Moonwell Lost $8.7 Million Without a Single Line of Code Being Hacked

2 hours ago 22

Lending protocol Moonwell lost an estimated $8.7 million to an exploit on Thursday. No smart contract was broken. An attacker simply made MAMO, a small Base token, look far more valuable than it is.

The inflated price let the attacker borrow real assets, including Coinbase Wrapped Bitcoin (cbBTC) and USD Coin (USDC). Security firm Blockaid caught the activity, and Moonwell froze new borrowing within hours.

How the Moonwell Exploit Worked

The trick was price, not code. Blockaid reported that the attacker manipulated MAMO collateral pricing to drain cbBTC from Moonwell’s mCBTC market. Its first estimate showed 50.6 cbBTC gone, worth more than $4 million.

Blockaid’s Exploit Detection identified suspicious activity against @MoonwellDeFi on Base.
An attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market.
Observed impact so far: 50.6 cbBTC ($4.0M+) drained
More details to follow. 🧵

— Blockaid (@blockaid_) August 27, 2026

MAMO is the token of Mamo, a yield tool built on Base. Every MAMO in existence is worth about $7.6 million combined, and the token trades near $0.011366. A market that small is cheap to pump.

 BeInCryptoMAMO Price Performance. Source: BeInCrypto

That was the whole attack. Pump MAMO on thin markets, post it as collateral at the fake price, and borrow assets with real value. Moonwell’s oracle, the system that feeds prices to the protocol, believed the pump.

Security firm PeckShield later put total losses at $8.7 million. That is more than the market value of every MAMO token. The firm said the funds now sit in the DAI stablecoin at a wallet starting with 0xD71d.

#PeckShieldAlert @MoonwellDeFi on Base has suffered an exploit, resulting in a loss of $8.7M. The stolen funds, in $DAI, are sitting in 0xD71d…C384 pic.twitter.com/YyTgIZRe3W

— PeckShieldAlert (@PeckShieldAlert) August 27, 2026

Borrow Caps Cut to One Wei as Recovery Questions Begin

Moonwell acknowledged the incident in a post, indicating that they were already working to stop the bleeding.

“We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact,” the team wrote.

One wei is the smallest unit possible. The change blocks all new loans without touching withdrawals. Supply caps for MAMO and WELL, Moonwell’s governance token, also fell to one wei.

Thursday’s exploit is not a first. Bad prices, not bad code, keep costing Moonwell money. A wrsETH oracle malfunction created around $3.7 million in bad debt in November 2025. A cbETH oracle misconfiguration added $1.78 million more in February. Pricing failures have now cost the protocol over $14 million in ten months.

The wider sector shows the same weakness. Term Labs lost roughly $8.5 million to a governance exploit on Sunday. Analysts increasingly blame economic design failures rather than broken code for DeFi’s biggest losses.

Moonwell says another update is coming. Two numbers will tell the real story. The first is the final bad debt once MAMO’s price settles. The second is how much cbBTC and USDC remains for suppliers who want out.

The post Moonwell Lost $8.7 Million Without a Single Line of Code Being Hacked appeared first on BeInCrypto.

Read Entire Article