Highlights
- Attacker manipulated the price of illiquid MAMO collateral to borrow real assets against it on Moonwell's Base market.
- Losses climbed from an initial $4 million in cbBTC to a confirmed $8.7 million across cbBTC, USDC and DAI.
- Stolen DAI was tracked moving into a wallet beginning with 0xD71d...C384.
- Security firms CertiK, Blockaid and PeckShield jointly flagged the exploit within roughly 40 minutes of the first detected transaction.
Moonwell, a lending protocol built on Coinbase's Base network, lost $8.7 million on August 27 after an attacker exploited a pricing weakness in its MAMO collateral market. According to Crypto Banter, citing monitoring from CertiK and Blockaid, the attacker inflated the price of the relatively illiquid MAMO token, then used the artificially propped-up collateral to borrow real, liquid assets — including Coinbase-wrapped Bitcoin (cbBTC) and USDC — that the protocol otherwise had no reason to release.
The incident unfolded in two stages that were visible in real time to on-chain trackers. Blockaid's first alert, relayed by PANews, put the initial damage at just over $4 million, based on roughly 50.6 cbBTC pulled from Moonwell's mBTC market. Within about 30 minutes, PeckShield's monitoring system escalated the figure to the confirmed total of $8.7 million as further borrows against the same manipulated collateral came to light, with the stolen DAI portion traced to a wallet beginning 0xD71d...C384, per PeckShield Alert.
How the MAMO Collateral Was Weaponized
Moonwell's exploit follows a pattern that has become disturbingly familiar in Base and Optimism DeFi: a low-liquidity token gets listed as loan collateral, and its thin order book makes its on-chain price trivial to move with a comparatively small amount of capital. Once the reported value of the attacker's MAMO holdings was inflated, the protocol's lending logic treated the position as sufficiently overcollateralized to approve large borrows of blue-chip assets like cbBTC, USDC and DAI — assets with real, deep liquidity that the attacker could then move freely. Moonwell has been exploited before: a November 2025 incident abused a faulty wstETH/wrsETH oracle to net roughly 295 ETH in profit, and a separate cbETH oracle misconfiguration cost the protocol $1.78 million after a governance proposal briefly priced the asset at $1.12 instead of roughly $2,200. Collateral-pricing risk on illiquid Base-native tokens has now cost the protocol tens of millions of dollars across three separate incidents in under a year.
Related: Core Lightning Tells Node Operators to Patch or Go Offline After AI-Found Bugs
What It Means for Base DeFi
The exploit adds to a rough week for Base-based protocols and lands the same day PANews separately reported an unrelated $6.2 million theft from RWA platform Realio Network, underscoring how attackers are systematically probing newer chains' lending and custody infrastructure for weak points. For Moonwell specifically, the repeated collateral-oracle failures raise pointed questions about the protocol's asset-listing risk controls — particularly its willingness to accept newly launched, thinly traded tokens like MAMO as loan collateral without tighter price-manipulation safeguards such as time-weighted oracles or borrow caps tied to a collateral asset's actual market depth. Depositors in Moonwell's other markets are not directly at risk from this exploit, but the protocol's total value locked and its ability to attract new liquidity are likely to take a near-term hit as the DeFi community reassesses which lending markets it still trusts on Base.
What Comes Next
Moonwell has not yet published an official post-mortem or confirmed whether a bug bounty negotiation with the attacker is underway, a step several exploited Base protocols have taken this year to recover partial funds. Watch for on-chain movement out of the 0xD71d...C384 wallet — attackers who fail to negotiate typically attempt to launder funds through a cross-chain bridge or mixer within 24 to 48 hours — as well as any governance proposal from Moonwell to delist or cap MAMO as collateral, which would be the clearest signal the protocol is treating this as a structural fix rather than an isolated incident.
