Moonwell MAMO Exploit: $8.7M Drained via Price Manipulation

Moonwell MAMO exploit inflating illiquid token collateral on Base to borrow and drain millions in crypto assets

An attacker turned the comparatively small market for the MAMO token into a source of multimillion-dollar loans. Within a few hours, the assailant inflated the value of collateral in Moonwell, borrowed $11 million in assets, and withdrew roughly $8.7 million in USDC from the Base network.

Two Manipulations Combined

According to the published incident post-mortem, the attack occurred on 27 August and combined two distinct manipulations at once. First, the attacker accumulated MAMO and formally deposited roughly 15.1 million tokens into Moonwell, receiving mMAMO receipt tokens in return. A further 53.4 million MAMO were then sent directly to the mMAMO contract without any new shares being issued.

How the Exchange Rate Was Skewed

This direct transfer sharply altered the ratio between the quantity of mMAMO and the assets underlying them. The exchange rate rose roughly 3.68-fold, and the 20-million-MAMO deposit cap offered no protection: Moonwell checked the limit only during a normal issuance of mMAMO and did not account for tokens sent straight to the contract address. Similar share-inflation mechanics had previously been used against other DeFi protocols.

Oracle Manipulation Through Thin Liquidity

In parallel, linked wallets aggressively bought up MAMO on decentralised exchanges. Because of the modest liquidity, the price feeding into Moonwell’s oracle climbed from about $0.0106 to $0.431, a rise of more than fortyfold. As a result, the protocol simultaneously saw more MAMO behind each mMAMO share and a manifold increase in the token’s own value.

An Inflated Position, $11 Million Borrowed

The attacker controlled roughly three-quarters of all issued mMAMO, so the bulk of the artificially created value accrued to their collateral. At the maximum price Moonwell accepted, the position was valued at about $22.3 million and permitted borrowing of around $11.2 million. In total, the assailant executed 18 loans in cbBTC, WETH, USDC, and wstETH worth $11.03 million.

A Market Flagged as Volatile From the Start

The MAMO market appeared on Moonwell in October 2025. In the original proposal, the developers explicitly flagged the token’s high volatility and comparatively small liquidity. It was precisely this shallow market depth that later allowed large purchases to shift the MAMO price so drastically.

Tracing the Funds Off Base

The attacker exchanged the acquired assets across several venues. From Base, 8,729,454 USDC were then withdrawn via Circle’s CCTP in two nearly identical transfers. About 8.728 million USDC arrived on Ethereum, whereupon the entire sum was converted into DAI and sent to a linked wallet. Analysts estimate the growth in the attacker’s tracked balance at roughly $6.785 million relative to the initial capital.

How the Operation Was Funded

To prepare the operation, a linked wallet received about 800 ETH through Tornado Cash. Of these, 799 ETH were exchanged for roughly $1.947 million in USDC, which became the attack’s principal external capital. Subsequent MAMO purchases totalling about $7.5 million were partly financed by the very assets borrowed from Moonwell itself.

Liquidations and Residual Debt

Liquidation of the position began just 32 seconds after the last successful loan. Over the following minutes, 595 liquidations took place, repaying part of the obligations and seizing nearly all of the attacker’s mMAMO. Despite the liquidations, at the time the post-mortem was prepared, roughly $9.13 million in unpaid debt remained in Moonwell, which the team treats as a potential deficit.

Moonwell’s Response

After detecting the problem, Moonwell lowered new borrow caps in the main Base markets to 1 wei, effectively halting lending, and also set minimal deposit caps for MAMO and WELL. The team continues to track the funds and is preparing further measures to restore the markets and address the consequences of the incident.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply