Moonwell (MAMO) (2026) — Crypto Hack
Not RecoveredAttacker inflated the price of illiquid MAMO ~8-40x and exploited a collateral-accounting flaw (direct transfers to the mMAMO contract bypassing the supply cap) to borrow real cbBTC, USDC, wstETH and ETH from Moonwell on Base.
Summary
Attacker inflated the price of illiquid MAMO ~8-40x and exploited a collateral-accounting flaw (direct transfers to the mMAMO contract bypassing the supply cap) to borrow real cbBTC, USDC, wstETH and ETH from Moonwell on Base.
How It Was Compromised — DeFi via Oracle Price Manipulation / Collateral Accounting Exploit
On August 27, 2026, an actor exploited Moonwell's MAMO market on Base by combining collateral-accounting inflation with manipulation of MAMO's oracle price. The attacker supplied 15.09M MAMO, then transferred another 53.39M MAMO directly into the mMAMO contract without minting receipt tokens, raising the exchange rate ~3.68x and bypassing the supply cap. MAMO's price feed rose from ~$0.0106 to ~$0.4313 while the attacker bought ~94.3M MAMO on thin liquidity. The inflated collateral supported 18 borrows of cbBTC, WETH, USDC and wstETH (~$11M gross). CertiK and PeckShield put the loss at ~$8.7M. Moonwell set borrow caps on every Base core market to 1 wei and supply caps for MAMO and WELL to the same level. Moonwell's post-mortem estimated ~$9.13M in remaining borrower obligations.
Fund Flow & Laundering Analysis
The attacker burned ~8.73M USDC on Base via Circle CCTP, received ~8.73M USDC on Ethereum, converted it to canonical DAI through Velora, and held it at an address funded from Tornado Cash (0x719e...919D principal account; 0xD71d...C384 operational account).