The Moonwell lending protocol on the Base layer-2 network has fallen victim to a targeted attack. The attacker exploited a vulnerability in the collateral pricing mechanism, resulting in losses of approximately $8.7 million. The incident was detected by my colleagues in the on-chain analytics space, and this is not the first time that low-liquidity assets have become the weak link in DeFi protocols.
Attack Mechanics: Price Manipulation and Unsecured Debt
The essence of the exploit comes down to manipulating the price of the low-liquidity token MAMO, which was used as a collateral asset. The attacker artificially inflated its value, then borrowed real liquid assets against this collateral: cbBTC, USDC, wstETH, and ETH. As a result, the protocol was left with unsecured debt, putting the funds of other depositors at risk.
Damage estimates vary depending on the calculation methodology. Early data indicated a loss of about 50.6 cbBTC (~$4 million), but a more detailed analysis conducted by ExVul specialists showed a figure of 71.36 cbBTC (~$5.7 million). My estimate, based on aggregated data, is $8.7 million, although some observers suggest it is approaching $9 million. The final amount will likely be revised upward as the investigation progresses.
Moonwell's Response and Precautionary Measures
The Moonwell team promptly confirmed the incident, linking it to the main MAMO market. As a preventive measure, developers restricted borrowing capabilities in all Core Markets on Base to 1 wei. This decision blocks new loans and prevents further growth of the debt. Additionally, restrictions were introduced on the supply of MAMO and WELL tokens.
The market reaction was mixed. In the first hours after the attack, the MAMO token unexpectedly showed growth, likely due to artificially inflated trading volumes. However, quotes then corrected, albeit without a sharp collapse. The native token WELL, on the other hand, lost about 13% of its value, dropping to $0.0032.
This incident once again raises the question of the safety of using low-liquidity assets as collateral. Such manipulations remain one of the most acute problems in DeFi, and protocols need to implement more reliable oracle mechanisms and protection against price anomalies.
My comment: This case is a vivid example of how liquidity pricing can become a catalyst for a hack. Protocols should pay more attention not only to the total value locked (TVL) but also to the quality of collateral assets. Using outdated or easily manipulated price feeds is a ticking time bomb that will eventually go off. I recommend investors carefully monitor audits and pricing mechanisms in projects where they place their funds.