Moonwell's $8.7M MAMO Exploit: How an Illiquid Governance Token Became an $11 Million Borrow Key on Base
An attacker pumped the price of Moonwell's illiquid MAMO governance token roughly eightfold — from $0.0105 to $0.088 — deposited it as overvalued collateral, and borrowed approximately $11 million in liquid assets including cbBTC, WETH, USDC, and wstETH across 18 transactions. Security firms CertiK and PeckShield estimated net losses at $8.7 million, exceeding Moonwell's entire annual fee revenue of $8.6 million. No smart contract code was broken. The attacker spent roughly $7 million on the manipulation and lost an estimated $3.8 million on that leg — a rational price for an oracle reading that unlocked far more in liquid borrows. It was Moonwell's fourth exploit in under a year.
This article is published for educational and informational purposes only. It does not constitute legal, financial, or investment advice. Nothing in this article should be relied upon as the sole basis for any decision relating to the security, investment value, or legal standing of any protocol or digital asset.
Information published on any code vulnerabilities must not be used to attack, test, or probe any protocol or system without explicit authorisation from its owner. Use of this content is subject to our Terms of Service and Privacy Policy.
What happened
On August 27, 2026, an attacker drained approximately $8.7 million from Moonwell's Base lending market without breaking a single line of smart contract code. The mechanism was price manipulation: the attacker pumped the price of MAMO, Moonwell's illiquid governance token, roughly eightfold - from approximately $0.0105 to nearly $0.088 - deposited it as collateral at the inflated valuation, borrowed heavily against that fictitious value, and abandoned the position. What remained was a portfolio of real, liquid assets owed by wallets that had no intention of repaying.
The operation was seeded with roughly 799 ETH. From that base, the attacker executed 18 distinct borrow transactions across Moonwell's Base Core Markets, pulling out cbBTC, WETH, USDC, and wstETH. According to Moonwell's own post-mortem, gross borrowing reached approximately $11.03 million, with remaining obligations estimated at $9.13 million once the dust had settled. Security firms CertiK and PeckShield placed net losses at around $8.7 million, the figure Moonwell has since used in its public communications.
Liquidations began just 32 seconds after the final borrow transaction, a detail that underlines the attacker's lack of interest in managing the position. The collateral was always destined to be worthless on exit; the borrowed assets were always the real objective. As Yahoo Finance noted, Moonwell lost $8.7 million without the protocol's code being broken.
In response, Moonwell set borrow caps for all Base Core Markets to 1 wei, effectively halting all new borrowing. Supply caps for both MAMO and WELL were also set to 1 wei. According to Protos, this was the protocol's fourth exploit in under a year, following oracle-related incidents in November 2025 and February 2026, and a governance-related attack in March 2026.
Root cause
The root cause was the acceptance of an illiquid, governance-only token - MAMO - as collateral in a lending market whose oracle faithfully reported a spot price that could be manipulated cheaply relative to the value of assets that could be borrowed against it. No invariant was violated. The oracle was not lied to in a cryptographic sense. It reported a genuine on-chain market price. The flaw was in the architecture: a token with minimal liquidity depth, and therefore a low manipulation cost, was assigned collateral eligibility in a market holding tens of millions of dollars in liquid assets.
The oracle's accurate, exploitable reading
Lending protocol oracles price collateral by observing real markets. For deep, liquid tokens - cbBTC, WETH, USDC - market depth is vast. Moving the price of Ethereum by even a fraction of a percent requires hundreds of millions of dollars of sustained buying pressure. That economic barrier makes the manipulation cost exceed any plausible lending profit, and so oracle manipulation attacks against liquid assets are rare and expensive.
MAMO is not a liquid asset. It is a governance token whose trading activity is thin. When the attacker deployed approximately $7 million in buy pressure against MAMO, the token's price rose from around $0.0105 to nearly $0.088 - an approximately eightfold increase, as reported by Cryptopolitan. At that elevated price, the MAMO deposited as collateral appeared - to Moonwell's oracle - to be worth far more than was recoverable in a forced liquidation. The attacker then borrowed liquid assets against this inflated reading and walked away.
The collateral-value gap
The fundamental problem is the divergence between two values that a lending protocol must treat as equivalent for its collateral model to hold:
// What the oracle saw:
mamo_oracle_price = $0.088 // real spot price after $7M buy pressure
mamo_deposited = [large amount]
mamo_collateral_value = mamo_deposited * $0.088
= ~$11.03M (reported)
// What the market could actually absorb on liquidation:
mamo_liquidation_depth = thin
mamo_realistic_exit = ~$3.2M (estimated, after attacker sell-down)
// The gap - assets borrowed against collateral that could never cover them:
borrowed_liquid_assets = cbBTC + WETH + USDC + wstETH
gross_borrows = ~$11.03M across 18 transactions
obligations_remaining = ~$9.13M
net_protocol_loss = ~$8.7M (CertiK / PeckShield estimate)
// Liquidations begin 32 seconds after final borrow.
// Collateral is already unwinding. Recovery is partial at best.Why a collateral factor alone was insufficient
Lending protocols apply a collateral factor - typically a haircut of 20–50% - to account for price volatility during liquidation. A collateral factor of, say, 50% on MAMO means the protocol would only allow borrowing against half the oracle-reported value. But collateral factors are calibrated for normal market volatility, not for the scenario in which the oracle price itself has been driven up eightfold specifically to inflate borrowing capacity. When the base price is fabricated, a percentage haircut applied to that fabricated price still produces a dangerously inflated borrowable value. The collateral factor assumes a genuine market price as its input. It provides no protection when that input is the product of deliberate manipulation.
The structural economics of the attack
The attack's economic logic is straightforward. The cost of manipulating a thin market is bounded by the market's liquidity depth. The profit from that manipulation is bounded by the amount of liquid collateral the lending protocol holds. When the ratio of lendable assets to manipulation cost is sufficiently high, the attack is profitable even accounting for the manipulation loss on the exit side. In this case:
seed_capital = ~799 ETH
manipulation_spend = ~$7M (buying MAMO to inflate price)
mamo_exit_loss = ~$3.8M (selling MAMO after borrowing, price crashed)
gross_borrowed = ~$11.03M (cbBTC, WETH, USDC, wstETH)
net_loss_to_protocol = ~$8.7M
attacker_net_gain ≈ $8.7M - $3.8M manipulation loss
≈ $4.9M estimated profit
// The protocol's annual fee revenue: ~$8.6M (TechTimes)
// A single exploit erased more than one full year of earnings.What could have been done
- Apply liquidity-depth requirements before approving collateral. Every token accepted as collateral should pass a minimum liquidity threshold - a measure of how much capital it takes to move the price by a defined percentage on available venues. A token whose entire on-chain liquidity is thin enough to move eightfold on $7 million of buying pressure has no business serving as collateral in a market that holds hundreds of millions of dollars. Governance tokens, by design, are not optimised for trading liquidity. Their eligibility as collateral should be evaluated on that basis, not on whether they have a market price.
- Use time-weighted average price oracles, not spot. A TWAP oracle smooths the reported price over a window of time, typically 30 minutes or more. A sudden eightfold price spike that lasts only as long as necessary for the attacker to post collateral and execute borrows would register as a modest anomaly in a TWAP reading, not as a sustained new valuation. Spot oracles are, by definition, real-time: they report the current price truthfully. When that current price is the product of concentrated manipulation, a TWAP-based collateral valuation reports a meaningfully lower and more defensible number.
- Implement borrow caps tied to realistic liquidation depth, not oracle value. Even after accepting a token as collateral, the maximum amount that can be borrowed against it should be bounded by what the market can realistically absorb in a forced liquidation - not by what the oracle currently reports multiplied by a static collateral factor. A dynamic borrow cap calibrated to on-chain liquidity depth, updated continuously, would have limited the amount of cbBTC and USDC the attacker could extract regardless of the oracle price at the time of deposit.
- Apply circuit breakers on anomalous price movements for collateral tokens. A price movement of 8x in an asset that has been accepted as collateral is an observable on-chain event. A circuit breaker that pauses or restricts new borrowing against any collateral asset whose price has increased by more than a defined threshold (e.g. 50%) within a rolling window would have interrupted this attack at the point of collateral deposit, before any borrows were executed. Price anomalies of this magnitude have no legitimate explanation in a governance token context.
- Separate governance tokens from borrowable-collateral eligibility entirely. The cleanest mitigation is the most direct one: protocol governance tokens - MAMO and WELL - should not be eligible as collateral in lending markets where real assets can be borrowed against them. Governance tokens exist to vote, not to serve as reserves. Their price is influenced by sentiment, not by the deep market activity that makes a token resistant to manipulation. A governance token can be held in a wallet, staked for voting, or used in protocol incentive structures; it should not be the key to an unlocked borrow position in a liquid market.
- Investigate and address the prior pattern before accepting new collateral types. Moonwell had experienced three prior exploits in under a year by the time this attack occurred. Each incident increases the information available about how the protocol's collateral and oracle architecture can be abused. A structured review of collateral eligibility and oracle design - conducted after any major incident and before new collateral types are listed - would have provided an opportunity to identify the MAMO manipulation surface before it was exploited.
Lessons for the industry
The Moonwell exploit belongs to a well-documented attack class: oracle manipulation via illiquid collateral. The earliest prominent examples date to 2020. It has been executed against Cream Finance, Mango Markets, Euler Finance, and numerous smaller protocols in the years since. The mechanics are the same in every case: find a token with thin liquidity, pump its price, use the inflated price to borrow real assets, exit before liquidation. The attack does not require a code flaw. It requires a collateral list that includes tokens whose price can be moved for less than the value of what can be borrowed against them.
The MAMO case adds one detail worth examining carefully: the attacker lost money on the manipulation itself. They spent approximately $7 million buying MAMO and recovered approximately $3.2 million when they sold. The $3.8 million loss on the manipulation leg was the cost of purchasing the oracle reading they needed. This is not unusual. What is notable is that a loss of $3.8 million was a rational price to pay, because the borrowed assets on the other side were worth roughly $8.7 million. The attack was profitable precisely because the ratio of liquid lending capacity to manipulation cost was high enough to absorb a significant manipulation loss and still generate a net gain.
That ratio is not a property of the attacker. It is a property of the protocol's collateral design. The moment Moonwell accepted MAMO as collateral in a market holding cbBTC and USDC, it created a lending facility whose manipulation cost was bounded by MAMO's thin order books, while its profit potential was bounded by the depth of its liquid reserves. The disparity between those two numbers is readable on-chain by anyone who cares to look.
The recurring nature of Moonwell's incident history - four exploits in under a year - raises a harder question for the industry. Individual incidents can be attributed to oversight, complexity, or novel attack vectors. A pattern of incidents at the same protocol over the same period suggests a structural feature of the protocol's security posture: that the lessons of prior exploits are not being systematically incorporated into collateral policy, oracle architecture, or monitoring infrastructure before new exposure surfaces are introduced. Security is not a state achieved at deployment. It is a property that has to be maintained across the full lifecycle of a protocol's collateral and oracle decisions.
For the broader DeFi ecosystem, the takeaway from Moonwell's August 2026 incident is familiar but worth repeating: a lending protocol is only as secure as its weakest collateral. The depth and liquidity of every listed collateral asset directly determines the economic floor for an oracle manipulation attack. When governance tokens - assets that exist for voting, not for trading - are added to collateral lists in markets with meaningful liquid reserves, that floor drops to whatever it costs to move a thin order book. In this case, it cost $7 million to unlock $11 million in liquid assets. That trade will be executed by any actor who discovers it, because the profit motive is written into the collateral architecture itself.
- 01The Block, Moonwell investigates lending market issue on Base
- 02Yahoo Finance, Moonwell lost $8.7 million without code being broken
- 03Crypto.news, Moonwell MAMO exploit drains $8.7M from Base lending market
- 04Coin360, Moonwell MAMO exploit drains about $8.7 million
- 05Moonwell Forum, Post-mortem of MAMO market incident on Base
- 06TechTimes, Moonwell oracle exploit exceeds full annual revenue
- 07Cryptopolitan, Attackers hit Moonwell for almost $9M in price manipulation exploit
- 08Protos, Moonwell's latest $9M attack marks four incidents in a year