Key Points
- A malicious actor exploited the illiquid MAMO token’s price mechanism to extract genuine cbBTC from Moonwell’s Base network lending platform
- Blockchain security experts CertiK and PeckShield both calculated the total damage at approximately $8.7 million
- The drained assets were converted to DAI stablecoin and moved to a single wallet
- The protocol implemented emergency borrow limits of 1 wei across all Base Core Markets to prevent additional losses
- WELL token value declined 13% while MAMO decreased 9% in the aftermath
On August 27, decentralized finance platform Moonwell experienced a significant security breach that resulted in approximately $8.7 million being extracted from its MAMO Core Market operating on the Base blockchain.
Multiple blockchain security organizations including CertiK, PeckShield, and Blockaid confirmed the same exploitation technique. The perpetrator artificially inflated the collateral valuation of MAMO, a token with limited liquidity, to dramatically increase its perceived worth.
Using this artificially elevated collateral, the exploiter withdrew authentic cbBTC from Moonwell’s mCBTC lending pool. Blockaid’s preliminary assessment indicated that 50.6 cbBTC valued at more than $4 million had been extracted, though PeckShield subsequently calculated the complete loss at approximately $8.7 million.
The compromised assets were subsequently converted into DAI stablecoin and transferred to a single wallet address.
Protocol’s Emergency Measures
Moonwell took immediate action to prevent additional exploitation. The development team implemented borrowing caps of 1 wei across all Core Markets on the Base network, essentially halting all new loan activity.
Supply caps for MAMO and WELL tokens were similarly restricted to 1 wei. Supply restrictions for other supported assets on the platform remained at their existing levels.
The protocol announced it would provide additional details as the investigation progressed. Moonwell has not yet issued a comprehensive technical analysis or indicated whether fund recovery is possible.
MAMO’s market value had experienced significant volatility even before this security incident. The token reached a peak of $0.227 before declining nearly 20% following its Coinbase listing in August 2025.

In the wake of the breach, Moonwell’s native WELL token decreased approximately 13% within a 24-hour timeframe. MAMO experienced a decline of roughly 9% during the same period.
Recurring Security Vulnerabilities
This incident marks another chapter in Moonwell’s troubled security history throughout 2026. A February oracle malfunction incorrectly valued Coinbase Wrapped ETH at approximately $1.12 despite its actual market price near $2,200, resulting in roughly $1.78 million in uncollateralized debt.
The defective oracle reportedly contained code produced using Anthropic’s Claude Opus 4.6 artificial intelligence model, with an erroneous scaling factor responsible for the valuation mistake.
A March incident saw an exploiter invest approximately $1,800 in MFAM tokens to successfully pass a harmful governance proposal on Moonwell’s Moonriver implementation. The proposal threatened seven lending markets with approximately $1.08 million in exposure before emergency multisig controls prevented execution.
The August 27 security breach occurred during an extended period of substantial DeFi sector losses. Through April 18, cryptocurrency platforms had experienced more than $606 million in losses across a minimum of 12 separate incidents during that month.
The most significant individual event was the $292 million Kelp DAO breach, attributed to North Korea’s Lazarus Group. Binance Research subsequently reported that April’s exploits drove approximately $13 billion in total value locked withdrawals from blockchain-based protocols.
Moonwell confirmed its investigation into the MAMO Core Market exploitation continues.





