What Happened in the Moonwell Exploit? $8.7M Lost on Base
2026-08-28
On August 27, 2026, the Moonwell exploit on Base drained $8.7 million after an attacker manipulated the price of MAMO collateral to borrow real assets from the decentralized lending protocol. This price-oracle attack, not a smart-contract breach, targeted Moonwell’s MAMO Core Market and left the protocol with significant bad debt.
This article walks through what happened, how the exploit actually worked, whether user funds were affected, and how Moonwell responded.
Key Takeaways
MAMO, a thinly traded collateral token unrelated to Moonwell's own WELL token, was artificially pumped roughly eightfold and used to borrow real assets from Moonwell.
Security firms CertiK, PeckShield, and Blockaid independently estimated losses near $8.7 million, with stolen funds converted to DAI and sitting untouched in a single wallet.
Moonwell froze new borrowing across all Base markets within hours; existing user deposits remained withdrawable, but the drained liquidity leaves bad debt the protocol still has to address.
What Happened: The Moonwell Base Exploit in Brief
An attacker targeted Moonwell's MAMO Core Market on Base. By manipulating MAMO's price, they made a relatively small holding look far more valuable than it was, then used that inflated value as collateral to borrow real, liquid assets, including cbBTC, USDC, wstETH, and ETH.
Security firms CertiK, PeckShield, and Blockaid separately confirmed the loss at roughly $8.7 million. No Moonwell smart contract was breached in the process; the exploit worked entirely through price manipulation.
How the MAMO Collateral Exploit Worked
A Price Trick, Not a Code Hack
Moonwell prices collateral using a spot oracle, meaning it simply reads whatever price a token is trading at on a decentralized exchange in that exact moment. MAMO had only around $1.18 million in daily trading volume before the attack, a small pool by DeFi standards.

By aggressively buying MAMO across its two main trading venues, Aerodrome SlipStream and Uniswap V4, the attacker pushed MAMO's price from roughly $0.011 up to somewhere between $0.088 and $0.43 depending on the measurement window, according to different security trackers.
Moonwell's oracle read that inflated price as legitimate, allowing the attacker to deposit MAMO and borrow far more valuable assets than the position was actually worth.
MAMO vs. WELL: Why the Distinction Matters
This is the part worth repeating clearly. MAMO is the collateral asset that was manipulated; it is tied to the separate Mamo app, which stated its own contracts were never compromised. WELL is Moonwell's own native governance token, and it was not the token being manipulated.
Moonwell did lower the supply caps on both MAMO and WELL to 1 wei as a precaution, which is likely why the two tokens have been mentioned together in headlines.
Price-wise, both tokens saw volatile swings after the news broke, WELL fell roughly 13% within 24 hours according to CoinGecko-sourced reporting, while some intraday tracking also showed brief, sharp spikes amid the volatility, before settling into thin, choppy trading typical of a low-liquidity token reacting to bad news.
Explore more DeFi insights and trade securely! Register on Bitrue today to access a wide range of crypto markets with ease.
Were User Funds Affected?
Existing depositors on Moonwell's Base markets could still withdraw their funds after the exploit; the emergency measures blocked new borrowing, not existing withdrawals. That said, the $8.7 million that was drained came directly out of the protocol's lending liquidity, meaning the loan is effectively unrepayable bad debt unless the attacker returns the funds or is identified.
That bad debt has to be absorbed somewhere, which is why users interacting with Moonwell's Base markets, or apps like Mamo that route deposits through Moonwell, should watch for official updates on any compensation plan before assuming the situation is fully resolved.
Moonwell's Response
Moonwell confirmed the incident on X, stating it was aware of an issue affecting the MAMO Core Market on Base and was actively investigating. As an immediate measure, the protocol set borrow caps for all Core Markets on Base to 1 wei, the smallest possible unit on an Ethereum-based token, effectively halting new lending without requiring a lengthy governance vote. Supply caps for both MAMO and WELL were also set to 1 wei.
As of publication, Moonwell had not announced a compensation framework for the losses, and said further updates would follow as more information became available.
Quick Reference: MAMO vs. WELL
Read also: Moonwell (WELL) Price Prediction 2025–2030: Forecast & Strategic Analysis
Summary
The Moonwell exploit is a textbook case of oracle manipulation, not a contract-level hack. The attacker never touched Moonwell's code; they exploited the gap between a thinly traded collateral token's real value and what a spot-price oracle reported in the moment.
The distinction between MAMO and WELL matters for anyone trying to understand exposure: MAMO was the manipulated asset, WELL is Moonwell's own token that was affected mainly through emergency risk caps and market sentiment. Until protocols like Moonwell adopt stricter liquidity thresholds and time-weighted pricing for new collateral listings, this type of exploit is likely to keep recurring across Base DeFi.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
FAQ
What exactly happened in the Moonwell exploit?
An attacker manipulated the price of MAMO, a low-liquidity token Moonwell accepted as collateral, then used the artificially inflated value to borrow real assets like cbBTC, USDC, and ETH, draining roughly $8.7 million.
Is MAMO the same as Moonwell's WELL token?
No. MAMO belongs to a separate app called Mamo and was simply listed as collateral on Moonwell. WELL is Moonwell's own native governance token and was not the token directly manipulated in the attack.
Were user funds on Moonwell affected?
Existing deposits remained withdrawable after the exploit. The drained $8.7 million came from the protocol's lending liquidity rather than users' locked collateral directly, but it represents bad debt the protocol will eventually need to address.
How did Moonwell respond to the hack?
Moonwell set borrow caps for all Core Markets on Base to 1 wei, effectively halting new borrowing, and lowered supply caps for MAMO and WELL to the same level, all without requiring a full governance vote.
Could this kind of exploit happen again?
Yes. Any protocol using spot-price oracles for thinly traded collateral tokens carries similar risk. This is Moonwell's third oracle-related security incident in under a year, according to security researchers tracking the protocol.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
Disclaimer: The content of this article does not constitute financial or investment advice.




