The cryptocurrency lending protocol Moonwell fell victim to a sophisticated attack on the Base layer-2 network. The attacker, exploiting a vulnerability in the pricing mechanism, stole assets worth approximately $8.7 million. This incident once again highlights the systemic risks associated with low-liquidity collateral assets in DeFi.

Hack Mechanics: Price Manipulation and Borrowing Real Assets

The essence of the attack came down to manipulating the price of the MAMO token, which was used as collateral. Due to its low liquidity, the attacker was able to artificially inflate the value of the collateral, after which they took out significant loans in liquid assets — cbBTC, USDC, wstETH, and ETH. As a result, the protocol was left with unsecured debt, while real funds were withdrawn.

Damage estimates vary depending on the source and the point of measurement. Early on-chain data indicated a loss of approximately 50.6 cbBTC (over $4 million), but the figure grew as transactions were analyzed. ExVul analysts estimated losses at 71.36 cbBTC (~$5.7 million), my own calculations and CertiK data converge at $8.7 million, and a number of independent observers are already talking about approaching $9 million. This dynamic suggests that actual losses could be even higher.

Team Response and Market Implications

Moonwell developers promptly confirmed the incident, linking it to the main MAMO market. As a preventive measure, they set borrowing limits for all Core Markets on Base at 1 wei — this blocked the possibility of new loans and prevented further growth of the debt. Additionally, restrictions were introduced on the supply of MAMO and WELL tokens.

The market reacted ambiguously. In the first hours after the attack, MAMO unexpectedly showed growth, which was likely driven by artificially inflated trading volumes. However, quotes then corrected, albeit without a crash. The platform's native token WELL lost about 13%, dropping to $0.0032.

This is already the second serious incident in recent days: earlier, on August 19, the Maya Protocol project was forced to halt its network after a $1.7 million hack. Such events are a worrying signal for the entire DeFi sector.

My analysis: This attack is a classic example of how insufficient liquidity and vulnerability in price oracles create a breach in a seemingly reliable system. Protocols that use low-liquidity tokens as collateral must implement stricter control mechanisms and dynamic limits, otherwise we will see such scenarios repeated over and over again.