Moonwell on Base Hit by Ongoing Exploit as Attacker Allegedly Steals $9 Million
Moonwell on the Base network appears to be facing an ongoing exploit, with an attacker allegedly stealing approximately $9 million by manipulating its native MAMO token as collateral to borrow unbacked assets, according to information shared on X by @coinbureau.
The reported incident involves multiple crypto assets, including cbBTC, USDC, wstETH and ETH. At the same time, Moonwell’s native token was reported to have gained 25% within an hour, creating a sharp divergence between the protocol’s reported security incident and the market’s short-term reaction to its token.
The incident remains ongoing, according to the information provided, and the full extent of the impact has not yet been established.
Moonwell Exploit Involves MAMO Collateral
The reported attack centers on the use of MAMO as collateral within Moonwell’s lending infrastructure.
According to @coinbureau, the attacker manipulated the value or treatment of MAMO collateral and used it to borrow assets that were not adequately backed by the underlying collateral. The assets identified in the report include cbBTC, USDC, wstETH and ETH.
In lending protocols, collateral is generally deposited to secure borrowed assets. The value assigned to that collateral is therefore a critical component of the system because it determines how much a user can borrow and whether a position remains adequately collateralized.
If an attacker is able to manipulate the collateral valuation or another markets mechanism governing borrowing limits, it can potentially create a situation in which more assets are withdrawn than the deposited collateral can legitimately support.
The information shared by @coinbureau indicates that this mechanism was central to the reported Moonwell incident.
Reported Losses Reach $9 Million
The reported exploit has resulted in $9 million in stolen assets so far, according to the X post.
The figure represents the amount identified in the report at the time of publication and could change as the incident develops. Because the exploit was described as ongoing, additional transactions or losses could potentially be identified as investigators examine the affected contracts and addresses.
The assets allegedly borrowed by the attacker span several major cryptocurrency categories. cbBTC is a Bitcoin-backed asset used within decentralized finance applications, while USDC is a dollar-pegged stablecoin. wstETH represents a wrapped form of staked Ether, and ETH is the native cryptocurrency of the Ethereum network.
The involvement of several assets means the reported incident extends beyond a single token and could affect liquidity and lending positions associated with the affected Moonwell markets.
Further details about the precise mechanism used in the exploit were not provided in the original post. As a result, the reported manipulation of MAMO remains the central description of how the attacker was able to obtain the unbacked assets.
Moonwell Token Gains 25% During Incident
Despite the reported exploit, Moonwell’s native token was experiencing a sharp increase in markets value.
According to the information shared on X, the token gained 25% in just the past hour while the security incident was still unfolding.
The simultaneous price increase and reported protocol exploit represent two distinct developments. A token’s market price can move independently from the security condition of the underlying protocol, particularly during periods of heightened trading activity.
The reported price movement therefore cryptocurrency does not indicate that the protocol has recovered from the incident or that the reported losses have been reversed.
Ongoing Investigation Into the Attack
The reported incident highlights the risks associated with collateral valuation and lending mechanisms in decentralized finance protocols.
Moonwell operates as a decentralized lending platform, where users can supply assets and borrow against collateral through smart contracts. Such systems rely on automated rules and pricing mechanisms to determine the value of assets and the amount that can be borrowed.
When those mechanisms are manipulated, an attacker may potentially obtain assets without providing collateral of equivalent value.
At the time covered by the original X post, the exploit was described as ongoing and approximately $9 million had reportedly been stolen. The information does not establish the final loss amount or provide a definitive conclusion about the underlying vulnerability.
Security researchers, protocol developers and blockchain investigators typically examine on-chain transactions during such incidents to determine the attacker’s method, identify affected assets and assess whether additional funds remain at risk.
The reported Moonwell incident adds to the broader challenges facing decentralized finance platforms, where smart-contract vulnerabilities and economic manipulation can result in significant losses within a short period.
Writer: Victoria HaleTechnology & Blockchain WriterVictoria Hale writes about blockchain technology, digital infrastructure, and the intersection of emerging technologies with finance. Her articles explore how new protocols and systems are shaping the evolving digital economy.She prioritises clarity and accuracy when explaining technical developments to a general audience.
Check out other news and articles on Google News
Disclaimer:
The articles on HOKA.NEWS are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.
HOKA.NEWS isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember: crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.