BlockBriefe
Defi

Moonwell DeFi Protocol Loses $8.7 Million in Base Chain Exploit

Nathan Brooks 27.08.2026

How the Price Manipulation Worked

On Thursday, the multichain lending and borrowing platform Moonwell suffered a security breach on the Base network, resulting in the loss of approximately $8.7 million. CertiK identified the attack as involving manipulation of the MAMO token’s price to drain funds from the protocol’s collateral system. The exploit targeted Moonwell’s largest deployment by total value locked, raising immediate concerns about the safety of assets on the Base chain.

The breach occurred when attackers exploited a vulnerability in how Moonwell priced MAMO collateral, allowing them to inflate the token’s value artificially and borrow against it at unfair rates. This manipulation enabled the withdrawal of significant assets without sufficient backing. Moonwell, which operates across several blockchain networks, has concentrated much of its activity on Base, making this chain a critical point of failure. The incident underscores ongoing risks in decentralized finance, particularly around oracle reliability and collateral valuation mechanisms.

Could This Have Been Prevented with Better Oracle Design?

Attackers took advantage of a flaw in Moonwell’s pricing oracle for MAMO, a token used as collateral within the protocol. By temporarily distorting the market price of MAMO, they were able to trick the system into believing their collateral was worth more than it actually was. This allowed them to borrow larger amounts of other assets against insufficient collateral, effectively siphoning funds from the lending pool. CertiK’s analysis confirmed that the exploit relied on this specific vector, highlighting a gap in Moonwell’s risk management for low-liquidity assets.

Experts suggest that more robust oracle solutions, such as time-weighted average prices or multi-source feeds, might have mitigated the attack. Moonwell has not yet issued a detailed technical post-mortem, but the incident has prompted calls for stricter collateral requirements and improved monitoring of anomalous price movements. The protocol has paused affected markets on Base while investigating the breach and working with security firms to trace the stolen funds. Users are advised to avoid interacting with compromised contracts until further notice.

What is MAMO and why was it targeted? MAMO is a collateral token used within Moonwell’s lending system on Base. Attackers focused on it because its price could be manipulated due to relatively low liquidity, allowing them to inflate its value and extract excessive loans.

Frequently Asked Questions

Is Moonwell still operational on other chains? Yes, Moonwell continues to operate on other networks including Ethereum and Polygon. The exploit was isolated to the Base chain deployment, and other chains remain unaffected according to the protocol’s initial assessment.

Will users be reimbursed for their losses? Moonwell has not announced any compensation plan at this time. The team is focusing on investigation, mitigation, and coordination with exchanges and blockchain analysts to recover the stolen assets.

Share:

More stories: