Moonwell Protocol Exploited for $8.7M via MAMO Manipulation on Base

Topics: blockchain · Difficulty: intermediar

Attila Kiraly — Strateg AI & Educator · · 3 min read

Reprezentare grafică a unui lanț digital rupt, simbolizând o breșă de securitate în protocolul blockchain.

Originally published: August 27, 2026

Lending protocol Moonwell lost $8.7 million following a price manipulation attack involving the MAMO token on the Base network. The protocol responded by slashing borrow caps to 1 wei across all core markets to mitigate further risks.

What happened

Moonwell, a prominent decentralized lending protocol on the Base network, suffered a significant exploit resulting in the loss of approximately $8.7 million. The attack involved the price manipulation of a low-liquidity token called MAMO. The exploiter managed to artificially inflate MAMO's price, using it as collateral to borrow more stable and valuable assets from Moonwell’s core markets. Once the loans were secured, the attacker drained the liquidity, leaving the protocol with bad debt. In an immediate response to contain the damage, Moonwell’s contributors paused borrowing by setting borrow caps to 1 wei across all core markets on the Base chain.

Technology context

Lending protocols like Moonwell rely on a system of over-collateralization. To borrow funds, a user must deposit an asset of greater value than the amount they wish to take out. The protocol uses "price oracles" to determine how much a user can borrow based on their deposit. The vulnerability here lies in "thinly traded" assets. Because MAMO had very little trading volume, the attacker could easily move its price upward on decentralized exchanges. The lending protocol’s oracle then reported this inflated price, allowing the attacker to borrow millions of dollars against a collateral that was worth far less in a real-market liquidation scenario.

Why it matters

This incident is a stark reminder of the risks associated with "long-tail" assets in DeFi. When a protocol lists tokens with low liquidity, it opens a back door for price manipulation attacks. For the broader Web3 ecosystem, this highlights that even on high-growth networks like Base, the fundamental principles of risk management—such as strictly limiting the use of volatile, low-cap tokens as collateral—cannot be ignored. It also impacts user trust in automated market-making and lending systems that may not have sufficient safeguards against flash-pump schemes.

Key terms explained

Impact

In the short term, Moonwell must manage the $8.7 million shortfall and restore confidence among its liquidity providers. While the protocol is still functional for withdrawals, the emergency halt on borrowing disrupts the platform's core utility. In the medium term, we will likely see a wave of de-listing or stricter risk parameters for similar low-liquidity tokens across the entire DeFi landscape. Protocols may become more conservative, potentially reducing the yield opportunities for users as they prioritize security over asset diversity.

What's next

Expect Moonwell to undergo a rigorous post-mortem analysis and potentially implement new security layers, such as decentralized risk managers (like Gauntlet or Chaos Labs) to monitor collateral health in real-time. The industry is moving toward more resilient oracle designs that ignore sudden price spikes in low-volume pools. Furthermore, the Base ecosystem may introduce more standardized security guidelines for developers to prevent similar price-oracle exploits from recurring as the network continues to scale.

Educational analysis generated with AI and editorially reviewed.

Original source: thedefiant.io

Want to learn the fundamentals? What is Blockchain?

Frequently Asked Questions

How did the attacker exploit Moonwell?

The attacker manipulated the price of the MAMO token due to its low liquidity, then used the inflated value as collateral to borrow and withdraw $8.7 million in other assets.

What is the current status of Moonwell?

Borrowing has been effectively paused (set to 1 wei) on all core markets on Base to prevent further losses, while the team investigates the incident.

What does '1 wei borrow cap' mean?

It is a technical way to disable borrowing. Since 1 wei is the smallest possible unit of Ether, no meaningful amount can be borrowed by users.

Is the Base network itself compromised?

No, the exploit was specific to the Moonwell protocol's handling of the MAMO token collateral, not a vulnerability in the Base network's underlying code.

How can DeFi protocols prevent this in the future?

By implementing more robust price oracles, setting stricter liquidity requirements for collateral assets, and using automated risk monitoring tools.

Glossary Terms

Continue Learning

Explore more insights about technology, automation, and Web3 in the EduWeb Academy.

Explore Academy