Moonwell MAMO Exploit: $8.7M Drained via Price Manipulation
An attacker turned the comparatively small market for the MAMO token into a source of multimillion-dollar loans. Within a few hours, the assailant inflated the value of collateral in Moonwell, borrowed $11 million in assets, and withdrew roughly $8.7 million in USDC from the Base network.
Two Manipulations Combined
According to the published incident post-mortem, the attack occurred on 27 August and combined two distinct manipulations at once. First, the attacker accumulated MAMO and formally deposited roughly 15.1 million tokens into Moonwell, receiving mMAMO receipt tokens in return. A further 53.4 million MAMO were then sent directly to the mMAMO contract without any new shares being issued.
How the Exchange Rate Was Skewed
This direct transfer sharply altered the ratio between the quantity of mMAMO and the assets underlying them. The exchange rate rose roughly 3.68-fold, and the 20-million-MAMO deposit cap offered no protection: Moonwell checked the limit only during a normal issuance of mMAMO and did not account for tokens sent straight to the contract address. Similar share-inflation mechanics had previously been used against other DeFi protocols.
Oracle Manipulation Through Thin Liquidity
In parallel, linked wallets aggressively bought up MAMO on decentralised exchanges. Because of the modest liquidity, the price feeding into Moonwell’s oracle climbed from about $0.0106 to $0.431, a rise of more than fortyfold. As a result, the protocol simultaneously saw more MAMO behind each mMAMO share and a manifold increase in the token’s own value.
An Inflated Position, $11 Million Borrowed
The attacker controlled roughly three-quarters of all issued mMAMO, so the bulk of the artificially created value accrued to their collateral. At the maximum price Moonwell accepted, the position was valued at about $22.3 million and permitted borrowing of around $11.2 million. In total, the assailant executed 18 loans in cbBTC, WETH, USDC, and wstETH worth $11.03 million.
A Market Flagged as Volatile From the Start
The MAMO market appeared on Moonwell in October 2025. In the original proposal, the developers explicitly flagged the token’s high volatility and comparatively small liquidity. It was precisely this shallow market depth that later allowed large purchases to shift the MAMO price so drastically.
Tracing the Funds Off Base
The attacker exchanged the acquired assets across several venues. From Base, 8,729,454 USDC were then withdrawn via Circle’s CCTP in two nearly identical transfers. About 8.728 million USDC arrived on Ethereum, whereupon the entire sum was converted into DAI and sent to a linked wallet. Analysts estimate the growth in the attacker’s tracked balance at roughly $6.785 million relative to the initial capital.
How the Operation Was Funded
To prepare the operation, a linked wallet received about 800 ETH through Tornado Cash. Of these, 799 ETH were exchanged for roughly $1.947 million in USDC, which became the attack’s principal external capital. Subsequent MAMO purchases totalling about $7.5 million were partly financed by the very assets borrowed from Moonwell itself.
Liquidations and Residual Debt
Liquidation of the position began just 32 seconds after the last successful loan. Over the following minutes, 595 liquidations took place, repaying part of the obligations and seizing nearly all of the attacker’s mMAMO. Despite the liquidations, at the time the post-mortem was prepared, roughly $9.13 million in unpaid debt remained in Moonwell, which the team treats as a potential deficit.
Moonwell’s Response
After detecting the problem, Moonwell lowered new borrow caps in the main Base markets to 1 wei, effectively halting lending, and also set minimal deposit caps for MAMO and WELL. The team continues to track the funds and is preparing further measures to restore the markets and address the consequences of the incident.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.