Moonwell Hit with $9M DeFi Lending Protocol Exploit
The DeFi lending protocol Moonwell has been hit by an exploit that drained over $9 million in real crypto assets. The attacker manipulated the price of MAMO, which was accepted as collateral on Moonwell, from around $0.0105 to $0.088, an increase of nearly eight times.
The inflated token value was used to borrow cbBTC, USDC, wstETH, and ETH from the platform. According to blockchain security firm CertiK, this was not a direct attack on Moonwell's code, but rather the attacker took advantage of a price oracle that could be moved by trading activity in the thin MAMO market.
The attack quickly turned the inflated MAMO value into real funds, with around $8.7 million already drained and total losses exceeding $9 million. This is not the first security issue Moonwell has faced, as the project also faced a major security incident on February 18, 2026, after a faulty smart contract caused a huge pricing error.