Moonwell suffered an exploit on Wednesday after an attacker manipulated the price of MAMO on its Base lending market and used the inflated collateral to borrow real assets that it never repaid. The losses are estimated to be in the range of about $4 million to $9 million.
The attack drained cbBTC, USDC, wstETH, and ETH out of real depositor liquidity. Moonwell, a decentralized lending protocol, has suffered its third security incident in nine months. An attacker manipulated the price of the illiquid MAMO token on Moonwell’s Base lending market, driving its value up about eightfold from around $0.0105 to nearly $0.088 and allowing them to borrow real crypto assets like cbBTC, USDC, wstETH, and ETH against inflated collateral that was never repaid.
Moonwell suffers its third incident in nine months
The security firm ExVul says the attacker spent about $7 million buying MAMO to force the price up, then sold roughly $3.2 million of it back, taking a loss of close to $3.8 million on the token trades alone. The loss was a calculated cost that let the attacker borrow around $10 million in real assets from Moonwell, leaving a net haul of roughly $6 million. The Blockaid security firm first flagged suspicious activity against the mCBTC market, reporting an initial drain of 50.6 cbBTC, worth over $4 million.
The attacker’s wallet then moved most of the stolen funds, holding just over $4,600 hours later. Because the exploit was still unfolding, loss estimates shifted in real time. Blockaid’s early estimate was just over $4 million, the lowest figure, while ExVul put the loss at roughly 71.36 cbBTC, worth about $5.7 million. CertiK said the attacker’s address had collected close to $8.7 million, while others reported that $9 million had already been drained.
Meanwhile, the native governance token of Moonwell, WELL, initially spiked about 25% but later corrected downward by roughly 13% to around $0.0032. The company has about $72.77 million in total value locked, according to DeFiLlama, making the attack a significant blow to both the protocol and depositors. The Moonwell team acted quickly after the attack, cutting the MAMO market’s borrowing limit to the smallest possible amount (1 wei). The move basically stopped anyone from borrowing more against that token.
They also lowered the supply limits for both MAMO and WELL. The attack is currently under investigation. Before this incident, Moonwell had suffered two oracle-related failures. The first occurred in November 2025, when a spot-price manipulation classified as oracle manipulation occurred. On February 15, 2026, a separate $1.78 million bad-debt event occurred due to a misconfigured cbETH oracle that reported the asset at about $1.12 instead of roughly $2,200. The second incident drew more attention because the relevant code changes listed Anthropic’s Claude Opus 4.6 as a commit co-author, and that sparked a debate over AI-assisted “vibe coding” in DeFi.

