Moonwell investigates lending market issue on Base as security firms flag multimillion-dollar exploit
Security firms CertiK and PeckShield estimate losses of around $8.7 million after an attacker manipulated the collateral price of MAMO.
Moonwell, a decentralized lending protocol operating on Coinbase's Base blockchain, is investigating a significant security incident after an attacker exploited a vulnerability in one of its lending markets. Security firms CertiK and PeckShield have both flagged the breach, estimating total losses of approximately $8.7 million. The exploit involved manipulation of the collateral price of MAMO, a token used within the protocol's lending infrastructure.
Moonwell is an open-source, non-custodial lending and borrowing platform built on Base, one of the faster-growing Ethereum Layer 2 networks. The protocol allows users to deposit crypto assets as collateral to borrow other tokens. Price oracle manipulation — the method apparently used in this attack — is a well-documented attack vector in decentralized finance, where bad actors artificially inflate or deflate asset prices to drain funds from lending pools before market mechanisms can respond.
The incident adds to a growing list of DeFi exploits in 2025 and 2026, raising continued questions about the security of lending protocols on emerging Layer 2 networks. Base, despite its association with Coinbase, operates as a permissionless ecosystem, meaning protocols deployed on it bear responsibility for their own security audits and risk management practices.
Moonwell has acknowledged the issue publicly and indicated an active investigation is underway. Users and analysts will be watching closely for the protocol's official post-mortem, any potential recovery efforts, and whether affected users will receive compensation.
Source: The Block