Moonwell did not need a broken smart contract to lose $8.7 million. It only needed a thin collateral token, a price feed the market could push around, and a lending system willing to treat that price as truth.
That is why the Moonwell MAMO exploit on Base matters. It is not just another hack headline. It is a cleaner, nastier lesson in how decentralised lending can fail when liquidity risk is dressed up as innovation.
The Attack Was a Price Problem, Not a Code Problem
Moonwell said on 27 August that it was investigating an issue affecting its MAMO Core Market on Base. Its emergency response was blunt: borrow caps for all Base Core Markets were reduced to 1 wei, while supply caps for MAMO and WELL were also cut to 1 wei. In practice, new borrowing was frozen while the protocol tried to work out what had happened.
Security firms gave the market the working explanation before a full post-mortem arrived. CertiK said the attacker manipulated the relatively illiquid MAMO token’s collateral price, then used that inflated collateral value to borrow real cbBTC from Moonwell’s mCBTC market. PeckShield and CertiK both put the loss at about $8.7 million. Blockaid said it observed 50.6 cbBTC, worth more than $4 million, drained during the activity.

The Defiant reported that proceeds were consolidated into 8,728,318 DAI at a single Ethereum address. It also cited MAMO’s market capitalisation at about $6 million and roughly $1.18 million of 24-hour volume before the attack. That is the whole controversy in one comparison: a protocol accepted a small, moveable asset as collateral, and the attacker used the price movement to pull out assets that were far harder to fake.
One Wei Is Not a Victory Lap
Moonwell’s “borrow caps to 1 wei” move was the correct emergency brake. It also revealed how little room there was between normal operations and a full defensive crouch.
In its public statement, Moonwell said: “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact.” That is sensible incident response. But it is not the same thing as a healthy market.
A lending protocol can call a token collateral only if it can believe the price when things go wrong. If the price can be shoved around cheaply, the collateral is not really collateral. It is a liability waiting for a motivated counterparty.
Moonwell Has Seen This Film Before
The awkward part is that this was not Moonwell’s first pricing-related embarrassment of the year. Crypto.news and The Defiant both pointed back to a February cbETH oracle incident that left the protocol with about $1.78 million of bad debt after Coinbase Wrapped ETH was mispriced at roughly $1.12 instead of around $2,200.
There was also a March governance scare on Moonriver, where an attacker allegedly used about $1,800 of MFAM tokens to push a proposal that could have put around $1.08 million at risk. Moonwell had emergency mechanisms to stop that proposal. The point is not that every incident was identical. The point is that Moonwell’s 2026 risk story is starting to look less like isolated bad luck and more like a repeated stress test of peripheral controls.

The latest numbers make that uncomfortable. The Defiant cited Moonwell total value locked at $71.5 million, with $68.2 million on Base, $32.6 million in active loans and $8.6 million in annualised fees. An estimated $8.7 million drain is therefore not a rounding error. It is roughly the size of a full year of protocol fees.
The Collateral Menu Is the Real Debate
The timing made the story sharper. Three days before the attack, Moonwell was reportedly pitching a wider collateral menu, including the possibility that tokenised stocks could become viable collateral once Chainlink finishes research into 24/7 price feeds. The broader industry wants every asset to be borrowable, lendable and instantly composable. The MAMO price manipulation is the counter-argument.
More collateral types can bring more users, more fees and more narrative heat. They also bring more surfaces where market depth, oracle design and governance settings have to work perfectly at the same time. The smaller and thinner the asset, the less margin for error.
Mamo, the AI-powered personal finance app linked to the token, said its own contracts were not compromised. That distinction matters. But it will not comfort users who discovered that an external lending venue’s collateral design could still freeze access or damage liquidity around assets they thought were safely routed.
What Happens Next
Moonwell still owes the market a detailed post-mortem: exact transaction sequence, oracle construction, risk-parameter history, any recoveries and the treatment of affected users. Until then, the cleanest conclusion is also the most damaging one.
This was a DeFi exploit where the visible failure was not a missing semicolon or an obviously broken contract. It was a risk model that let a thin token become too powerful inside a lending market.
The next phase of DeFi security will not be won by audits alone. It will be won by protocols admitting that liquidity is part of security — and that a price no one can defend is not a price at all.










