Key Takeaways
- A malicious actor exploited the illiquid MAMO token’s price mechanics to extract genuine cbBTC from Moonwell’s lending platform on Base
- Blockchain security companies CertiK and PeckShield independently confirmed damages totaling approximately $8.7 million
- The drained assets were converted to DAI stablecoin and transferred to a single wallet
- The protocol implemented emergency borrow caps of 1 wei on all Base Core Markets to prevent additional losses
- WELL token value declined 13% while MAMO decreased 9% in the aftermath
On August 27, the decentralized finance platform Moonwell became the target of a sophisticated exploit that resulted in approximately $8.7 million being siphoned from its MAMO Core Market operating on the Base blockchain.
Multiple cybersecurity organizations including CertiK, PeckShield, and Blockaid traced the attack to an identical vulnerability. The perpetrator exploited MAMO’s limited liquidity to artificially manipulate its collateral valuation upward.
Using this artificially inflated collateral position, the attacker secured loans of legitimate cbBTC from Moonwell’s mCBTC lending pool. Blockaid’s preliminary analysis revealed that 50.6 cbBTC—valued at over $4 million—had been extracted, though PeckShield’s subsequent investigation established the comprehensive loss at approximately $8.7 million.
The compromised assets were subsequently converted into DAI stablecoin and aggregated within a single wallet address.
Protocol’s Emergency Measures
Moonwell acted swiftly to contain the breach’s impact. The development team implemented borrow caps across all Core Markets on Base, setting them to 1 wei—effectively freezing all new loan originations.
Supply caps for MAMO and WELL tokens were similarly restricted to 1 wei. However, supply restrictions for other digital assets on the platform remained at their existing levels.
The protocol’s team indicated they would provide additional details as their forensic analysis progresses. A comprehensive post-mortem report has not been issued, and no confirmation regarding potential fund recovery has been made public.
MAMO’s market value had demonstrated significant volatility prior to this security incident. The token reached a peak of $0.227 before experiencing nearly a 20% decline following its Coinbase listing in August 2025.

In the wake of the breach, Moonwell’s native WELL token depreciated approximately 13% within a 24-hour window. MAMO experienced a comparable decline of roughly 9% during the identical timeframe.
Recurring Security Vulnerabilities
The August incident represents the latest in a series of security challenges for Moonwell throughout 2026. In February, an oracle malfunction incorrectly valued Coinbase Wrapped ETH at approximately $1.12 despite actual market pricing near $2,200, creating roughly $1.78 million in uncollateralized debt.
That defective oracle system allegedly incorporated code produced by Anthropic’s Claude Opus 4.6 artificial intelligence model, with an erroneous scaling parameter triggering the valuation anomaly.
In March, a separate threat actor invested approximately $1,800 in MFAM tokens to achieve quorum for a hostile governance proposal on Moonwell’s Moonriver implementation. The proposal targeted seven distinct lending markets and threatened approximately $1.08 million before emergency multisignature controls neutralized the threat.
The August 27 security breach occurred during a sustained wave of DeFi vulnerabilities. Through April 18, cryptocurrency protocols had sustained losses exceeding $606 million spanning at least 12 separate incidents that month.
The most substantial individual event was the $292 million Kelp DAO compromise, attributed to North Korea’s Lazarus Group. Binance Research subsequently reported that April’s exploits triggered approximately $13 billion in total value locked withdrawals from blockchain protocols.
Moonwell confirmed that its forensic investigation into the MAMO Core Market exploit continues.


