Moonwell's Fourth Exploit in a Year: $8.7M Lost to a MAMO Price Manipulation
An attacker pumped an illiquid collateral token and borrowed against the inflated price — no smart contract bug required. It's Moonwell's fourth loss event in under a year.
Key Takeaways
- An attacker manipulated the price of MAMO, an illiquid token, from roughly $0.01 to $0.43, then borrowed liquid assets — reportedly including cbBTC, USDC, wstETH and ETH — against the inflated collateral and abandoned it, per [The Defiant](https://thedefiant.io/news/hacks/moonwell-loses-8-7-million-to-mamo-price-manipulation-on-base).
- No smart contract was broken. This was a collateral-pricing and market-design failure, not a code vulnerability — a distinction that matters for how protocols should be tested.
- This is Moonwell's fourth exploit in under a year: a $3.7M oracle manipulation in November 2025, a $1.78M oracle attack in February 2026, a $1M governance attack in March 2026, and now $8.7M — over $15M in cumulative losses.
- Moonwell's emergency response was to set borrow caps across every core Base market, and supply caps for MAMO and WELL, to 1 wei — effectively freezing new activity protocol-wide rather than patching a single line of code.
What happened
On 27 August, an attacker took roughly $8.7 million from Moonwell, a lending protocol on Base, by manipulating the price of MAMO — a thinly traded token that Moonwell's markets accepted as collateral. According to The Defiant, the attacker accumulated MAMO and traded it aggressively enough to push the price from around $0.01 to as high as $0.43. With MAMO now marked at an inflated value inside Moonwell's market, the attacker borrowed more liquid assets — reportedly including cbBTC, USDC, wstETH and ETH — against it, then let the overvalued collateral get liquidated, keeping the borrowed funds. Early on-chain monitoring cited by The Defiant put more than $4 million of the drained value in cbBTC alone.
Why this isn't a code-level "hack"
The detail worth sitting with, per crypto.news: no smart contract was broken and no bug was patched afterward. This was a pricing and risk-parameter failure — the protocol let a low-liquidity token be used as collateral without limits tight enough to survive someone simply buying up its thin order book. That's an economic design problem, and it's a different kind of finding than the ones a Solidity audit is built to catch. It requires modeling how a market's own price feed behaves under adversarial buy pressure, not just reviewing the code that reads that feed.
A pattern, not an incident
This is Moonwell's fourth loss event in under twelve months, according to web3isgoinggreat.com:
- November 2025 — $3.7 million lost to an oracle manipulation attack.
- February 2026 — $1.78 million lost to a second oracle attack.
- March 2026 — $1 million lost to a governance attack.
- August 2026 — $8.7 million lost to the MAMO collateral-price manipulation described above.
Four distinct root causes — oracle design twice, governance, and now collateral-listing risk — losing over $15 million combined is a signal about the protocol's overall risk process, not just a run of bad luck on isolated code paths.
What this means for protocols that list long-tail collateral
Lending markets that accept illiquid or newly-listed tokens as collateral are making an implicit bet that the token's on-chain liquidity is deep enough that price manipulation isn't economically worthwhile. That assumption needs to be tested against real order-book depth and realistic attacker capital — not assumed from a token's market cap. Isolated markets, conservative loan-to-value ratios for thin-liquidity assets, and supply/borrow caps sized to actual liquidity are standard mitigations; several of Moonwell's four incidents suggest those parameters were set too loosely for the assets involved.
Moonwell's response
Per The Defiant, Moonwell set borrow caps to 1 wei across every core market on Base, and supply caps for MAMO and WELL to the same level — halting new borrowing and further deposits of the affected tokens protocol-wide while it investigates. That's a containment measure, not a fix; whether Moonwell tightens collateral-listing criteria going forward is the detail worth watching.
Frequently Asked Questions
Was the Moonwell MAMO exploit a smart contract bug?
No. Reporting from The Defiant and crypto.news indicates no contract vulnerability was exploited — the attacker manipulated the market price of an illiquid collateral token and borrowed against the inflated value, a market-design and risk-parameter failure rather than a code defect.
How much has Moonwell lost to exploits in total?
Across four incidents in under a year — a $3.7M oracle attack (November 2025), a $1.78M oracle attack (February 2026), a $1M governance attack (March 2026), and this $8.7M price manipulation (August 2026) — losses total more than $15 million, per web3isgoinggreat.com.
How can DeFi protocols prevent this kind of collateral price manipulation?
Common mitigations include isolating illiquid assets into their own markets, setting loan-to-value ratios and supply/borrow caps sized to actual on-chain liquidity rather than market cap, and using time-weighted or manipulation-resistant price sources for thinly traded collateral.
Sources
- 1Moonwell loses $8.7 million to fourth exploit in less than a year — Web3 Is Going Great
- 2Moonwell Loses $8.7 Million To MAMO Price Manipulation On Base — The Defiant
- 3Moonwell MAMO exploit drains $8.7M from Base lending market — crypto.news