Skip to content
Est. MMXXVIVol. VI · № 329RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 324Oracle Manipulation

Moonwell MAMO Oracle Manipulation

An attacker inflated the price of the illiquid MAMO token to borrow real assets from Moonwell's lending markets on Base, draining about $8.7 million.

Date
Victim
Moonwell
Chain(s)
Status
Funds Stolen

On August 27, 2026, Moonwell, a lending protocol on the Base network, was exploited when an attacker manipulated the collateral value of its relatively illiquid MAMO token and borrowed real assets against the inflated position, draining approximately $8.7 million. Security firms PeckShield and CertiK both put the loss at around $8.7 million, making it one of the larger DeFi incidents of the month.

What happened

According to CertiK's assessment, the attacker manipulated the collateral value of MAMO, a thinly traded token, then used the inflated collateral to borrow genuine assets from Moonwell's markets. Blockaid's initial trace flagged 50.6 cbBTC worth more than $4 million being drained from the mCBTC market, with total borrowings across affected markets estimated at more than $11 million gross and roughly $8.7 million in net losses. The protocol's post-mortem placed the attack sequence in the early hours of August 27, 2026 (UTC), during which the attacker posted the over-valued MAMO as collateral and withdrew cbBTC and other assets before the position could be liquidated at honest prices.

Aftermath

Moonwell moved to contain the bleeding by lowering borrow caps across all Core Markets on Base to 1 wei and cutting supply caps for MAMO and WELL to the same negligible level, effectively freezing new borrowing. The team said its investigation remained active and disclosed no recovery of funds, so the status here is stolen. The incident marked Moonwell's third security failure in eleven months and, by some accounts, exceeded the protocol's full annual revenue.

Why it matters

This was Moonwell's second oracle-driven collateral incident of 2026, following its February 2026 decimals-mismatch exploit, and it underscores how dangerous it is to accept thinly traded tokens as collateral in a lending market. When an asset like MAMO can be pushed far from fair value, its price feed becomes an attack surface: inflate the collateral, borrow blue-chip assets, and walk away before liquidation catches up. The same failure mode drove the far larger Tectonic exploit on Cronos only days later, reinforcing that conservative collateral onboarding and manipulation-resistant oracles remain the front line of lending-protocol security.

Sources & on-chain evidence

  1. [01]crypto.newshttps://crypto.news/moonwell-mamo-exploit-drains-8-7m-from-base-lending-market/
  2. [02]en.cryptonomist.chhttps://en.cryptonomist.ch/2026/08/28/moonwell-mamo-exploit/
  3. [03]forklog.comhttps://forklog.com/en/moonwell-suffers-8-7-million-hack/
  4. [04]kucoin.comhttps://www.kucoin.com/news/flash/moonwell-exploit-on-base-drains-8-7m-via-mamo-oracle-manipulation

Related filings