Moonwell MAMO Exploit Explained: What Happened on Base
Moonwell, one of Base's largest lending protocols, lost an estimated $8.7 million to $9.1 million in blue-chip collateral — cbBTC, wrapped ETH, USDC and wstETH — after an attacker manipulated the price feed on its MAMO lending market on Thursday, August 27. This is the Moonwell MAMO exploit explained in plain terms: the attacker didn't hack any code or steal a private key. They exploited the fact that MAMO's collateral value was being read straight off live trading prices on decentralized exchanges, with nothing in place to smooth out short-term price swings. By trading MAMO against itself in large size, they inflated its price roughly 40-fold in minutes, then borrowed millions of dollars in real assets against that inflated value before Moonwell's liquidation system could catch up. WELL, Moonwell's governance token, sold off roughly 13% and MAMO fell about 9% in the 24 hours after the disclosure, as of Friday.
Is My Money on Base Safe?
For most Moonwell users, yes — but with a caveat. The exploit was contained to the MAMO market specifically; it didn't touch the protocol's core stablecoin or blue-chip lending pools directly. Moonwell moved fast once the attack was detected, freezing new borrowing across the MAMO and WELL markets by capping them at effectively zero and letting its liquidation engine claw back most of the attacker's position — 595 separate liquidation events closed out the bulk of the bad debt within hours. If you're holding cbBTC, WETH or USDC deposits in markets unrelated to MAMO, your funds were never at direct risk from this specific attack. The real risk isn't this incident alone — it's what it says about any Moonwell market, or any Base lending protocol, that still lists a thinly-traded token as collateral without the same protection.
How the Attacker Pumped MAMO 40x
This wasn't opportunistic — it was planned and funded well in advance. Moonwell's own post-mortem shows the attacker prepared a wallet about a week ahead of the exploit, seeding it on August 21 with a small amount of ETH routed through the privacy tool Tornado Cash, then funding it with roughly 800 ETH in total — about $1.95 million — also sourced through Tornado Cash and moved onto Base via Circle's CCTP bridge. That capital funded a three-step attack. First, the attacker supplied 15 million MAMO tokens to Moonwell's MAMO market, then transferred another 53 million MAMO directly into the underlying contract without formally depositing it — a move that inflated the exchange rate between MAMO and its interest-bearing version by roughly 3.7x while dodging the market's supply cap. Second, they bought roughly 94 million MAMO, repeatedly routing trades through a single thin MAMO/USDC liquidity pool on the decentralized exchange Aerodrome, pushing the oracle price from about $0.0106 to $0.4313. Because Moonwell's MAMO market read collateral value straight from that spot price with no time-weighted averaging — a "TWAP," which smooths a price over a window of time so a single large trade can't move it — the inflated price was accepted instantly. Third, with collateral now wildly overvalued, the attacker borrowed roughly $11 million in cbBTC, WETH, USDC and wstETH across 18 separate borrows before liquidations could kick in. That window was just 32 seconds.
Why This Is Moonwell's Third Oracle Failure in a Year
The MAMO exploit isn't Moonwell's first brush with bad price data — it's the third in under twelve months, and the pattern should worry depositors more than any single loss figure. In October 2025, a Chainlink oracle mispriced AERO, VIRTUAL and MORPHO, generating about $1.7 million in bad debt. In November, a malfunctioning wrsETH price feed cost roughly $3.7 million. In February 2026, a misconfigured cbETH oracle, reportedly involving code partly written with AI assistance, added another $1.78 million. Add the MAMO loss and Moonwell's cumulative oracle-related losses since late 2025 now exceed a full year of the protocol's own fee revenue, which runs around $8.6 million annually. Each incident had a different technical trigger, but they share the same root problem: a mismatch between what an oracle reports and what an asset is genuinely worth in a market with real depth. That looks like a governance and engineering-standards issue, not bad luck repeating itself.
What Happens Next for Moonwell and Base DeFi
The most likely near-term outcome is that Moonwell keeps borrowing frozen or capped on its Base Core Markets while it ships a fix — almost certainly a shift to TWAP-based pricing and stricter listing standards for any token that isn't deeply liquid. Expect a formal governance post-mortem proposal in the coming days codifying that change protocol-wide, not just for MAMO. Moonwell has also said it preserved on-chain evidence of the attacker's wallet, including a cross-chain trail through USDC's CCTP bridge and DAI, which leaves open the possibility of funds being tracked or frozen if the attacker tries to cash out through a centralized venue. The common misunderstanding here is treating this as "Moonwell got hacked" in the sense of stolen code or a broken smart contract. Nothing was hacked. The contracts did exactly what they were told: price collateral off the market. The lesson for anyone using Base lending protocols is to check not just whether a platform has been audited, but whether the specific market you're depositing into prices its collateral in a way a well-funded trader can't simply buy their way around.
Sources
- https://forum.moonwell.fi/t/post-mortem-mamo-market-incident-on-base/2208
- https://www.theblock.co/news/defi/2026-08-27-moonwell-investigates-base-lending-market-issue-412913
- https://finance.yahoo.com/markets/crypto/articles/moonwell-lost-8-7-million-122819291.html
- https://www.crowdfundinsider.com/2026/08/302632-defi-exploit-moonwell-freezes-base-borrowing-after-8-7m-mamo-price-manipulation-incident/
- https://www.techtimes.com/articles/325839/20260827/moonwell-oracle-exploit-exceeds-full-annual-revenue-third-failure-11-months.htm
- https://thedefiant.io/news/hacks/moonwell-loses-8-7-million-to-mamo-price-manipulation-on-base
- https://forum.moonwell.fi/t/mip-x43-cbeth-oracle-incident-summary/2068
- https://www.spendnode.io/blog/moonwell-cbeth-oracle-misconfiguration-1-78m-bad-debt-chainlink-oev-ai-code/