HomeZ - Banner home engMoonwell MAMO exploit drains $8.7M in cbBTC after collateral manipulation

Moonwell MAMO exploit drains $8.7M in cbBTC after collateral manipulation

Another day, another DeFi lending exploit — but this one didn’t need a single line of malicious code. On August 27, decentralized lending protocol Moonwell lost roughly $8.7 million after an attacker figured out how to game the price of one of its own listed tokens, MAMO, and used the inflated collateral to walk away with real bitcoin-backed assets on the Base network. The Moonwell MAMO exploit has reignited scrutiny of how thinly traded tokens can become a backdoor into otherwise well-audited lending markets.

Key takeaways

  • Moonwell lost about $8.7 million on August 27 after an attacker manipulated the price of the illiquid MAMO token used as collateral on Base.
  • The attacker borrowed real cbBTC against the inflated MAMO collateral, then converted the proceeds into DAI and consolidated everything in one wallet.
  • Moonwell set borrow caps to 1 wei across all Base Core Markets and cut MAMO and WELL supply caps to 1 wei to stop further bleeding.
  • WELL fell about 13% and MAMO dropped roughly 9% within 24 hours of the attack.
  • This is Moonwell’s third security incident in 2026, following an oracle mispricing bug and a governance attack earlier in the year.

Moonwell Suffers $8.7 Million Exploit via MAMO Token Price Manipulation

An attacker drained approximately $8.7 million from Moonwell’s MAMO Core Market by exploiting a weakness that had nothing to do with smart contract code and everything to do with market thinness. MAMO, a relatively illiquid token on Base, turned out to be an easy lever to pull: push its price up artificially, and the protocol’s collateral math follows along.

Attack Mechanics and Loss Estimation

Security firms CertiK, PeckShield, and Blockaid independently traced the same attack path. The attacker manipulated MAMO’s collateral price to inflate its apparent value, then used that puffed-up collateral to borrow real cbBTC — Coinbase’s wrapped bitcoin — from Moonwell’s mCBTC market. Blockaid’s early read put the damage at more than $4 million, tied to 50.6 cbBTC drained in the initial phase. PeckShield later settled on a final estimate close to $8.7 million, a figure CertiK corroborated independently.

Why this matters: when three separate security firms converge on the same number and the same mechanism, it removes much of the ambiguity that usually surrounds early exploit reports. It also confirms this wasn’t a bug exploit or a flash loan trick in the traditional sense — it was a collateral-pricing weakness tied directly to a token’s shallow liquidity.

Stolen Funds Consolidated as DAI Stablecoin

Once the attacker had the borrowed cbBTC in hand, the funds were converted into DAI stablecoin and funneled into a single wallet address. Stablecoin consolidation is a familiar move in crypto exploits — it locks in value against further market swings and simplifies whatever comes next, whether that’s laundering, bridging, or simply sitting still while investigators watch.

Moonwell’s Emergency Response to Contain the Breach

Moonwell moved within hours to choke off any further damage, effectively freezing new borrowing across its Base markets rather than waiting for a full diagnosis.

Borrow Caps and Supply Limitations Implemented

The protocol set borrow caps for all Core Markets on Base down to 1 wei — an amount so small it functions as a hard stop, preventing any new borrowing activity platform-wide. Alongside that, Moonwell reduced supply caps for both MAMO and WELL tokens to 1 wei as well, directly targeting the two assets tied to the exploit. Supply limits for every other asset on the platform were left untouched, suggesting the response was narrowly scoped to the compromised markets rather than a blanket lockdown.

Market Impact and Ongoing Investigations

Markets reacted almost immediately once the exploit became public. Moonwell’s native WELL token dropped around 13% within 24 hours, according to CoinGecko data, while MAMO itself fell roughly 9% over the same window, per DEX Screener figures. For a token that already carried a volatile history — MAMO hit an all-time high of $0.227 before losing nearly 20% following its Coinbase debut in August 2025 — the exploit added fresh pressure to an asset investors were already watching closely.

Investigation Status and Transparency Concerns

Moonwell has said it will share further updates as its investigation continues, but the protocol has not yet published a full post-mortem or confirmed whether any of the stolen funds can be recovered. That leaves an open question hanging over the incident: whether the DAI sitting in that single wallet ever makes its way back to the protocol or its users.

Context of Repeated Security Issues and Widespread DeFi Exploits in 2026

This isn’t Moonwell’s first brush with trouble this year, and that pattern matters for anyone assessing the protocol’s risk profile going forward.

Previous Moonwell Vulnerabilities and Attacks

In February, an oracle error mispriced Coinbase Wrapped ETH at around $1.12 — while it was actually trading near $2,200 — leaving Moonwell with about $1.78 million in bad debt. That faulty oracle reportedly relied on code generated with the help of Anthropic’s Claude Opus 4.6 model, where an incorrect scaling factor triggered the pricing error. Then in March, an attacker spent roughly $1,800 buying MFAM tokens to push a malicious governance proposal through quorum on Moonwell’s Moonriver deployment. That an emergency multisig mechanism was in place to protect approximately $1.08 million that faced risk across seven lending markets targeted by the proposal intervened and blocked it.

Three separate incidents in a single year — an oracle bug, a governance attack, and now a collateral manipulation exploit — point to a broader pattern rather than one-off bad luck. Each incident exposed a different attack surface: pricing infrastructure, governance mechanics, and now the reliability of thinly traded collateral assets. For a lending protocol, that breadth of exposure raises harder questions about how deeply security reviews cover every asset a market chooses to list, not just the flagship ones.

April 2026 DeFi Exploit Wave and Industry-Wide Risks

Moonwell’s August exploit lands inside a rougher stretch for decentralized finance generally. By April 18, crypto protocols had already lost more than $606 million across at least 12 separate incidents that month alone, with the largest being the $292 million Kelp DAO exploit linked to North Korea’s Lazarus Group. Binance Research later estimated that April’s exploits contributed to roughly $13 billion in total value locked outflows from on-chain protocols — a reminder that individual hacks rarely stay isolated; they tend to spook capital across the whole sector.

Set against that backdrop, the Moonwell MAMO exploit looks less like an isolated failure and more like one entry in a longer ledger of DeFi lending vulnerabilities tied to collateral pricing and illiquid tokens. Whether Moonwell’s rapid-response caps restore user confidence — or whether repeated incidents push liquidity elsewhere on Base — will likely depend on what the pending post-mortem actually reveals.

FAQ

How did the attacker execute the Moonwell exploit?

The attacker manipulated the collateral price of the illiquid MAMO token to borrow real cbBTC from Moonwell’s lending market on the Base network.

What measures did Moonwell take to limit further losses?

Moonwell set borrow caps of 1 wei across all Base Core Markets and reduced supply caps for MAMO and WELL tokens to 1 wei to stop new borrowing and limit risk.

What was the financial impact on Moonwell’s tokens following the exploit?

Following the exploit, Moonwell’s WELL token price dropped about 13% while the MAMO token price fell roughly 9%.

Is Moonwell able to recover the stolen funds?

Moonwell’s investigation is ongoing, and the protocol has not yet confirmed whether any stolen funds can be recovered.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Alessia Pannone
Graduated in communication sciences, currently student of the master's degree course in publishing and writing. Writer of articles from an SEO perspective, with care for indexing in search engines.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST