• Moonwell’s Base lending market suffered an exploit that drained more than $9 million.

  • The attacker pushed MAMO’s price nearly eight times higher through market manipulation.

  • The attacker borrowed cbBTC, USDC, wstETH and ETH from Moonwell markets.

Moonwell’s DeFi lending protocol has been hit by an exploit that drained more than $9 million in real crypto assets. The attacker manipulated MAMO’s price, used the inflated token value as collateral, and borrowed cbBTC, USDC, wstETH, and ETH from the platform.
While, the Moonwell project has yet to give a full official update.

How Did the Moonwell Attack Happen?

According to blockchain security firm CertiK, the attacker manipulated the price of MAMO, which was accepted as collateral on Moonwell.

The token’s price was pushed from around $0.0105 to $0.088, an increase of nearly eight times. This made the attacker’s MAMO holdings appear far more valuable than their real market value.

The attacker then used this inflated collateral to borrow real assets from Moonwell, including cbBTC, USDC, wstETH, and ETH.

The problem was not a direct attack on Moonwell’s code. Instead, the attacker took advantage of a price oracle that could be moved by trading activity in the thin MAMO market.

Over $9M in Real Assets Drained

The attack quickly turned the inflated MAMO value into real funds. CertiK reported that around $8.7 million had already been drained, while other tracking showed the total loss had passed $9 million.

Blockchain monitoring firm ExVul SkyEye reported that the largest single transaction moved 14.34 cbBTC, worth about $1.15 million.

This shows the main risk, the attacker used an artificially high token price to take out assets that had real market value.

Moonwell’s Past Hack Adds to Security Concerns

This is not the first security issue Moonwell has faced. On February 18, 2026, Moonwell faced a major security incident after a faulty smart contract caused a huge pricing error on Base.Â

The issue came from MIP-X43, a governance proposal that enabled Chainlink Oracle Extractable Value (OEV) wrapper contracts. The contract, partly written with Anthropic’s Claude AI, missed an important calculation step. This caused cbETH, worth around $2,200, to be priced at just $1.12.

The incident left Moonwell with around $1.78 million in bad debt, raising fresh concerns about smart contract security.

Moonwell Yet to Give Full Update

Moonwell has not yet released a full official explanation of the incident or confirmed the final amount lost.

Meanwhile, Moonwell’s native token is down 3%, trading at around $0.003407.

Was this writing helpful?

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.