Moonwell on Base Hit by Collateral Price Manipulation; Losses Estimated at $8.7M
AI Market Summary
Moonwell's Base lending market suffered a collateral price-manipulation event tied to low-liquidity MAMO, enabling overvalued collateral borrows of liquid assets (including cbBTC and USDC) and ~ $8.7m in losses. The protocol cut borrow and select supply limits to 1 wei, effectively pausing new borrowing on Base core markets. The incident underscores ongoing DeFi oracle/liquidity risks and can weigh on risk appetite toward Base and lending protocols.
Impact level
● Medium
Affected assets
BTC/USDT+2.17%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Moonwell, a lending protocol on Coinbase's Base network, has been hit by a collateral price manipulation incident that security firms estimate caused roughly $8.7 million in losses, according to CoinMarketCap.
Investigators say the attacker targeted MAMO, a low-liquidity token, pushing up its price and then using the inflated valuation as collateral to borrow higher-value assets. The borrowed assets reportedly included cbBTC and USDC.
In response, Moonwell moved to lock down risk on Base by tightening parameters across its Core Markets. The protocol cut the borrowing limit for all Core Markets on Base to 1 wei, effectively stopping new borrowing. It also reduced supply limits for MAMO and WELL to 1 wei, while leaving supply limits for other assets unchanged.
CertiK and PeckShield both pegged the losses at about $8.7 million. Blockaid previously flagged an outflow of 50.6 cbBTC from Moonwell's mCBTC market, worth more than $4 million at the time.
Analysts said the incident stemmed from pricing infrastructure rather than smart contract code. By exploiting thin liquidity in the MAMO market, the attacker was able to distort the token's price, then borrow more liquid assets against the overstated collateral value. PeckShield later said the stolen funds were consolidated into DAI.
One analysis estimated the attacker spent around $7 million buying MAMO, then sold part of the position to recoup roughly $3.2 million. While the trading leg itself took a loss, the attacker profited overall because the assets borrowed against the inflated collateral were worth more.
The episode underscores a recurring risk in DeFi lending: dependence on price feeds and the liquidity of collateral markets. When a collateral asset lacks depth, concentrated buying can rapidly lift quoted prices and, without safeguards, inflate borrowing capacity. The report pointed to a 2025 KiloEX attack tied to oracle weaknesses that led to about $7.5 million in losses. It also cited a recent Term Finance incident involving around $8.5 million, highlighting that major protocol failures are not limited to code vulnerabilities.
Moonwell said it is still investigating the MAMO market incident. Security teams including Blockaid and PeckShield continue to track related transactions, and the status of fund recovery remains unclear.