Moonwell MAMO exploit Base lending price manipulation The Moonwell MAMO exploit drained an estimated $8.7 million from the decentralized lending protocol on Aug. 27, 2026, after an attacker manipulated the thinly traded MAMO token’s on-chain collateral price and borrowed real cbBTC from the platform’s mCBTC market. The protocol has since halted new borrowing across its Base Core Markets while it investigates the loss, marking the third publicly disclosed security incident to hit Moonwell in 2026 alone.
According to Moonwell, the team lowered all Base Core Market borrow caps to 1 wei and reduced supply caps for MAMO and WELL to the same minimum value, a move intended to prevent any new borrowing positions from opening during the investigation. “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact,” Moonwell said in a statement.
Security firms PeckShield and CertiK separately estimated the loss at approximately $8.7 million, though initial reporting placed the figure closer to 50.6 cbBTC, worth slightly more than $4 million. Blockaid traced the attack to the manipulation of the MAMO token’s collateral price. The attacker subsequently consolidated the stolen funds into DAI at a single address, a pattern consistent with similar price-peg exploits across decentralized finance.
Moonwell MAMO exploit Base lending price manipulation: How the price manipulation worked
The exploit followed a familiar playbook for protocols accepting low-liquidity assets as collateral. By moving the MAMO token’s reported price on the platform’s pricing source, the attacker was able to convince Moonwell’s Core Markets that the collateral posted was worth far more than its actual market value. With that inflated collateral position in place, the attacker borrowed cbBTC, a wrapped Bitcoin asset on Base backed by real reserves, against the artificially valued MAMO before prices reverted.
MAMO had reached an all-time high of $0.227 in mid-2025 after gaining more than 120% during a weeklong rally tied to its Coinbase listing. The token had subsequently fallen by roughly 20% as selling activity increased, leaving the asset with relatively thin order books on both centralized and decentralized venues, conditions that make on-chain price oracles easier to influence with limited capital.
Market reaction and token impact
The Moonwell WELL governance token fell about 13% over the 24 hours following the incident, while MAMO itself declined by roughly 9% in the same window. The price action suggests that traders anticipated further protocol-level losses or governance intervention as investigators traced the movement of the stolen assets through DeFi rails.
The exploit comes against a backdrop of an unusually costly year for crypto security. According to figures cited by CertiK and aggregated by industry researchers, DeFi protocols lost more than $635 million in April 2026 alone, exceeding the total recorded across the entire first quarter. DeFi total value locked stood at $82.7 billion at the end of April, down 10.7% from the previous month, with Binance Research estimating that April’s exploits contributed to roughly $13 billion in TVL outflows across on-chain protocols.
A third incident in a single year
Moonwell had already weathered two significant security episodes earlier in 2026. In February, an oracle calculation error mispriced Coinbase Wrapped ETH (cbETH) at roughly $1.12 while the asset traded near $2,200, leaving lending markets with about $1.78 million in bad debt. Reports later indicated that the faulty oracle logic incorporated code generated with Anthropic’s Claude Opus 4.6 model, a case study that CertiK highlighted in April when warning that AI misuse and infrastructure weaknesses were becoming significant components of crypto security risk.
In March, an unknown party acquired about $1,800 worth of MFAM governance tokens and pushed a malicious proposal through quorum on Moonwell’s Moonriver deployment, putting approximately $1.08 million of assets at risk. The Break Glass Guardian multisig halted the proposal before the funds were moved. The recurring pattern, thin-liquidity collateral manipulation, points to a structural weakness in how lending markets price small-cap assets, and the Moonwell MAMO exploit on Base illustrates how quickly that weakness can be turned into a multimillion-dollar loss.
This incident forms part of a troubling pattern that has defined the DeFi landscape in 2026, where oracle manipulation attacks on lending protocols have surged alongside the broader April 2026 exploit wave that drained hundreds of millions from protocols across multiple chains. Attackers have increasingly relied on AI-assisted tooling to scout vulnerabilities, simulate price feed behavior, and coordinate multi-block manipulation sequences with a speed and precision that manual exploitation rarely matched in prior years. The Moonwell MAMO exploit Base lending price manipulation is now cited alongside earlier 2026 incidents as evidence that even audited, well-established lending markets remain exposed when oracles and liquidation logic fail to keep pace with increasingly automated adversarial strategies.
Moonwell has not yet published a full post-mortem or identified a suspect address, and the protocol’s borrowing remains effectively paused on Base Core Markets as the investigation continues into the Moonwell MAMO exploit on Base lending markets.
Source: https://crypto.news/moonwell-mamo-exploit-drains-8-7m-from-base-lending-market/ Moonwell MAMO exploit Base lending price manipulation.

