The Base chain-lending agreement Moonwell was subjected to an incident of collateral price manipulation. The attackers borrowed higher-value assets as collateral after placing higher and less mobile MAM prices, resulting in losses of approximately $8.7 million. Moonwell then urgently tightened the base market lending parameters and largely suspended additional borrowing.
Loan ceiling reduced to 1 wei
Moonwell has lowered the borrowing ceiling for all Core Markets on Base to 1wei, which means that new borrowings can hardly continue. The agreement also reduced the supply ceilings for MAMO and WELL to 1 wei, while the supply ceilings for other assets remained unchanged.
The security agencies CertiK and Peck Shield both estimated losses of approximately $8.7 million. Blockaid previously monitored that 50.6 cbBTCs out of the MCBTC market of the agreement exceeded $4 million at current prices.
The problem is pricing, not contract code.
The incident was not a common smart contract breach attack, more like the use of pricing infrastructure. The attackers, by taking advantage of the MAMO market ' s lack of liquidity, pushed up the token offer and borrowed more liquid assets such as cbBT and USDC from overvalued collateral.
Peck Shield subsequently indicated that stolen funds had been classified as DAI. According to one analysis, the attackers spent approximately $7 million on the purchase of MAMOs and subsequently sold some of the warehouses and recovered about $3.2 million. Although the transaction itself suffered a loss, the assets borrowed through overvaluation of the collateral were of higher value and ultimately profitable.
Low liquidity collateral risk recurrence
The incident once again revealed DeFi's dependence on price feeding and collateral liquidity. If a mortgage asset is not traded in sufficient depth, a centralized purchase may quickly push up the offer; as soon as the agreement does not provide sufficient protection, the level of borrowing will be magnified.
Similar problems do not arise for the first time. In 2025, KiloEX was also reported to have been attacked for the weakness of the price prediction machine, resulting in losses of approximately $7.5 million. Some $8.5 million of DeFi events have also occurred recently in Term Finance, which shows that the protocol risks do not come from code loopholes alone.
According to Moonwell, investigations into the MAMO market incident are continuing. Security researchers such as Blockaid and Peck Shield are also following up on related transactions on an ongoing basis and the recovery of funds is not yet clear.
