Base The chain lending protocol Moonwell encountered an incident of collateral price manipulation. After the attacker drove up the price of MAMO, which has weaker liquidity, they used it as collateral to borrow higher-value assets, resulting in a loss of approximately 8.7 million US dollars. Moonwell Subsequently, Base urgently tightened the market lending parameters, essentially halting new loans.
The borrowing limit has been reduced to 1 wei.
Moonwell has reduced the borrowing limit for all Core Markets on Base to 1 wei, which means that new borrowings are almost impossible to proceed with. The agreement also lowered the supply limits for MAMO and WELL to 1 wei as well, while the supply limits for other assets have not been adjusted yet.
Security agencies CertiK and PeckShield both estimated their losses at approximately 8.7 million US dollars. Blockaid previously observed that 50.6 cbBTC were leaked from the protocol's mCBTC market, which, at that time's price, amounted to over 4 million US dollars.
The problem lies in pricing, not in the contract code.
This incident is not like a common smart contract vulnerability attack; rather, it seems to be an exploitation of the pricing infrastructure. The attackers took advantage of the insufficient market liquidity of MAMO to drive up the token prices first, and then used the overvalued collateral to borrow more liquid assets such as cbBTC and USDC.
PeckShield Subsequently, it was reported that the stolen funds were collected into DAI. According to one analysis, the attacker spent approximately 7 million US dollars to buy MAMO, and then sold some of their positions, recovering about 3.2 million US dollars. Although there were losses in the transactions themselves, by overestimating the value of the collateral, the assets borrowed were worth more, allowing them to ultimately make a profit.
Low liquidity collateral risk reappears
This incident once again exposes the dependence of the DeFi lending pair on bid prices and collateral liquidity. If the trading volume of a certain collateral asset is insufficient, concentrated buying orders may rapidly push up prices; once the protocol does not have sufficient protections in place, the borrowing limits can be increased significantly.
Similar issues are not a new occurrence. Reports mention that in 2025, KiloEX also suffered an attack due to vulnerabilities in its price predictor mechanism, resulting in losses of approximately 7.5 million US dollars. Recently, Term Finance also experienced an incident costing about 8.5 million US dollars, indicating that protocol risks do not stem solely from code vulnerabilities.
Moonwell indicates that the investigation into this MAMO market incident is still ongoing. Security researchers such as Blockaid and PeckShield are also continuously tracking related transactions, but the status of fund recovery is currently unclear.











