Moonwell Lost $8.7 Million Without a Single Line of Code Being Hacked
Lending protocol Moonwell misplaced an estimated $8.7 million to an exploit on Thursday. No good contract was damaged. An attacker merely made MAMO, a small Base token, look way more beneficial than it’s.
The inflated worth let the attacker borrow actual property, together with Coinbase Wrapped Bitcoin (cbBTC) and USD Coin (USDC). Security agency Blockaid caught the exercise, and Moonwell froze new borrowing inside hours.
How the Moonwell Exploit Worked
The trick was worth, not code. Blockaid reported that the attacker manipulated MAMO collateral pricing to empty cbBTC from Moonwell’s mCBTC market. Its first estimate confirmed 50.6 cbBTC gone, price greater than $4 million.
MAMO is the token of Mamo, a yield instrument constructed on Base. Every MAMO in existence is price about $7.6 million mixed, and the token trades close to $0.011366. A market that small is affordable to pump.
That was the entire assault. Pump MAMO on skinny markets, put up it as collateral on the faux worth, and borrow property with actual worth. Moonwell’s oracle, the system that feeds costs to the protocol, believed the pump.
Security agency PeckShield later put whole losses at $8.7 million. That is greater than the market worth of each MAMO token. The agency stated the funds now sit within the DAI stablecoin at a pockets beginning with 0xD71d.
Borrow Caps Cut to One Wei as Recovery Questions Begin
Moonwell acknowledged the incident in a put up, indicating that they have been already working to cease the bleeding.
“We are conscious of a difficulty affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, stopping new borrowing and limiting the potential for additional impression,” the staff wrote.
One wei is the smallest unit potential. The change blocks all new loans with out touching withdrawals. Supply caps for MAMO and WELL, Moonwell’s governance token, additionally fell to 1 wei.
Thursday’s exploit just isn’t a first. Bad costs, not dangerous code, maintain costing Moonwell cash. A wrsETH oracle malfunction created round $3.7 million in dangerous debt in November 2025. A cbETH oracle misconfiguration added $1.78 million extra in February. Pricing failures have now price the protocol over $14 million in ten months.
The wider sector exhibits the identical weak point. Term Labs misplaced roughly $8.5 million to a governance exploit on Sunday. Analysts more and more blame economic design failures slightly than damaged code for DeFi’s greatest losses.
Moonwell says one other replace is coming. Two numbers will inform the actual story. The first is the ultimate dangerous debt as soon as MAMO’s worth settles. The second is how a lot cbBTC and USDC stays for suppliers who need out.
The put up Moonwell Lost $8.7 Million Without a Single Line of Code Being Hacked appeared first on BeInCrypto.
