An attacker forced Moonwell’s price oracle to overvalue MAMO, then used the inflated token as collateral to borrow cbBTC from the protocol’s Base lending market. This is Moonwell’s third security incident in nine months. Each one involved an asset whose price could not yet be fully trusted, and each time that asset was allowed to do something consequential anyway, whether holding governance power, backing real collateral, or pricing a loan.
The attack began at 08:43 UTC on August 27, 2026, and was still unfolding hours later, with no official response yet from Moonwell. Blockaid, the security firm that first flagged the activity, said the attacker inflated the price Moonwell’s oracle assigned to MAMO, letting a relatively small amount of the token pass as collateral worth far more. That let the attacker draw cbBTC out of the mCBTC market, a pool meant to be backed by real Bitcoin exposure.
Blockaid’s Exploit Detection identified suspicious activity against @MoonwellDeFi on Base.
An attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market.
Observed impact so far: 50.6 cbBTC ($4.0M+) drained
More details to follow. 🧵— Blockaid (@blockaid_) August 27, 2026
ExVul, a security research account tracking the exploit, said the attacker pushed MAMO’s price roughly eightfold, from about $0.0105 to about $0.088, before using the inflated token as collateral. Moonwell has not confirmed this mechanism independently, and the figure comes from a single tracker rather than corroborated reporting.

Basescan records show seven of the borrow transactions individually, ranging from 0.50 cbBTC to a single 14.34 cbBTC draw, the largest of the batch. The attacker’s wallet has already moved most of the stolen funds elsewhere. As of publication it held just over $4,600, a fraction of what passed through it hours earlier.
WELL, Moonwell’s own governance token, spiked to roughly $0.0048 in the hours after the exploit began, then fell back below $0.0035, a swing of nearly 30% within the same day, according to CoinGecko data. As of publication, WELL was trading around $0.0035, down 4.3% over the past 24 hours with a market capitalization near $15.9 million.

Today’s incident is not Moonwell’s first brush with a mispriced asset. In November 2025, an oracle misconfiguration valued cbETH at $1.12 instead of roughly $2,200, creating $1.78 million in bad debt within about four minutes, as we reported at the time. Before that, an attacker spent just $1,800 to push a malicious governance proposal that put $1.08 million at risk.
The three incidents share a common weakness rather than a common cause. Each time, an asset whose price could not yet be fully trusted, whether by governance vote, oracle configuration, or now direct manipulation, was allowed to do something consequential: hold voting power, back real collateral, or set the terms of a loan.
Moonwell had not issued a public statement as of this writing. The final scale of Thursday’s exploit remains unresolved between the competing figures reported so far, and Basescan continues to record activity from the attacker’s wallet.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.
















