Highlights

  • The attacker's technique relied on thin liquidity in the MAMO token, not a smart-contract bug in Moonwell's core code.
  • Inflating MAMO's on-chain price let the attacker borrow cbBTC, USDC and DAI worth far more than any real collateral posted.
  • This is the third distinct oracle-related exploit against Moonwell in under a year, following incidents in November 2025 and earlier this year.
  • The pattern points to a structural weakness in how Base lending markets price newly listed, thinly traded collateral.

The $8.7 million drained from Moonwell's Base lending market on August 27 wasn't the result of a broken smart contract — it was a pricing problem. Crypto Banter's breakdown, drawing on monitoring from CertiK and Blockaid, describes an attacker who inflated the price of MAMO, a relatively illiquid token accepted as collateral on Moonwell, and then borrowed real, liquid assets against the artificially propped-up position. Because MAMO trades in thin markets, moving its reported price required comparatively little capital — and once the oracle reflected that inflated price, Moonwell's lending logic treated the attacker as safely overcollateralized.

MAMO Price Manipulation Exposes a Recurring Flaw in Base Lending Markets
Image via @crypto_banter on X

A Familiar Attack Shape

Price-oracle manipulation is one of the oldest exploit patterns in DeFi, but it keeps working because it targets an economic assumption rather than a coding error: that an on-chain price feed accurately reflects an asset's real, deep-market value. When a collateral asset has low liquidity, a well-capitalized attacker can move its spot price sharply with a single large trade or a flash loan, then immediately borrow against the inflated valuation before the price mean-reverts. PANews's earlier report, citing Blockaid, put the first-detected leg of the attack at roughly 50.6 cbBTC — about $4 million — before PeckShield's later tally brought the confirmed total to $8.7 million as additional borrows against the same manipulated MAMO position surfaced.

Moonwell's Third Strike

What distinguishes this incident is that it's not Moonwell's first brush with oracle risk. In November 2025, an attacker abused a faulty wstETH/wrsETH price feed that erroneously valued a flash-loaned deposit at $5.8 million, walking away with roughly 295 ETH in profit. Separately, a governance proposal misconfigured a cbETH oracle to price the asset at $1.12 instead of its real value near $2,200, costing the protocol $1.78 million. Three separate collateral-pricing failures in under a year, each involving a different asset and a different specific mechanism, suggests the protocol's oracle and asset-listing review process hasn't kept pace with how quickly new, thinly traded tokens get approved as loan collateral on Base.

Related: Core Lightning Tells Node Operators to Patch or Go Offline After AI-Found Bugs

Why Base Lending Markets Keep Getting Hit

Base has drawn a wave of new token launches and DeFi activity over the past year, and lending protocols competing for that volume face pressure to list new collateral assets quickly to capture yield-seeking deposits. That competitive dynamic cuts directly against the caution oracle security requires: a newly launched token like MAMO may not have the trading depth across enough venues for a time-weighted or multi-source oracle to resist manipulation, yet listing it as collateral can be a meaningful growth driver for a protocol chasing TVL. Until Base-native lending markets adopt stricter collateral-listing standards — deeper minimum liquidity thresholds, borrow caps scaled to real market depth, or mandatory circuit breakers on rapid price moves — thinly traded collateral will remain the softest target on the chain.

What to Watch

The immediate question is whether Moonwell publishes a technical post-mortem naming the exact oracle configuration that was exploited, as it did after the wstETH/wrsETH incident. Longer term, watch whether Base's other lending protocols — several of which share similar collateral-listing practices — move preemptively to tighten oracle requirements for illiquid tokens before they become the next target, and whether the attacker's DAI wallet shows any movement toward a bridge or mixer in the coming days.