Moonwell Hit by $8.7M DeFi Exploit via MAMO Price Manipulation
DeFi protocol Moonwell suffered an estimated $8.7 million exploit on August 27, after an attacker manipulated the price of MAMO collateral on Base and used its inflated value to borrow higher-quality assets from the protocol.
The attack targeted Moonwell's MAMO Core Market, exploiting the relatively limited liquidity of MAMO to increase the token's apparent collateral value before borrowing assets from Moonwell's lending markets.
CertiK initially identified the attacker borrowing Coinbase Wrapped Bitcoin (cbBTC) from the mCBTC market. PeckShield subsequently reported a broader $8.7 million loss, with the stolen value eventually consolidated into DAI at an attacker-controlled address.
The incident illustrates a fundamental risk for decentralized lending protocols that accept thinly traded tokens as collateral, and highlights the need for robust oracle protections to prevent price manipulation.