Moonwell investigates $8.7 million Base exploit tied to MAMO price manipulation

Attack targeted lending markets after MAMO collateral value was artificially inflated
TL;DR
- Moonwell investigated an Aug. 27 exploit on Base after CertiK and PeckShield estimated losses at about $8.7 million.
- Security firms said the attacker manipulated the relatively illiquid MAMO collateral price and borrowed valuable assets from Moonwell markets.
- The episode was Moonwell’s fourth pricing-related incident in less than a year.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Moonwell investigated an exploit affecting its MAMO Core Market on Base on Aug. 27, 2026, after CertiK and PeckShield estimated losses at approximately $8.7 million and identified manipulation of the relatively illiquid MAMO token’s collateral value as the attack mechanism.

Moonwell responded by restricting activity across its Base lending markets. “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact,” Moonwell said on X. “The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged.”

Blockaid said its Exploit Detection system identified suspicious activity involving Moonwell approximately an hour after the attack began. Blockaid said: “An attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. Observed impact so far: 50.6 cbBTC ($4.0M+) drained.” Its alert was posted Aug. 27.

CertiK said the attacker manipulated MAMO’s collateral value and then borrowed real cbBTC from Moonwell’s mCBTC market. Blockaid independently identified the same apparent mechanism, while PeckShield later estimated that approximately $8.7 million had been drained and said the funds were consolidated into DAI at a single address.
Attacker reportedly spent millions pushing MAMO higher
The attack relied on increasing the market value of MAMO, a relatively illiquid token accepted as collateral on Moonwell, and borrowing other assets against the inflated valuation. The attacker reportedly spent $7 million pumping MAMO before selling the token after the attack at an estimated $3.8 million loss.
Assets borrowed during the incident included cbBTC, USDC, WETH and wstETH. After Blockaid’s initial estimate of more than $4 million in observed losses, the amount continued rising, with later estimates from CertiK and PeckShield reaching approximately $8.7 million. Another description of the incident characterized the deposits drained from Moonwell as almost $9 million.
The proceeds were swapped into DAI, characterized as a non-freezable stablecoin, and 8.7 million DAI was held at Ethereum address 0xD71dD9B6e634412713c47fe7aE02c628e338C384. The address had been funded through Tornado Cash.
WELL fell around 13% over the preceding 24 hours, while MAMO dropped roughly 9% over the same period. Moonwell said it would share further updates as more information became available.
The Aug. 27 incident occurred during a period in which multiple DeFi protocols had been hacked for more than $600 million since April 2026. That total was led by a $292 million exploit of Kelp DAO. The source material characterized the period as one of the worst stretches for DeFi exploits and suggested advances in artificial intelligence appeared to be contributing to the broader activity.
Moonwell has faced four pricing-related incidents in less than a year
The latest attack marked Moonwell’s fourth pricing-related incident in less than a year. The previous events involved a market price discrepancy, an oracle malfunction and an incorrect collateral valuation, while the Aug. 27 incident involved deliberate manipulation of MAMO’s collateral price.
The October episode occurred during the Oct. 10 market crash and resulted in liquidations as well as bad debt. The following month, fallout from the Balancer hack led to problems with Moonwell’s wrsETH/ETH oracle. February’s incident triggered sudden liquidations of positions backed by cbETH after the contract assigned the asset the wrong value.
The Aug. 27 attack differed because the attacker was reported to have deliberately moved the price of thinly traded MAMO before borrowing against the inflated collateral. Moonwell’s response focused on preventing further borrowing by reducing the relevant market caps to effectively negligible levels.
FAQ
What Moonwell market was affected?
The MAMO Core Market on Base.
Which security firms estimated the total loss?
CertiK and PeckShield each put losses at approximately $8.7 million.
Which assets were borrowed during the attack?
cbBTC, USDC, WETH and wstETH.
How did Moonwell restrict further borrowing?
It set Base Core Market borrow caps and MAMO and WELL supply caps to 1 wei.
This article has been refined and enhanced by ChatGPT.