Blockchain AcademicsBlockchain Academics
Moonwell Loses $8.7M on Base After Attacker Inflates MAMO Oracle Price

Moonwell Loses $8.7M on Base After Attacker Inflates MAMO Oracle Price

An oracle manipulation attack drained $8.7 million from Moonwell's lending protocol on Base network, with the attacker using an artificially inflated low-liquidity token as collateral to borrow higher-value assets. WELL token fell 13% following the announcement.

Blockchain Academics NewsroomEdited by Wael RajabAugust 28, 20263 min read
Share

Moonwell Loses $8.7M on Base After Attacker Inflates MAMO Oracle Price

An oracle manipulation attack drained $8.7 million from Moonwell's lending protocol on Base network this week, with the attacker using an artificially inflated low-liquidity token as collateral to borrow higher-value assets before converting them to stablecoin and withdrawing.

The exploit targeted MAMO, a thinly traded token whose price oracle proved vulnerable to manipulation. By inflating MAMO's reported price, the attacker unlocked borrowing capacity far beyond what the token's actual market value would support. The borrowed assets, which included cbBTC (Coinbase-wrapped Bitcoin), were then converted to DAI and withdrawn. The mechanics follow a well-worn DeFi attack pattern: find a weak oracle attached to an illiquid collateral token, pump the reported price, borrow against the inflated value, and exit before the protocol can respond.

Moonwell moved quickly once the exploit was detected. The team halted all borrowing on Base and reduced borrow caps across every core market to 1 wei, effectively freezing new borrowing at the protocol level. One wei is the smallest denomination of ether, making it a functional zero. The emergency measure prevented further extraction and, according to the team, automated safeguards protected remaining user funds from additional exposure. The response mirrors incident management playbooks used after previous DeFi oracle exploits, though the $8.7 million loss had already cleared the protocol before those controls engaged.

WELL, Moonwell's native governance token, fell 13% following news of the attack. The percentage decline was consistent across on-chain data and public announcements.

Oracle manipulation has been one of DeFi's most persistent structural weaknesses since the sector's early growth phase. Lending protocols that accept low-liquidity tokens as collateral create a straightforward attack surface: thin order books mean small capital can move a spot price dramatically, and if that spot price feeds directly into a protocol's collateral valuation, the protocol effectively prices collateral at whatever an attacker is willing to temporarily pay. The Moonwell incident fits that template precisely. The MAMO token's low liquidity was not an edge case the attacker discovered; it was the attack vector itself.

The broader question for Moonwell and protocols like it is collateral quality. The emergency borrow cap reduction demonstrates that on-chain safeguards can limit damage once an exploit is live, but those controls offer no protection during the window between manipulation and detection. Stricter listing criteria for accepted collateral tokens, time-weighted average price oracles (TWAPs) that resist single-block manipulation, and circuit breakers that trigger on anomalous price movements are among the standard mitigations the industry has developed in response to exactly this class of attack. Whether Moonwell's collateral risk framework adequately screened for MAMO's liquidity profile before listing it will likely be central to any post-mortem.

Base, Coinbase's Ethereum Layer 2 network, has attracted significant DeFi activity since its launch, and Moonwell has been one of the more active lending protocols deployed there. The network's relative youth means the security tooling and oracle infrastructure surrounding it is still maturing compared to mainnet Ethereum, where years of exploits have driven more rigorous collateral standards at major protocols like Aave and Compound. That gap represents ongoing risk for protocols deploying on newer chains.

Moonwell has not yet published a full post-mortem or outlined remediation steps beyond the emergency borrow cap reduction. The protocol's ability to recover user confidence will depend heavily on what that review reveals about how MAMO was listed as collateral and what changes are made to prevent a similar attack on the next thinly traded token in its collateral registry.

Discussion

Loading comments...