The cryptocurrency market has once again faced a serious security incident: the Moonwell lending protocol on the Base layer-2 network has been exploited. An unknown attacker used a vulnerability in the pricing mechanism of the collateral asset, leading to losses estimated at approximately $8.7 million. My analysis of on-chain data and messages from security teams indicates that the attack was carefully planned.
Attack Mechanics and Scale of Damage
The essence of the incident comes down to manipulation of the price of the low-liquidity token MAMO, which was used as collateral. The attacker artificially inflated its value, after which they were able to borrow significant amounts of real assets, including cbBTC, USDC, wstETH, and ETH. As a result, the platform was left with unsecured debt.
Damage estimates vary depending on the source and time of recording. Initial on-chain calculations showed a loss of about 50.6 cbBTC (over $4 million). However, as the analysis deepened, the figures grew: ExVul analysts estimated losses at 71.36 cbBTC (~$5.7 million), while my own calculations and data from CertiK converge on a sum of $8.7 million. Some independent observers even cite a figure of around $9 million, suggesting a possible underestimation of the initial data.
Team Response and Market Consequences
Moonwell developers responded promptly to the incident, confirming issues with the main MAMO market. As a preventive measure, they set borrowing limits for all major markets on Base at 1 wei, which effectively blocked the possibility of new loans and prevented further growth of the debt. Additionally, restrictions were introduced on the supply of MAMO and WELL tokens.
Against this backdrop, the market reacted ambiguously. The MAMO token initially showed growth, likely due to artificially inflated trading volumes, but then corrected without a sharp collapse. At the same time, the platform's native token WELL lost about 13% of its value, falling to $0.0032, reflecting investor concerns about the protocol's resilience.
This incident once again highlights a systemic problem in DeFi protocols: dependence on the accuracy of oracles and the liquidity of collateral assets. Manipulation of low-liquidity tokens remains one of the most effective attack vectors. I expect that Moonwell will have to not only compensate for the losses but also revise pricing mechanisms to protect against such scenarios in the future. The market will be closely watching the situation as it develops, since trust in the protocol directly affects the value of its tokens.