What Happened To Moonwell’s MAMO Market?
Decentralized lending protocol Moonwell is investigating an incident affecting its MAMO Core Market on Base after blockchain security firms estimated that an attacker extracted approximately $8.7 million by manipulating the price of the relatively illiquid MAMO token.
Moonwell responded by effectively shutting down new borrowing across its Core Markets on Base while it investigates the incident. The protocol reduced borrow caps for all Core Markets on the network to 1 wei, preventing new loans and limiting the possibility of additional losses.
“As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact,” Moonwell said. “The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged.”
The measures allow Moonwell to restrict further activity without completely shutting down every market on Base. Setting a cap at 1 wei, the smallest denomination commonly used for Ethereum-based assets, makes meaningful new borrowing or deposits into the affected markets effectively impossible.
Moonwell said it is continuing to investigate and will provide additional information when available.
How Did The Attacker Extract $8.7 Million?
Security firms CertiK and PeckShield independently estimated losses at approximately $8.7 million. PeckShield said the stolen funds were ultimately consolidated into the DAI stablecoin at a single blockchain address.
The apparent attack centered on the price used to value MAMO as collateral. CertiK said the attacker manipulated the price of MAMO, an asset with relatively limited liquidity, and then used the inflated collateral value to borrow real cbBTC from Moonwell’s mCBTC market.
Blockaid separately identified the same apparent mechanism, adding support to the assessment that collateral-price manipulation was central to the exploit.
The attack illustrates a recurring vulnerability in decentralized lending markets that accept thinly traded tokens as collateral. If an attacker can move the market price used by a lending protocol without committing comparable capital, the protocol can temporarily treat the manipulated asset as being worth far more than its realizable value.
That can allow the borrower to extract higher-quality collateral such as Bitcoin-backed assets or stablecoins before the manipulated token price returns to normal. The protocol is then left with collateral that may be worth substantially less than the assets borrowed against it.
Investor Takeaway
The Moonwell incident puts attention on collateral quality rather than smart-contract code alone. Lending protocols can face large losses when low-liquidity tokens are accepted as collateral and their pricing mechanisms can be moved faster than risk controls respond.
Why Did WELL And MAMO Fall?
Moonwell’s WELL token dropped about 13% over the previous 24 hours following reports of the incident, while MAMO declined roughly 9% over the same period.
The reaction reflects two different risks. WELL holders are exposed to concerns about Moonwell itself, including the size of any unrecoverable loss and whether additional markets were affected. MAMO holders face the added problem that the token appears to have been directly involved in the collateral-price manipulation.
The decision to reduce supply caps for both MAMO and WELL also shows that Moonwell is limiting additional exposure to those assets while it determines what happened. Other supply caps were left unchanged, suggesting the protocol’s immediate restrictions are concentrated on borrowing activity and the two tokens most closely connected to the incident.
For users with funds already supplied to Moonwell, the next updates will be important in determining whether losses are confined to the exploited market, how existing positions will be handled and whether the protocol can recover any of the transferred assets.
What Does The Exploit Mean For DeFi Lending?
The incident lands during another difficult period for decentralized finance security. Multiple protocols have suffered more than $600 million in reported exploits since April, led by a roughly $292 million attack involving Kelp DAO.
Moonwell’s case is particularly relevant for lending protocols because collateral markets depend on accurate prices and sufficient liquidity during stressed conditions. Accepting smaller tokens can increase borrowing options and attract additional users, but it also creates a larger gap between quoted collateral values and the amount that could actually be sold without moving the market.
Risk controls such as conservative loan-to-value ratios, borrowing limits and supply caps are intended to reduce that exposure. Their effectiveness depends on whether those limits are tight enough before an attacker attempts to manipulate the underlying market.
Moonwell’s immediate reduction of borrow caps may contain further damage, but attention will now turn to its post-incident assessment. Investors and depositors will be watching for confirmation of the final loss, any recovery efforts and whether collateral or oracle parameters are changed before normal borrowing resumes on Base.





