Newsroom
27 August, 2026 / News / AI / Tags: mamo, moonwell, cbbtc, attacker, caps

An attacker inflated the value of the illiquid MAMO token to borrow real assets from the lending protocol’s markets, prompting emergency caps on new loans
Decentralized lending protocol Moonwell is investigating a multimillion-dollar incident on its Base deployment after an attacker manipulated the price of the relatively illiquid MAMO token and used the inflated collateral to drain assets from its markets. Security firms estimated the losses at approximately $8.7 million.
The attack, which began early on August 27, 2026, targeted Moonwell’s Core Markets on the Base network. According to reports from blockchain security firms, the perpetrator artificially raised MAMO’s market price and then deposited the tokens as collateral to borrow higher-value assets that were never repaid.
Security firm Blockaid first flagged suspicious activity against Moonwell’s mCBTC market. The firm reported that an attacker manipulated MAMO collateral pricing to borrow cbBTC, with an initial observed impact of 50.6 cbBTC valued at more than $4 million.
Other firms later revised the scale of the losses higher. CertiK and PeckShield independently estimated total drains of about $8.7 million. Assets taken included cbBTC, USDC, wstETH and ETH drawn from depositor liquidity. PeckShield noted that the attacker later consolidated the proceeds into DAI at a single address.
On-chain data showed multiple borrow transactions, including one draw of 14.34 cbBTC. The attacker’s wallet subsequently moved most of the funds, leaving only a small residual balance hours later.
Analysts tracking the incident said the attacker pushed MAMO’s price roughly eightfold, from around $0.0105 to about $0.088. One assessment indicated the attacker spent approximately $7 million purchasing MAMO to force the price higher, then sold roughly $3.2 million of the tokens back, accepting a trading loss as the cost of extracting larger sums in real assets.
Moonwell responded by setting borrow caps for all Core Markets on Base to 1 wei, the smallest possible unit, effectively preventing new borrowing while the investigation continues. Supply caps for both MAMO and WELL, the protocol’s governance token, were also reduced to 1 wei. Supply limits for other assets remained unchanged.
WELL initially rose sharply after the incident began before declining. The token traded lower by around 13 percent over the subsequent 24 hours. MAMO also fell roughly 9 percent over the same period.
Moonwell’s total value locked stood near $73 million prior to the event, according to data cited in contemporaneous reports. The protocol stated it would release further details as its investigation progresses.
The August 27 event marks Moonwell’s third significant security issue in nine months. In November 2025, an oracle-related incident created problems involving mispriced assets. In February 2026, a misconfigured cbETH oracle reported the asset at approximately $1.12 instead of its market value near $2,200, generating about $1.78 million in bad debt within minutes. That episode involved code changes that listed an AI model as a commit co-author, prompting discussion about automated development practices in DeFi.
A separate governance incident earlier in 2026 saw an attacker acquire a small quantity of tokens and advance a malicious proposal that placed roughly $1.08 million at risk before emergency mechanisms intervened.
Security researchers have noted that the latest attack centered on the use of a thinly traded token as collateral rather than a direct breach of smart-contract code. The shallow liquidity in MAMO made it feasible for concentrated buying to move the price used by the protocol’s valuation mechanisms.
Moonwell has not yet issued a full technical post-mortem detailing the precise oracle configuration or transaction sequence. The final loss figure remains subject to ongoing review as on-chain activity continues to be examined.









