Moonwell Exploit on Base: How a MAMO Oracle Manipulation Drained $8.7 Million From the Lending Market

On August 27, 2026 an attacker pulled roughly $8.7 million out of the Moonwell lending protocol on the Ethereum layer Base without breaking a single line of program code. He pushed up the price of a thinly traded token and posted that inflated holding as collateral for loans. If you have funds sitting in a DeFi lending market, the most important question raised by this case is this: which collateral does your own market accept, and who sets its price?
Moonwell exploit on Base: what happened on August 27
Moonwell is a lending protocol, an application into which users deposit crypto assets so that other users can borrow against collateral of their own. It runs on Base, the Ethereum layer 2 operated by Coinbase, and ranks there among the larger addresses for interest-bearing deposits.
The protocol's post-mortem dates the attack sequence to August 27, 2026 between 06:09:45 and 09:30:13 UTC. Within those three hours and change the attacker borrowed assets with a gross value of $11,028,762 from four markets, according to the report. The security firms PeckShield and CertiK put the damage at around $8.7 million the same day; Blockaid initially identified 50.6 cbBTC worth more than $4 million flowing out of a single market. The spread between these figures is explained by the cut-off point: the gross amount describes what was borrowed, the lower figures describe what was actually missing after the liquidations.
… Continue reading the full article at the original source below.



