Moonwell Lending Loses $8.7M on Base as MAMO Collateral Price Manipulated
CertiK and PeckShield independently put the loss at $8.7M after an attacker inflated MAMO's price to borrow cbBTC and USDC from Moonwell.

Two security firms, CertiK and PeckShield, have independently put the loss from an exploit on the Moonwell lending protocol at roughly $8.7 million. Both firms trace the loss to a manipulation of the collateral price of MAMO, a token used on the Base network, which an attacker used to borrow cbBTC and USDC from Moonwell’s markets.
What’s confirmed by two sources: the $8.7 million figure, the MAMO collateral-price manipulation, and the borrowed assets, cbBTC and USDC. What’s not yet public: a full on-chain forensic breakdown, exact transaction hashes, or whether any funds have been frozen or recovered.
How the collateral price was reportedly pushed up
Both CertiK and PeckShield describe the same mechanism: the attacker pushed up the price Moonwell’s markets used for MAMO as collateral, then borrowed against that inflated value. The protocol treated the distorted price as valid and released cbBTC and USDC loans well above what real MAMO collateral would have supported.
Moonwell has said it is investigating the issue on Base. Neither report attributes the loss to a flaw in Moonwell’s smart contract code itself. The mechanism described is a price input problem, not a broken function or a bypassed access control, which is why coverage has framed it as an exploit without a code hack.
What still needs a second source
The $8.7 million figure and the MAMO-to-cbBTC/USDC mechanic clear Cryptaur’s two-source bar. Details beyond that, such as how MAMO’s price feed was sourced, whether it relied on a thin on-chain pool or an external oracle, and whether Moonwell has paused the affected market, have not yet appeared in more than one independent account and should be treated as provisional until Moonwell or the security firms publish a fuller post-mortem.
MAMO trades on Base, the same network Moonwell’s lending markets run on. Borrowers there use various tokens as collateral to draw stablecoins and wrapped assets like cbBTC, which is what made an inflated MAMO price directly convertible into real, transferable value.
A pricing exploit, not a code exploit
For lenders and borrowers on Base, the distinction matters. A contract-level hack usually forces a protocol-wide pause and a rewrite. A price-input exploit points instead at how a market sources and validates the value of a specific collateral asset, in this case MAMO, before a loan is approved.
Until Moonwell publishes its own account of which market was affected and whether the $8.7 million loss is final, the number stands on two-source confirmation from CertiK and PeckShield, and nothing more precise than that.
Sources
Related articles
Cronos Halts Chain After $75M Tectonic Exploit, TONIC Pumped 100x in 20 Minutes
Cronos froze its network after an estimated $75M Tectonic hack. Two outlets confirm the halt; the breakdown traces to one researcher.
Bitwise Launches Tokenized Stock Portfolios as Market Hits $2.49B
Bitwise's Coinbase-powered, Glider-rebalanced portfolios target Mag 7, AI and robotics stocks as tokenized equities pass $2.49 billion.
Term Finance Loses $8.5M as Attacker Drains 68% of Vault Deposits
A governance takeover let an attacker empty Term Finance's Meta Vaults of nearly $8.8M in ETH and swap 1.68M USDC for DAI.