Moonwell Locks Base Borrowing After $8.7M MAMO Attack
Attackers extracted roughly $8.7 million from Moonwell after artificially inflating the price oracle of the low-liquidity MAMO token, then using it as collateral to borrow higher-value assets before converting them to DAI.

Key Takeaways
- Attackers manipulated MAMO oracle prices to drain about $8.7 million in assets from Moonwell.
- Ecosystem partner Zyfai safely auto-rebalanced user funds while MAMO and WELL tokens plunged 15%.
- Moonwell capped Base borrow limits to 1 wei while security teams audit the breach for upcoming fixes.
Automated Safeguards Protect User Funds
Decentralized lending protocol Moonwell has restricted borrowing across all Core Markets on the Base network as it investigates a security incident affecting its MAMO Core Market. Blockchain security firms, including Peckshield, estimate that the attacker extracted about $8.7 million in digital assets by manipulating the collateral price of the MAMO token.
In response to the vulnerability, Moonwell confirmed the active investigation and immediate risk-mitigation measures:
“We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged.”
By dropping the borrow cap to 1 wei, Moonwell suspended new lending activity without pausing contract operations entirely.
The incident triggered automated safeguards across ecosystem partners. Asset management platform Zyfai disabled all Morpho vaults managed by Moonwell as a precaution, confirming that user funds remain safe.
According to Zyfai, automated agents executing its yield maxxing strategy had already begun rebalancing capital out of the affected vaults before the incident escalated. Zyfai reported that its risk system—which tracks real-time on-chain data alongside off-chain signals such as sentiment and social media incident reports—detected multiple converging risk flags. The system triggered risk-based rebalancing while notifying quant teams, who subsequently shut down all Moonwell-related yield opportunities.
Preliminary analyses by security providers Certik, Peckshield, and Blockaid show that the core exploit involved three key phases. First, the attacker targeted the low-liquidity MAMO token, artificially inflating its price oracle metrics. Next, the attacker used the digital asset’s inflated valuation as collateral to borrow higher-value assets—including wrapped bitcoin (cbBTC)—against the protocol. Finally, the attacker converted these assets into DAI stablecoins and consolidated them into a single wallet address.
Following the incident, the WELL token fell roughly 15%, while MAMO dropped by nearly the same percentage. Moonwell and associated protocol security teams continue to audit the breach, with further technical post-mortems expected once the investigation concludes.
