Market Times:

London:

New York:

Singapore:

Loading cryptocurrency data...

Base Protocol Moonwell Hit by $8.7M Oracle Manipulation Exploit

Moonwell's history makes current issues seem more serious, as repeated problems can erode trust, even when individual defenses improve over time.

Nobitex Resupply NPM Hack

Moonwell, a decentralized lending platform on Base, has experienced a serious security incident involving fake token prices. The event led to a loss of about $8.7 million.

Investigators found that repeated borrowing activities turned these fake prices into real assets taken from Moonwell’s lending reserves during the attack. The latest incident raises concerns about whether decentralized platforms can safely use low-traded assets as collateral for lending.

MAMO Manipulation Results in $8.7M Loss

Blockchain security firms reported that an attacker exploited MAMO, a less liquid asset used as collateral in Moonwell’s Base markets. On-chain evidence indicates that MAMO’s price surged from approximately $0.0105 to $0.088, significantly increasing the value of the collateral held by the attacker.

This inflated collateral value allowed the attacker to borrow more valuable assets, including cbBTC, USDC, wstETH, and ETH, from Moonwell. Initial reports indicated that 50.6 cbBTC was drained, with later estimates suggesting the total loss was around $8.7 million.

In response to the incident, Moonwell quickly implemented measures to reduce borrow limits across the Base Core Markets. The protocol also set supply limits for MAMO and WELL, which restricted operations while developers investigated the incident and assessed the extent of the damage.

Not the First Time

This is not Moonwell’s first security incident. The protocol had faced security issues related to oracle failures and pricing errors, resulting in substantial financial losses for its users. For example, in October 2025, challenges with the AERO, VIRTUAL, and MORPHO coins caused $12 million in liquidations and $1.7 million in bad debt.

A month later, an error with the wrsETH oracle caused collateral to be overvalued, enabling an attacker to borrow millions before Moonwell could intervene. The incident resulted in approximately $3.7 million in bad debt across various assets and necessitated emergency measures.

Following the November incident, Moonwell reinstated borrow limits on Base and Optimism on November 12, after upgrading the oracles and implementing new controls. However, in February 2026, another oracle error mispriced cbETH at around $1.12 instead of its actual value of about $2,200. This led to widespread liquidations on Base.

Moonwell’s governance forum reported that 1,096 cbETH were seized, resulting in about $1.78 million in bad debt due to this pricing mistake alone. These incidents highlight persistent risks, despite the protocols’ attempts to enhance defenses and monitoring.

We Have The Best Crypto Community on Telegram.

Join the CoinTab Family Now

Ephraim Emmanuel