TLDR
- An attacker manipulated the price of the illiquid MAMO token to borrow real cbBTC from Moonwell’s lending market on Base
- Security firms CertiK and PeckShield both estimated losses at around $8.7 million
- Stolen funds were consolidated into DAI stablecoin at a single address
- Moonwell set borrow caps to 1 wei across all Base Core Markets to stop further damage
- Moonwell’s WELL token dropped 13% and MAMO fell 9% following the incident
Decentralized lending protocol Moonwell suffered an exploit on August 27 that drained around $8.7 million from its MAMO Core Market on the Base network.
MOONWELL EXPLOITED FOR ~$8.7M@MoonwellDeFi was exploited on Base, with losses estimated at around $8.7M.
WHAT HAPPENED?
The attacker manipulated the price of $MAMO, an illiquid collateral asset, artificially inflating its borrowing power.
Assets reportedly drained included… pic.twitter.com/LD55KEUuL9— Crypto Patel (@CryptoPatel) August 28, 2026
Security firms CertiK, PeckShield, and Blockaid all identified the same attack method. The attacker manipulated the collateral price of MAMO, a relatively illiquid token, to inflate its value.
With the inflated collateral, the attacker borrowed real cbBTC from Moonwell’s mCBTC market. Blockaid initially flagged that 50.6 cbBTC worth over $4 million had been drained before PeckShield put the final total at roughly $8.7 million.
The stolen funds were moved into DAI stablecoin and consolidated at a single wallet address.
Moonwell’s Response
Moonwell moved quickly to limit further damage. The protocol set borrow caps for all Core Markets on Base to 1 wei, effectively stopping all new borrowing.
Supply caps for both MAMO and WELL tokens were also reduced to 1 wei. Supply limits for other assets on the platform were left unchanged.
Moonwell said it would release more information as its investigation continued. The protocol has not yet published a full post-mortem or confirmed whether any funds can be recovered.
MAMO’s token price had a history of sharp swings before this incident. It hit an all-time high of $0.227 before losing nearly 20% after its Coinbase debut in August 2025.

Following the exploit, Moonwell’s WELL token fell around 13% in 24 hours. MAMO dropped roughly 9% over the same period.
A Pattern of Security Issues
This is not Moonwell’s first security problem in 2026. In February, an oracle error mispriced Coinbase Wrapped ETH at around $1.12 when it was trading near $2,200, leaving the protocol with about $1.78 million in bad debt.
That faulty oracle reportedly included code generated using Anthropic’s Claude Opus 4.6 model, with an incorrect scaling factor causing the pricing error.
In March, an attacker spent around $1,800 on MFAM tokens to push a malicious governance proposal through quorum on Moonwell’s Moonriver deployment. The proposal targeted seven lending markets and put around $1.08 million at risk before an emergency multisig mechanism blocked it.
The August 27 exploit sits within a broader period of elevated DeFi losses. By April 18, crypto protocols had lost more than $606 million across at least 12 incidents during that month alone.
The largest single incident was the $292 million Kelp DAO exploit, linked to North Korea’s Lazarus Group. Binance Research later said April’s exploits contributed to around $13 billion in total value locked outflows from on-chain protocols.
Moonwell said its investigation into the MAMO Core Market exploit remains active.







