Moonwell Loses $8.7 Million To MAMO Price Manipulation On Base

Binance
Bitbuy


The lending protocol cut borrow caps on every Base core market to 1 wei after an attacker inflated the price of a thinly traded collateral token and borrowed against it.

Moonwell lost roughly $8.7 million on Thursday after an attacker manipulated the price of MAMO, a small-cap token the lending protocol accepts as collateral on Base, and used the inflated position to borrow real assets.

The protocol had no faster remedy than shutting itself down. Moonwell’s response was to set borrow caps for every core market on Base to 1 wei, which stops new borrowing across the entire deployment, and to set supply caps for MAMO and WELL to the same level. Listing a token with about $1 million in daily volume as collateral is a governance decision, and on Thursday it cost the protocol more than four times its annualized revenue.

Blockchain security firms CertiK and PeckShield both put the loss at about $8.7 million. Blockaid, which flagged the activity as it happened, said it observed 50.6 cbBTC worth more than $4 million drained from Moonwell’s mCBTC market. The proceeds have been consolidated into 8,728,318 DAI at an Ethereum address that was empty until Aug. 21.

Binance

One Wei Kill Switch

“We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating,” Moonwell said at 7:21 a.m. ET, about two hours after the borrowing began. “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact.”

Moonwell had published no further update as of press time. The protocol’s monthly governance call, scheduled before the attack, is set for 17:00 UTC on Thursday with founder Luke Youngblood among the speakers. Youngblood has not commented publicly on the incident.

Illiquid Collateral, Real Loans

MAMO carried a market capitalization of about $6 million and roughly $1.18 million in 24-hour volume before the attack, according to CoinGecko. The token trades mainly in two Base pools, MAMO/cbBTC on Aerodrome SlipStream and MAMO/USDC on Uniswap V4.

MAMO’s thin liquidity made the price cheap to move. “Attacker manipulated relatively illiquid MAMO’s collateral price, then borrowed real cbBTC,” CertiK said. On the Aerodrome MAMO/cbBTC pool, MAMO traded as high as $0.4739 and as low as $0.0101 over the 24 hours through press time, GeckoTerminal data shows, a range of roughly 47 times.

The borrowing itself was ordinary. One Base transaction at 09:20:11 UTC drew 14.33 cbBTC, worth about $1.15 million, out of the mCBTC market for a gas fee of about a cent. The same address, 0x719e, also pulled 560 ETH worth roughly $1.42 million through Moonwell’s WETH unwrapper and moved USDC to Ethereum through Circle’s cross-chain transfer protocol, Basescan records show.

Tornado Cash To DAI

The Ethereum address holding the proceeds was funded on Aug. 21 with about 0.1 ETH from Tornado Cash, then received about 99 ETH across five transfers through the Stargate and Across bridges the same day, Etherscan shows. Two days before the attack it approved and deposited into Moonwell contracts. The funds have not moved since being converted to DAI.

Mamo Says Funds Safe

Mamo, the AI-powered personal finance app on Base whose token was manipulated, said its own contracts were untouched.

“Mamo was not hacked, and no Mamo contracts were compromised,” the project said. “Depositors on Mamo may be temporarily unable to withdraw USDC until liquidity returns to Moonwell. ETH and cbBTC remain available, but could be affected if liquidity falls.”

Mamo accounts route deposits to Moonwell and to Morpho on Base. Funds sitting in Morpho are unaffected, the project said. Moonwell has built out its Morpho vault business alongside its core lending markets.

Second Oracle Failure This Year

This is Moonwell’s second collateral-pricing failure this year. A Chainlink OEV wrapper enabled through governance left the protocol reading the raw cbETH/ETH exchange rate without multiplying by ETH/USD, pricing cbETH at about $1.12 instead of roughly $2,200. Liquidators seized 1,096.317 cbETH and the protocol took on $1.78 million in bad debt, according to Moonwell’s own incident summary. Contributors caught the error in four minutes and cut caps to 0.01, but fixing the oracle required a five-day governance vote and timelock.

Remediation for cbETH suppliers is still unresolved. A counter-proposal filed on Aug. 22 argues the foundation treasury should fund repayments rather than a reserve residual, and a thread opened on Aug. 26 asks what happens to suppliers who were never liquidated but still cannot withdraw.

Oracle and collateral-pricing attacks have hit lending protocols repeatedly this cycle, from Bonzo Lend’s $9 million Supra exploit on Hedera to Ostium’s $18 million vault drain. Aave responded to the KelpDAO exploit by proposing a protocol-wide risk framework.

WELL Slides As TVL Holds

WELL traded at $0.0035, down about 4% over 24 hours, with a market capitalization near $15.9 million, CoinGecko data shows. The token set an all-time low of $0.00274 earlier this month.

Moonwell held $71.5 million in total value locked at press time, $68.2 million of it on Base, with $32.6 million in active loans and $8.6 million in annualized fees, according to DefiLlama. With borrow caps at 1 wei, that lending capacity sits idle until the caps are restored.

Three days before the attack, Moonwell was pitching a wider collateral menu, saying tokenized stocks could become viable collateral on the protocol once Chainlink finishes research into 24/7 price feeds. Coinbase launched tokenized stocks on Base on Aug. 24.



Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*