonwell's Base market, then borrowed liquid assets against the inflated value. Moonwell stopped new borrowing across its Base Core Markets while it investigates.

How much was lost in the Moonwell exploit?

PeckShield and CertiK estimated the loss at about $8.7 million. A public on-chain review found 8,728,318.997396 DAI at an address cited in incident reporting, but Moonwell had not published a final loss accounting as of August 28, 2026.

Can Moonwell users borrow on Base after the incident?

Moonwell said it set borrow caps for all Base Core Markets to 1 wei, the smallest unit, which prevents new borrowing. The project did not immediately publish a date for restoring normal borrow caps.

Which Moonwell assets were restricted?

Moonwell said the MAMO Core Market was under investigation, borrow caps across Base Core Markets were reduced to 1 wei, and the supply caps for MAMO and WELL were also set to 1 wei. It said other supply caps were unchanged.