TL;DR
- Moonwell is investigating an issue in the MAMO Core Market on Base. New borrowing was suspended as a precautionary measure.
- Security firms CertiK and PeckShield estimate losses at approximately $8.7 million following manipulation of the MAMO token price.
- The attacker used the inflated MAMO collateral price to borrow real cbBTC from the mCBTC market and consolidated the funds into DAI.
The decentralized lending protocol Moonwell is investigating an incident affecting the MAMO Core Market on the Base network, after blockchain security firms CertiK and PeckShield flagged a multimillion-dollar exploit.
As an immediate measure, the protocol set borrowing limits for all Core Markets on Base to 1 wei, effectively blocking any new borrowing. Supply limits for MAMO and WELL were also adjusted to the same minimum value, while the remaining supply limits remain unchanged.
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating.
As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and…
— Moonwell (@MoonwellDeFi) August 27, 2026
Moonwell: Attack Vector
According to PeckShield’s analysis, the exploit drained approximately $8.7 million, with the stolen funds concentrated in DAI at a single address. CertiK confirmed the same loss estimate and detailed the attack vector: the perpetrator manipulated the collateral price of the MAMO token, a relatively low-liquidity asset, in order to borrow real cbBTC from the mCBTC market. Security firm Blockaid independently identified the same attack mechanism.
The impact was immediately reflected in the prices of tokens associated with Moonwell. The WELL token recorded a drop of around 13% over the past 24 hours, according to CoinGecko data, while MAMO fell approximately 9% in the same period, according to DEX Screener.
Dark Times for the DeFi Ecosystem
The incident adds to what has been one of the most critical periods for DeFi protocols. Since April, multiple projects have accumulated losses exceeding $600 million in exploits that, according to industry analysts, are being amplified by advances in artificial intelligence applied to vulnerability identification.
The most high-profile case was the Kelp DAO exploit, which involved losses of $292 million. Moonwell confirmed that it will publish further updates as more information about the incident becomes available.





