Moonwell cut MAMO borrow caps to 1 wei after an attacker siphoned an estimated $10 million in assets through a price manipulation exploit on Base.
CertiK, the blockchain security firm, flagged the exploit on Aug. 27, reporting that roughly $8.7 million in stolen funds had been consolidated at an address linked to the attacker.
The attacker inflated MAMO's market price, deposited the tokens as collateral into Moonwell's lending market, and borrowed high-value assets against them — including more than $4 million in cbBTC, Coinbase's wrapped Bitcoin product on Base. Before the exploit, the MAMO market operated with a borrow cap of 3 million tokens, a supply cap of 20 million, a 50 percent collateral factor, and a 30 percent reserve factor.
The new borrow cap of 1 wei — the smallest unit of value on Ethereum-compatible chains — effectively reduces borrowing capacity to zero. Moonwell also tightened supply caps on both MAMO and WELL while it conducts a review of the exploit's impact, a process that will determine whether and how the MAMO market reopens.
How the exploit worked
MAMO, the utility and governance token for an AI-driven yield optimization tool integrated with Moonwell, had limited trading volume and shallow order books, making its price vulnerable to manipulation. The attacker inflated MAMO's market price, deposited the tokens as collateral, and borrowed real assets against the artificially inflated value.
The oracle problem
This attack highlights a vulnerability that has affected DeFi lending protocols since the sector's earliest days: oracle risk. Lending protocols rely on price feeds to determine collateral value. When those price feeds can be manipulated — either through direct oracle attacks or by manipulating the underlying market that oracles reference — the entire system breaks down. For large-cap tokens like ETH or BTC, manipulating the spot price enough to fool an oracle is prohibitively expensive. For a token like MAMO, with a fraction of that trading volume, the cost of manipulation drops dramatically.
What this means for DeFi lending
The immediate fallout: Moonwell users with exposure to the MAMO market are in limbo. Borrowers cannot take new positions. Suppliers may find their assets effectively locked until the protocol completes its review. WELL, Moonwell's governance token, spiked to $0.0045 from $0.00367 before reversing sharply to $0.0033 as the exploit unfolded.
Moonwell allows users to supply assets and earn variable lending yields or borrow crypto assets against collateral across networks including Base, Optimism, Moonbeam, Moonriver, and Ethereum. The protocol's WELL token is primarily used for governance, staking, and ecosystem incentives.
The incident adds to a growing list of oracle-related exploits across DeFi lending platforms, raising questions about how protocols can better protect against low-liquidity token manipulation. As Moonwell's review progresses, the outcome will likely shape how other lending protocols on Base and beyond approach collateral risk for newly listed tokens.
This article is for informational purposes only and does not constitute investment advice.