Web3 Daily Exploits — 27 Aug 2026: Moonwell on Base left with ~$9M bad debt after MAMO collateral attack

Moonwell Base Core markets were drained via manipulated MAMO collateral; about $8.7M DAI now sits on Ethereum while protocol-side bad debt is tracking near $9.15M.

Share
Web3 Daily Exploits — 27 Aug 2026: Moonwell on Base left with ~$9M bad debt after MAMO collateral attack

Moonwell on Base took a confirmed collateral-and-oracle hit this morning; about $8.7 million in DAI is now parked on Ethereum. Required alert accounts otherwise posted no new protocol drains in the last 24 hours.

The only large, first-reported incident in this window is Moonwell Base Core. Security firms and the protocol confirmed an issue centered on the illiquid MAMO listing. Figures still differ by what is counted: assets borrowed, liquidator recoveries, value that reached Ethereum, and remaining unbacked debt.

Moonwell (Base) - MAMO collateral manipulation

Severity: High. Status: Confirmed; contained after the fact. Chain: Base, proceeds bridged to Ethereum.

What happened

On 27 August 2026, beginning around 09:13 UTC, an operator used MAMO, a thin Base token listed as Moonwell Core collateral with a 50 percent collateral factor, to borrow liquid assets. CertiK, Blockaid, and PeckShield independently flagged the event. Moonwell acknowledged an issue on the MAMO Core market and said it is investigating.

This is an economic and oracle-accounting attack on a Compound-v2-style market, not a published remote code-execution bug. Early coverage focused on a spot-price pump of MAMO. Later on-chain reconstruction argues a second lever: direct ERC-20 transfers of MAMO into the mMAMO market contract after the official supply cap had already rejected further mints, which would re-price existing mTokens via the cash divided by supply exchange-rate formula.

Loss estimates

  • Confirmed on Ethereum: about $8.7 million in DAI at 0xD71dD9B6e634412713c47fe7aE02c628e338C384, per CertiK and PeckShield. BlockWatchdog measured 8,728,318.997 DAI still unmoved after a Maker PSM swap.
  • Observed borrows: Blockaid first reported about 50.6 cbBTC, then updated to roughly 78.1 cbBTC plus 2.56 million USDC (about $8.79 million). Independent traces also list WETH and wstETH.
  • Protocol hole (likely, pending official accounting): BlockWatchdog put gross draws at 71.355 cbBTC, 623.60 WETH, 2,560,000 USDC, and 368 wstETH (about $11.03 million borrowed). After about $1.8 million recovered by liquidators, remaining bad debt was cited at about $9.15 million at 11:20 UTC, with only about 7.08 MAMO left on the position.

Treat $8.7 million as the clean on-Ethereum figure and about $9.15 million as the current protocol-shortfall estimate, not as two separate thefts.

Attack type

Price manipulation of a low-liquidity collateral asset, combined - if the later reconstruction holds - with uncapped token donations into a Compound-v2 mToken market that inflate the exchange rate. Borrowed assets were then taken against that inflated borrowing power.

  • Funding path reconstructed by BlockWatchdog: Tornado Cash withdrawals (21-23 Aug), about 1.95 million USDC bridged to Base via CCTP (24 Aug), a 10,000 USDC dry run (25 Aug), and a 32-hour MAMO pre-position (26 Aug).
  • On 27 Aug the MAMO oracle print was driven from about $0.0105 toward a peak near $0.43. Pre-attack MAMO inventory across routed pools was estimated around $920,000.
  • The 20 million MAMO supply cap appears to have held for official mints. BlockWatchdog says the comptroller rejected a 1-wei mint at 09:21:07 UTC, after which large MAMO balances were transferred directly to the market contract, lifting cash and the exchange rate (cited 0.0205133 to 0.0754604).
  • The operator borrowed cbBTC, USDC, WETH and wstETH until an AERO borrow failed for lack of liquidity.
  • Exit: about 8.73 million USDC burned on Base CCTP around 09:41-09:42 UTC, swapped to DAI in the Maker PSM at 09:44:47 UTC, then forwarded at 09:45:47 UTC.

The donation-plus-exchange-rate piece is a third-party reconstruction and is not yet in an official Moonwell post-mortem. Treat it as likely, not protocol-certified.

Key addresses and transactions

Operator (Base): 0x719eae70d4A83f35bF82A2740699F5db84BE919D

Aggregation wallet: 0xD71dD9B6e634412713c47fe7aE02c628e338C384

MAMO: 0x7300B37DfdfAb110d83290A29DfB31B1740219fE

mMAMO: 0x2F90Bb22eB3979f5FfAd31EA6C3F0792ca66dA32

mcbBTC: 0xf877ACAFa28c19b96727966690b2f44d35ad5976

mUSDC: 0xEdc817A28E8B93B03976FBd4a3dDBc9f7D176c22

Example cbBTC borrow cited by CertiK: 0xafb6f0fa257b115a5c813bf787b4c1535e63888b1d0dbeb1f3788f557f51798f

Additional tracked mcbBTC borrows:

Protocol response

Moonwell posted at 11:21 UTC that it is aware of an issue on the MAMO Core market on Base. It set borrow caps for all Core markets on Base to 1 wei, and set supply caps for MAMO and WELL to 1 wei. Other supply caps were left unchanged.

On-chain timing from BlockWatchdog: borrow caps at 10:53:43 UTC (about 83 minutes after the last exploit borrow and 71 minutes after CCTP exit); mMAMO supply cap at 11:09:43 UTC. This is containment of new borrows, not a full protocol freeze.

Context, not a new incident: Moonwell already carried a separate older cbETH shortfall from a February 2026 oracle misconfiguration. That hole is not this morning's loss.

Also noted

  • UPDATE (analysis only): GoPlus recapped the 25 August Realio (realio.fund) incident. Official Realio statement: webapp signing stack seized; treasury and custodial wallets swept across five chains. GoPlus figure: 127.9 million RIO (about $6.2 million) moved, about $317,000 cashed out. Root cause described as stolen hot signing keys, not a contract bug. GoPlus, quoting Realio.
  • SlowMist Enjin (~$162k) and FHToken (~$20k) alerts from 26 Aug 03:33-03:41 UTC, plus Phalcon's 17-23 Aug weekly roundup, sit outside this brief's cutoff.
  • DefimonAlerts, CyversAlerts, Immunefi, rekt.news, ZachXBT, and BlockSecTeam had no new exploit alerts in the last 24 hours.
  • A labeled U.S. government / FTX-Alameda seized wallet moved 24.4 BTC (~$1.9 million). Custody transfer, not an exploit.

Sources and references

Editor's note

Listing a thin token as borrowable collateral is an economic control problem. Supply caps that only gate mint() do not, by themselves, stop someone from sending the underlying into the market contract and moving a v2 exchange rate. Until Moonwell publishes official accounting, use the Ethereum DAI balance as the hard number and treat the $9.15 million bad-debt print as a well-sourced working estimate.

Window: about 11:35 UTC 26 Aug 2026 through 11:35 UTC 27 Aug 2026. Quiet elsewhere after required accounts were checked.