Moonwell, a lending protocol on Base, suffered an $8.7 million exploit on Aug. 27 after an attacker manipulated the price of MAMO, a thinly-traded collateral asset, according to security firm CertiK.
The attacker acquired a large MAMO position and executed trades that drove the token's price from $0.01 to $0.43 by 09:35 AM UTC, exploiting thin liquidity and oracle dependency. With MAMO artificially inflated, the attacker deposited it as collateral on Moonwell, gaining borrowing power that far exceeded the token's actual market depth.
On-chain data from Basescan showed withdrawals of over 50 cbBTC, millions in USDC, wstETH, and ETH. The attacker amplified the position by transferring MAMO directly into market contracts, increasing mToken exchange rates. When liquidity in certain markets dried up—including AERO—the attack ended. The stolen funds were moved to Ethereum address 0xD71d…C384 and converted to DAI.
Moonwell immediately set borrow caps to 1 wei across all Core Markets on Base, halting new borrowing. Supply caps for MAMO and WELL were similarly restricted to 1 wei. The team said it was investigating and would provide updates.
Liquidators recovered part of the position, but material bad debt remains. Both CertiK and PeckShield estimated total losses at $8.7 million.
The exploit mirrors prior oracle failures at Moonwell. In late 2025, a misconfigured oracle briefly priced Coinbase Wrapped ETH (cbETH) at $1, triggering $1.8 million in bad debt.
