Moonwell Exploit Drains $8.7M from Lending Markets by Manipulating MAMO Collateral
Moonwell's lending protocol on Base was hit by a major exploit that drained an estimated $8.7 million from its markets. The attack, which occurred on August 27, involved manipulating MAMO collateral pricing to inflate its value. This allowed the attacker to borrow cbBTC, USDC, wstETH, and ETH against the overvalued token.
The attacker then consolidated proceeds on Ethereum, with a large amount of cbBTC moved from the protocol worth more than $4 million. The exploit was linked to the use of oracles that provided external price data for lending protocols. Moonwell's oracle accepted the higher price of MAMO, increasing the amount the account could borrow.
PeckShield estimates that the attack caused $3.7 million in bad debt from wrsETH pricing failures and $1.78 million from cbETH pricing failures. The loss estimate is preliminary, with any recovery and remaining collateral value affecting the protocol's ultimate shortfall.