Moonwell currently operates across multiple chains, with Base representing the largest portion of its total value locked.
Moonwell, a multichain DeFi lending and borrowing protocol, has been hit by an exploit on Base, with attackers apparently draining about $8.7 million by manipulating the price of MAMO collateral, CertiK reported Thursday.
We have seen an exploit of @MoonwellDeFi lending market on Base.
Attacker manipulated relatively illiquid MAMO’s collateral price, then borrowed real cbBTC
eg. https://t.co/yOBrkzXzfn~$8.7M has now been aggregated athttps://t.co/7nIcZ59jpw
Stay Vigilant!
— CertiK Alert (@CertiKAlert) August 27, 2026
The attacker targeted MAMO, a relatively illiquid token, and artificially pushed its collateral value higher before using it to borrow real cbBTC from Moonwell’s lending market. CertiK said roughly $8.7 million in stolen funds had been consolidated at an address linked to the attacker.
Moonwell allows users to supply assets and earn variable lending yields or borrow crypto assets against collateral across networks including Base, Optimism, Moonbeam, Moonriver and Ethereum. The protocol’s WELL token is primarily used for governance, staking and ecosystem incentives.
WELL spiked to $0.0045 from $0.00367 before reversing sharply to $0.0033 amid the exploit.
Following the report, Moonwell temporarily restricted borrowing across its Base Core Markets while investigating an issue affecting the MAMO market. The project said the measures are precautionary and that it will provide another update as the investigation progresses.
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating.
As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and…
— Moonwell (@MoonwellDeFi) August 27, 2026
Disclosure: This article was edited by Viontent, see our Editorial Policy

