Moonwell Halts New Base Lending After MAMO Collateral Price Manipulation: Estimated Damage of $8.7 Million

Decentralized lending protocol Moonwell said it is investigating anomalous transactions that occurred on August 27 local time in the MAMO core lending market on Base, an Ethereum layer 2. According to TechTimes, MAMO is a small, low-liquidity token whose market capitalization was about $6 million before the incident. TechTimes analyzed that the attacker pushed the price up roughly eightfold in the shallow MAMO liquidity pools on Aerodrome and Uniswap, and that a spot price oracle without time-weighted average price (TWAP) protection reflected this in collateral value. Using the inflated MAMO as collateral, the attacker borrowed liquid assets such as Coinbase Wrapped Bitcoin (cbBTC) in amounts exceeding the actual disposal value and exited. PeckShield and CertiK estimated the damage at about $8.7 million, and the assets that were taken out were gathered in a single address as DAI. According to The Block, Blockaid also confirmed the same attack path. Moonwell lowered the borrow caps across the entire Base core market and the supply caps for MAMO and WELL to 1 wei, effectively the smallest unit the contract processes, halting new supply and borrowing without eliminating existing positions. According to Moonwell's official forum, an anomaly in the wrsETH oracle in November 2025 produced $3.7 million in bad debt, and The Block reported that a cbETH oracle configuration error in February 2026 produced about $1.78 million in bad debt. Moonwell's final incident report, along with confirmed losses, recovered amounts, the treatment of existing user positions, and a compensation plan, has not yet been disclosed. Based on the analysis published so far, this incident is classified not as a breach of smart contract code but as a manipulation of the collateral price the code referenced.

Metanomia View

Even when a smart contract executes exactly as specified, if the input price is manipulated, the lending market accepts an incorrect collateral value as fact. The capacity to control risk rests not on code alone but on which oracle is used, how collateral liquidity is screened, and who can lower supply and borrow caps, by how much, and how quickly. When on-chain lending is brought inside the regulatory perimeter in Korea as well, collateral eligibility standards, pricing methods, emergency-halt authority, and the order of loss allocation should be required to be disclosed at the level of a product prospectus.

Sources