$8.7M Moonwell Loss Highlights Risks of Thinly Traded Tokens
On August 27, Moonwell suffered an $8.7 million loss after an attacker manipulated the price of its own listed token, MAMO, to inflate its collateral value and borrow real cbBTC from the protocol's lending market on Base.
The attack leveraged a weakness in Moonwell's system related to thinly traded tokens, which can be easily manipulated by artificially inflating their prices. The attacker borrowed cbBTC against the inflated MAMO collateral, converted it into DAI stablecoin, and consolidated the funds into a single wallet address.
Moonwell responded quickly by setting borrow caps of 1 wei across all Base Core Markets and reducing supply caps for MAMO and WELL tokens to 1 wei. These measures were taken to limit further losses, but the protocol's native token price fell about 13% while MAMO dropped roughly 9% within 24 hours of the attack.
The Moonwell exploit marks the third security incident for the lending protocol in 2026, following an oracle mispricing bug and a governance attack earlier in the year. The incident raises questions about the reliability of thinly traded collateral assets and highlights the need for robust security measures to prevent such attacks.