CertiK reported Thursday that attackers drained about $8.7 million from Moonwell's lending market on Base by manipulating the price of its MAMO token collateral. Moonwell has since slashed the MAMO market's borrow cap to 1 wei, according to Crypto Briefing, freezing new borrowing while the protocol investigates.
Moonwell, a multichain DeFi lending protocol, lost about $8.7 million after an attacker manipulated the price of its MAMO token collateral on Base, blockchain security firm CertiK reported Thursday. The attacker targeted MAMO, a relatively illiquid token, then used the inflated collateral to borrow real crypto from Moonwell's markets.
According to Coinpedia, the attacker pushed MAMO's price from around $0.0105 to $0.088, an increase of nearly eight times. The inflated MAMO holdings were then deposited as collateral, letting the attacker borrow cbBTC, USDC, wstETH and ETH from Moonwell's lending markets.
A manipulated price oracle, not broken code
The exploit did not touch Moonwell's own code. Instead, the attacker took advantage of a price oracle that could be moved by trading activity in the thin MAMO market, Coinpedia reported. Crypto Briefing noted that kind of oracle manipulation is far cheaper to pull off on a low-liquidity token than on a large-cap asset like ETH or BTC.
Moonwell freezes borrowing in the MAMO market
Moonwell has reduced the borrow cap in its MAMO market to 1 wei, the smallest possible unit on Ethereum-compatible chains, effectively freezing new borrowing. The emergency move followed an attack that let the adversary borrow an estimated $10 million in assets against artificially inflated collateral, Crypto Briefing reported. Supply caps on both MAMO and Moonwell's WELL governance token were also tightened, and before the exploit the market's borrow cap stood at 3 million tokens with a 50% collateral factor.
A second security lapse this year
This is not Moonwell's first incident. On February 18, 2026, a faulty smart contract mispriced cbETH at $1.12 versus its roughly $2,200 market value, leaving the protocol with about $1.78 million in bad debt, Coinpedia reported. That earlier bug, Coinpedia reported, stemmed from a governance proposal enabling Chainlink oracle wrapper contracts.
Moonwell's WELL token spiked to $0.0045 from $0.00367 before reversing sharply to $0.0033 amid the exploit. Moonwell has not yet issued a full official update on the incident's final cost, Coinpedia reported.
Sources: Crypto Briefing, Crypto Briefing, Coinpedia Fintech News
Trading involves risk.