Moonwell lost about $8.7 million on Base on Thursday. As of early Friday the proceeds sat in a single Ethereum address holding about 8.73 million DAI. CertiK and Blockaid attributed the attack to price manipulation of MAMO, a thinly traded token Moonwell accepted as collateral, and PeckShield put the loss at $8.7 million. Onchain records show the attacker never had to defeat the protocol’s supply limit, because the route they used does not check it.

Moonwell limits how much MAMO can be supplied through its normal deposit route, and that limit is checked when a depositor mints shares. At 09:12:59 UTC the attacker supplied 7.1 million MAMO that way, taking 346 million shares. Then they stopped depositing. At 09:19:59 UTC they sent 34,910,397 MAMO straight to the market contract, and 70 seconds later another 18,482,894. Each burned 120,017 gas and emitted exactly two events, an interest accrual and a token transfer. Neither created a single share.

What That Did to the Shares

Moonwell runs on Compound v2 code, which values a share as the pool’s holdings divided by shares outstanding, so adding 53 million tokens to the numerator lifts all of them at once. The market’s stored exchange rate was 0.0205 in the block before the first transfer and 0.0755 once both had landed, about 3.7 times higher. The 346 million shares bought for 7.1 million MAMO could now claim roughly 26 million. Against that inflated collateral the attacker borrowed cbBTC, USDC and wstETH.

Not the First Time

Moonwell said in a post on X that it was investigating, and that “borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact.” New borrowing is frozen across those markets.

Its forum documents pricing trouble since October 2025, when a crash left bad debt its risk adviser attributed partly to gaps between its price feeds and the market. Weeks later an oracle fault left wrsETH “drastically overvalued” and let an attacker borrow millions, and Moonwell noted that “this was the same user responsible for the 10/10/25 exploit.” In February a cbETH configuration contained “a critical error” that priced the token near a dollar.

What It Cost

On June 8 a contributor proposed automated safeguards, among them a circuit breaker under which “If an oracle price deviates beyond a defined threshold from a secondary reference or established historical range, the affected market pauses automatically.” The thread drew three replies and no vote, and its author agreed on June 15 to do an earlier phase first. Whether the design would have caught this attack is unclear; it was never specified in enough detail to say.

Moonwell’s total value locked fell from about $73 million before the attack to about $45 million by early Friday, while borrowings rose. The sum taken is several times the roughly $1.9 million in protocol revenue DefiLlama records for the past year. Aave said in May it would add security reviews to its listing process after April’s $293 million KelpDAO exploit.

At least one depositor from February is still waiting. On August 23, four days before this attack, they wrote on the forum that they had “simply supplied cbETH” and were “currently unable to withdraw it”

Related Listen: Treasury Puts DeFi On Notice as Roman Storm Trial Drags On