QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Blog

Moonwell faces $9 million attack amid ongoing vulnerabilities

Moonwell's DeFi platform suffers a $9 million exploit, part of a troubling trend of attacks over the past year.

25 September 2026 · 3 min read
Moonwell faces $9 million attack amid ongoing vulnerability-implications-for-ai-security/">vulnerabilities

In yet another setback for the decentralized finance (DeFi) platform Moonwell, nearly $9 million was drained from its lending services, underscoring a troubling pattern of security vulnerabilities. This incident represents the fourth major exploit targeting the platform within the past year, raising concerns about the robustness of its operational security.

Understanding the recent breach

The latest attack unfolded on the Base network, where a malicious actor managed to exploit the liquidity available for borrowing. Blockchain security firm Blockaidwas quick to detect the breach, notifying stakeholders only an hour into the event.

Moonwell confirmed the security incident shortly after, reporting that it had taken immediate action by cutting all loan limits associated with the MAMO token and its own WELL token down to one wei. This proactive measure aimed to curb further damage by halting new borrowings from the platform.

How the attack was executed

The exploit was rooted in a price manipulation scheme that inflated the value of MAMO, a collateral token with low liquidity on the platform. By artificially boosting MAMO’s price, the attacker was able to borrow cbBTC—a wrapped Bitcoin variant—based on this inflated valuation.

Reports indicate that the attacker spent around $7 million to inflate MAMO’s market price, which they later sold for an estimated loss of about $3.8 million. The assets borrowed during this operation included cbBTC, USDC, WETH, and wstETH, contributing to a significant overall loss.

Details surrounding the fallout

Initially, Blockaid assessed the damage to exceed $4 million, but this number rose sharply as the attacker continued to liquidate their holdings. Ultimately, the attacker converted their profits into DAI, a non-freezable stablecoin, with a staggering amount of $8.7 million now residing in an Ethereum address associated with Tornado Cash.

This incident is not an isolated case. Moonwell has now faced four security breaches in less than a year, all of which were directly linked to pricing discrepancies. In a notable event last October, a market crash triggered approximately $12 million in liquidations and left the platform with about $1.7 million of bad debt.

The following month, implications from a hack on Balancer compounded struggles for Moonwell, resulting in $3.7 million worth of bad debt due to issues with the wrsETH/ETH oracle. The repercussions continued into February of this year when a miscalibrated Moonwell smart contract incorrectly valued cbETH at $1.12 instead of its true worth of around $2,200, which further caused $1.8 million in bad debt.

Broader implications for DeFi ecosystems

This persistent string of vulnerabilities raises significant questions about security measures within DeFi ecosystems. As more users engage with platforms like Moonwell, the risks associated with liquidity manipulation and oracle inaccuracies become vital points of focus.

Furthermore, incidents like the one at Moonwell highlight the critical need for robust mechanisms aimed at thwarting price manipulation and illiquid token exploitation. As DeFi platforms continue to innovate, maintaining security and trust becomes an increasingly complex challenge.

Looking ahead

As the aftermath of Moonwell’s latest breach unfolds, stakeholders will be looking for assurances of improved security measures. The DeFi community is urged to stay vigilant and consider the foundational principles of security and reliability in their future engagements.

Furthermore, this incident serves as a timely reminder to all platforms in the DeFi sector about the necessity of developing stronger price oracles and resilient smart contracts. As the industry evolves, it must prioritize user safety alongside innovative financial solutions.