Moonwell Loses $8.7 Million to Price Manipulation of MAMO Token on Base

Aug 29, 2026 16:58 Written by Yasir Arafat moonwell base hack oracle defi
Moonwell Loses $8.7 Million to Price Manipulation of MAMO Token on Base

Protocol halts all borrowing after exploit

Moonwell lost about $8.7 million on Thursday after an attacker manipulated the price of the MAMO token on the Base blockchain. The lending protocol responded by setting borrow limits to essentially zero across all its main markets on Base.

The attack began roughly two hours before Moonwell announced it was aware of the issue. By the time the protocol acted, the attacker had already drained assets from the mCBTC market. MAMO is a small-cap token accepted as collateral, meaning users can borrow against it.

Key numbers from the incident

  • Total loss estimated at $8.7 million by security firms CertiK and PeckShield.
  • Blockaid reported that 50.6 cbBTC, worth over $4 million, was drained from the mCBTC market.
  • The stolen funds were converted into 8,728,318 DAI, a stablecoin pegged to the US dollar.
  • MAMO had a market cap of about $6 million and daily trading volume of $1.18 million before the attack.
  • Moonwell holds $71.5 million in total value locked, with $68.2 million on Base.

How the price manipulation worked

MAMO is a token for an AI-powered personal finance app. Before the attack, it traded mainly on two pools with limited liquidity. This made the price easy to move.

Data shows the price of MAMO swung as much as 47 times over a 24-hour period, reaching as high as $0.4739 and dropping as low as $0.0101. The attacker used this volatility to inflate the collateral value of MAMO.

With the artificially high price, the attacker borrowed real assets against their MAMO holdings. One transaction pulled 14.33 cbBTC, worth about $1.15 million, out of the protocol for a gas fee of roughly one cent. Gas fees are small payments made to network validators to process transactions.

The same address also withdrew 560 ETH, worth about $1.42 million, through Moonwell's unwrapper. The attacker then moved USDC to the Ethereum network using Circle's cross-chain transfer protocol.

Where the stolen funds went

The Ethereum address holding the proceeds was empty until August 21. It received about 0.1 ETH from Tornado Cash, a privacy tool that mixes cryptocurrencies to obscure transaction trails. It also received about 99 ETH through bridges called Stargate and Across.

Two days before the attack, the address approved and deposited funds into Moonwell contracts. The funds have remained as DAI since being converted and have not moved since.

Moonwell's response and MAMO's stance

Moonwell stated that borrow caps for all Core Markets on Base were set to 1 wei. A wei is the smallest unit of Ethereum, equal to one quintillionth of an ETH. This effectively stops any new borrowing.

Supply caps for MAMO and WELL were also set to 1 wei, preventing new deposits of those tokens.

Mamo, the project behind the token, said its own contracts were not hacked. Depositors may face temporary withdrawal issues for USDC if liquidity does not return, but ETH and cbBTC remain available. Funds routed through Morpho on Base were unaffected.

This marks the second pricing failure this year

Moonwell experienced another collateral-pricing error earlier this year involving cbETH. A Chainlink oracle wrapper caused the protocol to price cbETH at $1.12 instead of its actual value of roughly $2,200. Liquidators took advantage of the error, resulting in $1.78 million in bad debt.

Contributors caught that error within four minutes, but fixing the oracle required a five-day governance vote. Remediation for affected suppliers is still unresolved.

Market impact and broader context

The WELL token fell about 4% to $0.0035 in the 24 hours following the incident. Moonwell's lending capacity currently sits idle due to the zero borrow caps.

Three days before the attack, Moonwell had discussed expanding its collateral menu to include tokenized stocks. Coinbase launched tokenized stocks on Base on August 24, just days after the exploit.

Oracle and collateral-pricing attacks have impacted several lending protocols this cycle. Bonzo Lend lost $9 million to a Supra exploit on Hedera, and Ostium suffered an $18 million vault drain.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!