Moonwell Hit by Third Exploit in Nine Months After MAMO Price Manipulation
Moonwell has been hit by its third security incident in nine months. On August 27, 2026, an attacker exploited the protocol's price oracle to overvalue MAMO, a token that is part of the Base lending market. The attacker then used the inflated value as collateral to borrow cbBTC from the mCBTC market.
The attack began at 08:43 UTC on August 27 and was still unfolding hours later with no official response yet from Moonwell. Blockaid, a security firm that flagged the activity, said the attacker inflated MAMO's price roughly eightfold, from about $0.0105 to about $0.088.
Moonwell has had similar incidents in the past, including an oracle misconfiguration in November 2025 that valued cbETH at $1.12 instead of its actual value of around $2,200. The three incidents share a common weakness: an asset whose price could not yet be fully trusted was allowed to do something consequential.