Moonwell Lending Protocol Hit by $8.7 Million Exploit
A hacker exploited a vulnerability in the Moonwell lending protocol on Base, the Ethereum layer 2 operated by Coinbase, to steal approximately $8.7 million. The attack occurred between August 27, 2026, 06:09:45 UTC and 09:30:13 UTC.
The attacker manipulated the price of the MAMO token from around $0.010597 to a peak of $0.43127363, roughly fortyfold, allowing them to post inflated collateral for loans. The stolen assets included cbBTC, WETH, USDC, and wstETH, which were borrowed from four markets.
The attack was not a traditional hack, as it did not involve overflowing memory or injected foreign code. Instead, the weakness lay in an assumption that the observed market price of a thinly traded token adequately describes its value as collateral.