Moonwell Base Hack Drains $8.7M, What It Means for You
An attacker manipulated the price of MAMO, a thinly traded Base token, and pulled about $8.7 million (USD) out of Moonwell's lending markets on 27 August 2026. Anyone parking crypto in a lending app should notice how fast a low-liquidity asset turned into a security hole.
What actually happened
Security firms CertiK and PeckShield put the loss near $8.7 million (USD) after the attacker manipulated MAMO's price on Base, according to The Defiant. Blockaid tracked the exploit live, saying 50.6 cbBTC, over $4 million (USD), left Moonwell's mCBTC market. One 09:20:11 UTC transfer moved 14.33 cbBTC, about $1.15 million (USD), for roughly a one cent gas fee. The same wallet also took 560 ETH, close to $1.42 million (USD). Moonwell said at 7:21 a.m. ET it was 'actively investigating' and cut every Base core market's borrow cap to 1 wei. The funds were converted into 8,728,318 DAI, per The Block. WELL token dropped about 4% to $0.0035.
How we got here
This marks Moonwell's second collateral pricing failure in 2026. Earlier this year, a Chainlink oracle wrapper mispriced cbETH near $1.12 instead of about $2,200, letting liquidators seize 1,096.317 cbETH and leaving $1.78 million (USD) in bad debt. That fix took a 5 day governance vote, and some suppliers still cannot recover funds. Similar failures hit Bonzo Lend on Hedera for $9 million (USD) and Ostium for $18 million (USD) this cycle. The hack landed as ETH traded near $2,490, down 1.33% in a day, while Ethereum ETFs logged $226 million (USD) in daily inflows, according to Decrypt, their strongest day in 10 months.
Why this matters for you
For everyday wallet users, this is a reminder to check what backs a lending pool before depositing. Moonwell's $71.5 million (USD) in total value locked, mostly on Base, stays frozen until governance lifts the 1 wei borrow caps. Mamo app users may see delayed USDC withdrawals, though ETH and cbBTC remain available. For bonuz.market readers watching DeFi yields, trading volume matters as much as a token's name. Builders should note that oracle fixes needing multi day votes cannot keep up with exploits finished in minutes.
The bigger question
DeFi keeps expanding faster than the governance systems meant to protect it. Moonwell's earlier cbETH fix needed 5 days of voting; this attack finished in minutes. If pricing failures keep repeating across lending protocols, when does slow, careful governance stop protecting users and start becoming the bigger risk? Who should decide when speed matters more than process?
What to watch
Moonwell's monthly governance call ran at 17:00 UTC on Thursday, 27 August 2026, with founder Luke Youngblood listed to speak; he had not commented publicly by press time. A 22 August 2026 proposal seeks treasury funds for cbETH repayments, and a 26 August 2026 thread asks about suppliers still unable to withdraw. Watch for Moonwell's next incident update.






