Moonwell lending protocol on Base hit by suspected exploit tied to MAMO collateral
Security & Exploits ·
An attacker has borrowed roughly $9M in assets from Moonwell on Base, with 50.6 cbBTC drained so far in what appears to be a collateral-manipulation exploit.
The attack centers on MAMO, which was reportedly used as collateral to draw down borrowing capacity far beyond its actual backing, allowing the attacker to extract assets including cbBTC from the protocol's lending pools. The activity was flagged as a possible exploit, with the borrowing pattern and collateral behavior consistent with a manipulation of how MAMO is priced or valued within Moonwell's lending markets, according to a report on X.
Moonwell operates as a lending protocol on Base, the Coinbase-incubated Ethereum Layer 2 network that has positioned itself as low-cost settlement infrastructure for both retail DeFi and institutional finance. Exploits that hinge on collateral valuation are a recurring risk in lending markets: if a token's price or liquidity can be manipulated, an attacker can inflate its apparent value as collateral and borrow far more than the position is actually worth, leaving the protocol holding bad debt once the collateral is seized or liquidated.
A separate account of the incident corroborates the core figures, describing the event as a lending protocol potentially exploited via collateral manipulation that enabled more than $9M in unauthorized borrowing, matching the scale of assets drawn from Moonwell.
The 50.6 cbBTC drained represents one confirmed slice of the total assets extracted, though the reporting indicates the borrowing and draining activity was ongoing or only partially tallied at the time of disclosure, meaning the final scope of losses had not yet been established.
What remains unresolved is whether Moonwell or Base-level infrastructure has taken any mitigating action, such as pausing markets or freezing the MAMO collateral mechanism, and whether the attacker's borrowed assets have been moved off-chain or laundered through bridges. Also unclear is the root cause of the collateral manipulation and whether other assets beyond cbBTC were affected by the same borrowing exploit. Confirmation from Moonwell itself, along with a full post-mortem detailing the exact mechanism and total funds at risk, has not yet surfaced in available reporting.