Moonwell Halts Borrowing on Base After MAMO Collateral Manipulation Drains 8.7 Million USD
Decentralized lending protocol Moonwell has frozen new borrowing across its Core Markets on Base after an apparent collateral price manipulation attack targeting the MAMO token drained roughly 8.7 million USD from the platform. The incident, first flagged on August 27, marks the second significant security event to hit the protocol this year and has reignited the industry debate over using thinly traded tokens as loan collateral.
The attack unfolded with surgical simplicity, according to blockchain security firms that examined the transactions. CertiK said the attacker manipulated the market price of MAMO, a relatively illiquid token, to inflate the value assigned to a collateral position. With the inflated collateral registered on the protocol, the attacker then borrowed real assets with deep liquidity — cbBTC, Coinbase’s wrapped Bitcoin — from Moonwell’s mCBTC market. In effect, the attacker used a token they could cheaply reprice on a thin market as a ticket to withdraw harder currency.
Blockaid, which monitored the attack in real time, identified the same mechanism and initially reported that roughly 50.6 cbBTC worth more than 4 million USD had been drained while the transactions were still being traced. PeckShield later put total losses at approximately 8.7 million USD and said the attacker had consolidated the stolen proceeds into DAI at a single address, a common technique that simplifies fund movement and complicates tracking.
Protocol response: caps slashed to 1 wei
Moonwell moved quickly to contain the damage. In a post on X, the protocol confirmed it was investigating an issue affecting the MAMO Core Market and said borrow caps for all Core Markets on Base had been set to 1 wei — the smallest possible unit on the network — effectively preventing any new borrowing positions from being opened while the investigation continues.
Supply caps for MAMO and the protocol’s native WELL token were also cut to 1 wei, halting new deposits of the two tokens. Supply limits for other assets on the platform were left unchanged, a signal that the team believes the vulnerability is confined to the manipulation vector around MAMO collateral rather than a broader flaw in the lending engine itself. Moonwell said it would publish further updates as its investigation progresses.
Markets reacted swiftly to the incident. Moonwell’s WELL token fell about 13 percent over the 24 hours following the exploit, according to CoinGecko data cited in initial reports, while MAMO dropped roughly 9 percent over the same period, per DEX Screener. The sell pressure is the latest chapter in MAMO’s volatile trading history — the token surged more than 120 percent in the week before its Coinbase listing in August 2025, reaching an all-time high of 0.227 USD before shedding nearly 20 percent as sellers took over.
A pattern of pricing failures
Thursday’s exploit is not an isolated event for Moonwell. Earlier in 2026, a pricing failure left the protocol’s lending markets with approximately 1.78 million USD in bad debt. In February, an oracle calculation error mispriced Coinbase Wrapped ETH, or cbETH, at roughly 1.12 USD while the asset was actually trading near 2,200 USD. The distorted feed allowed liquidators and automated bots to repay positions at the artificial valuation and seize cbETH collateral at a fraction of its real worth — a mechanical failure that, like the MAMO incident, stemmed from the gap between reported prices and actual market conditions.
The two incidents share an uncomfortable theme: both exploited the protocol’s dependence on price data for assets whose true liquidity does not match their listed valuation. Whether the fault lies with oracle infrastructure, collateral listing standards, or risk parameters that allowed a thin token to back meaningful borrowing, the outcome for users is the same — bad debt, frozen markets, and eroded confidence.
The collateral quality question
The Moonwell attack is the latest in a long line of exploits centered on low-liquidity collateral. Attackers have repeatedly demonstrated that when a token’s price can be moved cheaply on a decentralized exchange, any lending market that accepts it as collateral is effectively offering an exit ramp for real value. The maneuver is so well established in the attacker playbook that security researchers routinely flag newly listed, thinly traded tokens as systemic risks for the lending protocols that onboard them.
For Moonwell, the immediate priority is the investigation and a remediation plan for the 8.7 million USD hole. Historically, protocols in this position have chosen between treasury reimbursements, minting new governance tokens to cover losses, or socializing the bad debt among liquidity providers. No compensation plan had been announced at the time of writing.
The broader DeFi market will be watching how Base’s lending ecosystem responds. Base has grown into one of the most active networks for decentralized lending, and a high-profile manipulation attack on one of its flagship protocols strengthens the case for stricter collateral standards — higher borrow caps only for assets with proven depth, tighter supply limits on long-tail tokens, and oracle designs that discount prices derived from pools an attacker can cheaply sweep.
For users, the incident is a reminder that yield on lending platforms is only as secure as the weakest collateral the platform accepts. Moonwell’s rapid cap reductions may have prevented further losses, but they also froze legitimate borrowing activity across every Core Market on Base — a trade-off that illustrates how one thinly traded token can hold an entire lending suite hostage.
Moonwell had not responded to requests for additional comment at the time of publication. The protocol said further updates would be shared once its investigation into the MAMO Core Market incident is complete.
illiquid token as loan collateral, what could possibly go wrong. 8.7M gone and its the second security incident for moonwell this year lol
the wildest part is certik says the attacker basically just pumped MAMO price on a thin market and borrowed against it. not even a fancy exploit, just bad collateral listing
Second incident in one year and the lesson still hasnt landed. Protocols keep listing micro-cap collateral because the yield looks good on the dashboard. Regulators are taking notes.
moonwell let a token you could reprice on a thin dex pool back real borrowing. 8.7M gone in one afternoon and the emergency fix is caps at 1 wei. wild
and the 1 wei caps froze every core market on base, so legit borrowers are paying for the MAMO mess too
Second pricing incident this year after cbETH was quoted at 1.12 USD while trading near 2,200. At some point this stops being bad luck and becomes a collateral listing standards problem.
@Gorm the february mispricing and this are the same failure honestly. oracle says one number, the market says another, and someone arbitrages the gap
MAMO chart is a crime scene rn. anyone still holding that bag after the borrow halt, my condolences
WELL down 13 percent, MAMO down 9, and PeckShield says the attacker already consolidated into DAI at one address. Good luck with recovery.