Moonwell suspends lending due to a MAMO collateral price manipulation attack
Moonwell has currently suspended lending in its core markets on the Base Chain. Previously, the decentralized lending agreement lost approximately US$8.7 million due to a MAMO collateral price manipulation attack.
Summary of the incident
Moonwell restricted new lending in Base's core market due to the manipulation of MAMO collateral prices, resulting in the theft of approximately US$8.7 million. According to CertiK analysis, the attacker manipulated the collateral price of the illiquid MAMO token and subsequently lent real cbBTC from Moonwell's mCBTC market. Moonwell lowered its borrowing caps to 1 wei for all Base core markets, while also lowered its supply caps to 1 wei for MAMO and WELL to accommodate the incident investigation.
PeckShield estimated the damage at approximately US$8.7 million and noted that the attackers had consolidated the stolen funds into a DAI and stored them at a single address.
Official response and investigation progress
Moonwell announced on the social platform on August 27 that it was investigating issues affecting MAMO's core markets and had lowered the borrowing caps for all core markets on the Base chain to 1 wei as a precautionary measure. This means that users cannot open new borrowing positions during the investigation period.
Moonwell said: "As a precautionary measure, borrowing caps have been set at 1 wei for all core markets on the Base chain to prevent new borrowing and limit potential impacts." The agreement also pointed out that the supply caps of MAMO and WELL have also been reduced to 1 wei, while the supply limits of other assets remain unchanged. Moonwell promises to provide further updates as more information becomes available.
Blockchain security companies PeckShield and CertiK each estimated that the amount stolen was approximately $8.7 million. Blockaid traced the attack to the manipulation of the price of MAMO token collateral.
Attack method: Use the price of MAMO collateral to steal cbBTC
According to CertiK analysis, the attacker manipulated the collateral value of the less liquid MAMO token, and then used the falsely high collateral to lend real cbBTC from Moonwell's mCBTC market. Blockaid confirmed the same mechanism and initially reported that more than 50.6 cbBTC (worth more than $4 million) were found stolen during monitoring transactions. PeckShield then estimated the total damage at about $8.7 million and said the attackers had consolidated the proceeds into DAI, stored at a single address.
The security firm pointed out that the use of thinly traded assets as collateral was at the heart of the attack. By changing the market price of MAMO, attackers can raise the valuation of collateral positions and borrow more liquid assets.
MAMO has experienced sharp price fluctuations before. The token fell after launching Coinbase in August 2025, after rising more than 120% in the previous week. At the time, reports pointed out that MAMO had reached an all-time high of $0.227, and then fell nearly 20% due to increased selling activity.
MAMO prices are under pressure again after Thursday's security incident. According to data, Moonwell's WELL token has dropped by approximately 13% in the past 24 hours, while MAMO has dropped by approximately 9% over the same period.
The restrictions implemented by Moonwell cover lending functions in all core markets on its Base chain, not just incident markets. During the team's investigation, existing supply caps for assets other than MAMO and WELL remained unchanged.
Moonwell has previously encountered oracle and governance issues
Thursday's incident is one of a series of security issues Moonwell will encounter in 2026. Previously, a pricing error caused about $1.78 million in bad debts in its lending market.
In February, a oracle error caused Coinbase Wrapped ETH (cbETH) to be priced at approximately $1.12, while the asset was trading at nearly $2200. According to the agreement disclosure, this mispricing allowed liquidators and automated robots to repay positions at distorted valuations and seize cbETH collateral. The oracle logic error reportedly contained code generated using Anthropic's Claude Opus 4.6 model. Moonwell said at the time that an error in the scaling factor in the calculation caused a huge difference between the oracle value and the market price.
The following month, another security issue surfaced: An unknown party purchased approximately $1800 in MFAM tokens and used them to force malicious governance proposals in the Moonriver deployment. The proposal seeks to control seven lending markets, Moonwell's controllers and its oracle through contracts controlled by attackers, putting approximately $1.08 million in assets at risk. Moonwell's Break Glass Guardian multi-signature mechanism provided an emergency mechanism to block a proposal before it was implemented, and subsequent votes rejected the proposal.
Unlike the pricing glitch in February, the security company that evaluated the August 27 incident described the attack as an active manipulation of the market price used for MAMO collateral. Moonwell has not released a detailed post-mortem analysis report to determine the specific contracts, oracle structures or transaction sequences involved.
DeFi attacks have continued to be high since April
The Moonwell attack followed a series of major DeFi attacks in the second quarter of 2026. Among them, April became one of the months with the worst losses throughout the year. CertiK warned in April that AI abuse and infrastructure vulnerabilities are becoming an important part of cryptocurrency security risks. The company said attackers are taking advantage of social engineering, infrastructure vulnerabilities and more advanced automated tools, including AI-assisted phishing, deep counterfeiting and attack techniques.
According to relevant data, as of April 18, the cryptocurrency agreement had lost more than US$606 million in at least 12 incidents that month. This total has exceeded the total loss in the first quarter of 2026.
Kelp DAO is one of the largest events. On April 18, attackers stole approximately 116,500 rsETH, worth approximately $292 million, from its cross-chain setting. LayerZero later stated that the Kelp DAO attack involved a breach of the RPC infrastructure used by its decentralized verifier network and affected the Kelp DAO's single DVN rsETH configuration. The company said preliminary evidence points to a North Korea-related TraderTraitor organization that is linked to the Lazarus Group.
The incident also affected the lending market that holds rsETH. Aave suffered massive withdrawals and left behind a large number of bad debts after the stolen rsETH was used as collateral to borrow other assets. SparkLend and Fluid limit the affected markets.
In June, the Binance Research Institute stated that the DeFi attack in April resulted in an outflow of approximately US$13 billion in the total locked value of on-chain agreements. Its May market report showed that DeFi TVL was US$82.7 billion at the end of April, down 10.7% from the previous month, while attack losses totaled US$635.24 million that month.
Moonwell has not disclosed whether the $8.7 million valuation is the final loss from its MAMO core market event, nor has it said whether any affected assets can be recovered. The agreement said the investigation is still ongoing and a further announcement will be issued when more information becomes available.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following