Decentralized lending protocol Moonwell has temporarily restricted new borrowing across its Core Markets on Base following an apparent price manipulation attack involving the MAMO token.
Blockchain security firms estimate that the exploit resulted in losses of approximately $8.7 million. The attacker reportedly manipulated the price of MAMO, used the inflated token value as collateral, and then borrowed more liquid assets from Moonwell.
In response, Moonwell reduced borrowing limits across its Base Core Markets to effectively zero while its team investigates the incident and works to prevent additional losses.
Moonwell Halts New Borrowing on Base
Moonwell confirmed on Aug. 27 that it was investigating an issue affecting its MAMO Core Market.
As an emergency precaution, the protocol lowered borrow caps across all Core Markets on Base to just 1 wei. While technically not zero, the limit effectively prevents users from opening meaningful new borrowing positions.
Moonwell also reduced supply caps for MAMO and WELL to 1 wei. Supply limits for other supported assets remained unchanged.
The broader restrictions indicate that Moonwell is taking precautions beyond the specific MAMO market while investigators determine exactly how the exploit occurred.
Blockchain security companies PeckShield and CertiK estimated losses at approximately $8.7 million, while Blockaid linked the incident to manipulation of MAMO’s collateral price.
Moonwell has said additional information will be released as its investigation progresses.
Attacker Manipulated MAMO Collateral Price
According to early assessments from security researchers, the attack centered on the relatively low liquidity of MAMO.
CertiK said the attacker manipulated MAMO’s market price before using the artificially inflated tokens as collateral on Moonwell.
Once the collateral appeared to be worth significantly more, the attacker was reportedly able to borrow real cbBTC from Moonwell’s mCBTC market.
This type of exploit takes advantage of the difference between a manipulated collateral valuation and the actual liquidity or market value of the token.
Thinly traded assets can be particularly vulnerable because relatively small amounts of capital may cause significant price movements. If a lending protocol relies on that manipulated price when calculating borrowing power, an attacker may be able to obtain valuable assets against collateral that is actually worth much less.
Blockaid initially identified approximately 50.6 cbBTC, worth more than $4 million, leaving the protocol during the attack.
PeckShield later increased the estimated total loss to around $8.7 million and reported that the attacker consolidated the stolen assets into DAI at a single address.
MAMO and WELL Prices Fall After Exploit
The security incident also put pressure on tokens connected to the Moonwell ecosystem.
WELL dropped approximately 13% over the preceding 24 hours, while MAMO declined roughly 9% during the same period, according to market data cited in the original report.
MAMO was already known for significant price volatility.
Following its Coinbase debut in August 2025, the token experienced a sharp correction after previously gaining more than 120% in a week. MAMO had reached an all-time high near $0.227 before falling almost 20% as selling pressure increased.
The token’s relatively limited liquidity has now become particularly important because security researchers believe its price was manipulated to increase the value of collateral used on Moonwell.
Moonwell Has Faced Previous Oracle Problems
The MAMO incident is not Moonwell’s first major security-related problem in 2026.
In February, an oracle calculation error incorrectly priced Coinbase Wrapped ETH, or cbETH, at approximately $1.12 when its actual market price was close to $2,200.
The dramatic pricing error allowed liquidators and automated bots to repay positions using the incorrect valuation and seize cbETH collateral.
The incident ultimately left Moonwell’s lending markets with approximately $1.78 million in bad debt.
According to Moonwell’s disclosure at the time, the faulty oracle calculation contained an incorrect scaling factor. Code generated with Anthropic’s Claude Opus 4.6 model was reportedly involved in the oracle logic.
The February incident highlights how heavily decentralized lending platforms depend on accurate and manipulation-resistant pricing systems.
However, the latest MAMO exploit appears to be different.
Rather than a simple calculation error, security researchers believe the Aug. 27 attack involved deliberately manipulating the market price being used to value MAMO collateral.
Moonwell has not yet released a complete post-mortem detailing the oracle configuration, affected smart contracts, or exact transaction sequence.
Governance Attack Also Targeted Moonwell
Moonwell faced another security concern in March when an unknown party acquired approximately $1,800 worth of MFAM tokens and used them to support a malicious governance proposal on the protocol’s Moonriver deployment.
The proposal attempted to gain control over seven lending markets as well as Moonwell’s comptroller and oracle infrastructure through an attacker-controlled contract.
Approximately $1.08 million in assets could have been placed at risk if the proposal had been successfully executed.
Moonwell’s Break Glass Guardian multisig provided an emergency protection mechanism, while subsequent governance votes moved against the proposal.
Taken together, the oracle failure, governance attack, and latest MAMO exploit highlight several different types of risks facing decentralized lending platforms.
DeFi Security Threats Remain Elevated
Moonwell’s latest exploit comes during another difficult year for decentralized finance security.
Crypto protocols suffered hundreds of millions of dollars in losses during April alone, with more than $606 million reportedly stolen across at least 12 incidents by April 18.
That figure had already exceeded total exploit losses recorded during the entire first quarter of 2026.
One of the biggest attacks involved Kelp DAO, where attackers drained approximately 116,500 rsETH valued at around $292 million from its cross-chain infrastructure.
LayerZero later said compromised RPC infrastructure associated with its decentralized verifier network played a role in the incident. Preliminary evidence reportedly pointed toward North Korea-linked TraderTraitor, which has been associated with the Lazarus Group.
The Kelp DAO incident also demonstrated how an exploit can spread risk across interconnected DeFi protocols.
Stolen rsETH was used as collateral to borrow other assets, contributing to problems in lending markets. Aave faced large withdrawals and bad debt, while SparkLend and Fluid restricted affected markets.
This interconnectedness remains one of the major challenges in DeFi. A weakness involving one token, oracle, bridge, or liquidity source can potentially create losses across several protocols.
AI and Infrastructure Risks Add to DeFi Security Concerns
Security researchers have also warned that attackers are becoming more sophisticated.
CertiK previously highlighted AI misuse and infrastructure vulnerabilities as growing areas of concern for the crypto industry in 2026.
Attackers are increasingly combining traditional smart-contract vulnerabilities with social engineering, compromised infrastructure, automated tools, phishing campaigns, and AI-assisted techniques.
At the end of April, DeFi total value locked stood at approximately $82.7 billion, representing a 10.7% monthly decline, according to figures cited by Binance Research.
Exploit-related losses during April were estimated at approximately $635.24 million.
Events such as the Moonwell MAMO exploit reinforce the importance of robust oracle systems, conservative collateral parameters, liquidity monitoring, and emergency controls for decentralized lending platforms.
Moonwell Investigation Remains Ongoing
Moonwell has not yet confirmed whether the estimated $8.7 million represents the final amount lost in the MAMO exploit.
It also remains unclear whether any portion of the stolen assets can be frozen, recovered, or returned.
For now, the protocol’s decision to reduce Base Core Market borrowing caps to 1 wei effectively blocks new borrowing while investigators assess the damage.
The MAMO and WELL supply restrictions provide another layer of protection against additional activity involving the affected assets.
A detailed post-mortem will be important for determining exactly how the attacker manipulated MAMO’s collateral value and whether Moonwell’s oracle design, collateral parameters, liquidity assumptions, or other safeguards contributed to the exploit.
Until that investigation is complete, the incident serves as another reminder that collateral pricing remains one of the most critical security components of decentralized lending markets.










































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































