Moonwell Exploit Shows Risks Lurking in Thinly Traded Collateral
A major security incident occurred on August 27, 2026, when an attacker exploited the Moonwell lending protocol on the Ethereum layer Base. The attacker manipulated the price of a thinly traded token, MAMO, which is used as collateral for loans. The price of MAMO rose from $0.010597 to $0.43127363, nearly fortyfold, allowing the attacker to post inflated collateral and borrow approximately $11 million in assets.
The attack was not a hack in the classical sense, but rather an exploitation of the protocol's assumption that market price accurately reflects a token's value as collateral. The attacker borrowed cbBTC, WETH, USDC, and wstETH, which were then swapped into DAI and consolidated in one address.
Moonwell implemented emergency measures to contain the damage, including lowering borrow caps for all core markets on Base to 1 wei, effectively halting new loans. The protocol also set supply caps for MAMO and WELL tokens to prevent further exploitation.
The incident has left approximately $9.131 million in open obligations from the MAMO market, which will be borne by depositors of the four plundered markets. Moonwell's post-mortem analysis emphasized the importance of understanding how a lending protocol's markets are built and the risks associated with supplying collateral to core markets.