Incident case file
Sign in to watchMoonwell MAMO Market Oracle Manipulation — $9.13M Bad Debt on Base
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn August 27, 2026, an attacker manipulated Moonwell's MAMO lending market on Base between 06:09:45 and 09:30:13 UTC via a donation-style oracle manipulation that bypassed the protocol's supply cap. The gross amount borrowed against the manipulated collateral was $11,028,762; approximately $8.7M was realized and bridged out via CCTPv2, converted through Maker's PSM and the Velora/AVNU swap aggregator into stablecoins. Moonwell's official post-mortem confirmed the resulting bad debt at $9,131,342, the figure the protocol itself recommends as the authoritative loss number. This was the third exploit event for the Moonwell protocol within a 9-11 month period. No compensation plan has been announced. Both attacker addresses carry official Etherscan exploiter tags citing PeckShieldAlert, and the funding relationship between the two (traceable via the 'Funded By' field on Etherscan) confirms the attack chain. Several address-poisoning wallets sending near-zero dust transfers with lookalike prefixes/suffixes were identified targeting Exploiter 2's address in the days following disclosure.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)