Moonwell is investigating a multimillion-dollar exploit of its MAMO Core Market on Base after security firms CertiK and PeckShield flagged the incident. The protocol has frozen new borrowing across its Base markets as a precaution while it works out what happened.
Attacker manipulates MAMO's collateral price
Security firm PeckShield estimated the exploit drained roughly $8.7 million, with the attacker moving the stolen funds into DAI and parking them at a single address. CertiK put the losses at the same $8.7 million figure, saying the attacker manipulated the collateral price of the relatively illiquid MAMO token, then borrowed real cbBTC from the mCBTC market to pull off the exploit. Security firm Blockaid separately identified the same apparent attack mechanism.
Moonwell responded by freezing risk parameters across its Base deployment. According to Moonwell: "borrow caps for all Core Markets on Base have been set to 1 wei", the protocol said, adding that this prevents new borrowing and limits the potential for further impact. Supply caps for MAMO and WELL were also set to 1 wei, while supply caps for all other markets remain unchanged.
WELL and MAMO tokens slide
The exploit has hit token prices tied to the protocol. Moonwell's WELL token is down around 13% over the past 24 hours, according to CoinGecko data. MAMO has fallen roughly 9% over the same period, per DEX Screener.
Part of a costly stretch for DeFi
The incident extends one of the worst periods for DeFi exploits, seemingly driven by advancements in artificial intelligence. Multiple protocols have been hacked for more than $600 million since April, led by the $292 million exploit of Kelp DAO.
Moonwell said it will share further updates as soon as more information becomes available. The protocol did not respond to a request for comment from The Block.
Source: The Block
Trading involves risk.