← Radar

Incident case file

Sign in to watch

Moonwell MAMO Market Oracle Manipulation — $9.13M Bad Debt on Base

Incident date Aug 26, 2026Last updated Sep 24, 2026

0 views

ContainedBaseOracle manipulation / donation attackCluster: MOONWELL-BASE-2026-08

Estimated loss

$9.1M

Affected users

1
Group joining is coming soon.

Investigation

80%

Facts and investigation

Ledger

Attacker

Exploiter 1: 0x719eae70d4A83f35bF82A2740699F5db84BE919D; Exploiter 2 (funder): 0xD71dD9B6e634412713c47fe7aE02c628e338C384 (both Etherscan-labeled)

Funds moved to

Converted through Maker PSM and Velora/AVNU aggregator swaps into DAI/USDC; final holdings tracked to the same wallet cluster.

Linked

Exploiter 1 (initial actor): 0x719eae70d4A83f35bF82A2740699F5db84BE919D — Etherscan-tagged 'Moonwell Exploiter 1' with an active PeckShieldAlert warning. Exploiter 2 (funder): 0xD71dD9B6e634412713c47fe7aE02c628e338C384 — Etherscan-tagged 'Moonwell Exploiter 2'. Multiple address-poisoning lookalike wallets (0xD71d927b..., 0xD71dDD2b...) sending dust transfers of $0.000873 were detected mimicking the funder address.

Chronology

1 beat
  1. On August 27, 2026, an attacker manipulated Moonwell's MAMO lending market on Base between 06:09:45 and 09:30:13 UTC via a donation-style oracle manipulation that bypassed the protocol's supply cap. The gross amount borrowed against the manipulated collateral was $11,028,762; approximately $8.7M was realized and bridged out via CCTPv2, converted through Maker's PSM and the Velora/AVNU swap aggregator into stablecoins. Moonwell's official post-mortem confirmed the resulting bad debt at $9,131,342, the figure the protocol itself recommends as the authoritative loss number. This was the third exploit event for the Moonwell protocol within a 9-11 month period. No compensation plan has been announced. Both attacker addresses carry official Etherscan exploiter tags citing PeckShieldAlert, and the funding relationship between the two (traceable via the 'Funded By' field on Etherscan) confirms the attack chain. Several address-poisoning wallets sending near-zero dust transfers with lookalike prefixes/suffixes were identified targeting Exploiter 2's address in the days following disclosure.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)