> ## Content Index
> Fetch the complete content index at: https://web3-daily-exploits.ghost.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# Web3 Daily Exploits — 28 Aug 2026: Moonwell’s $8.7M MAMO hit; CCC pair drained on BNB
- URL: https://web3-daily-exploits.ghost.io/web3-daily-exploits-28-aug-2026-moonwell-ccc/
- Published: 2026-08-28T12:09:16.000Z
- Updated: 2026-08-28T12:17:10.000Z
- Description: Moonwell on Base is still the window’s largest confirmed loss after an illiquid-collateral price attack; a separate CashCowCoin drain on BNB Chain took about $117K.
- Author: Jacobo Avariento
- Tags: Daily Brief, Exploits, Web3 Security

Moonwell on Base remains the day’s largest confirmed incident after an attacker inflated illiquid MAMO collateral and borrowed real assets, leaving roughly $8.7 million aggregated in DAI on Ethereum. A separate BNB Chain drain of CashCowCoin’s CCC/WBNB pair extracted about $117,000 through a flawed sell path and reserve sync.

The last 24 hours were not quiet. The dominant story is still Moonwell’s MAMO-collateral event on Base, first flagged on 27 August and still the only eight-figure protocol loss in this window. Security firms now agree on the core shape of the attack — thin-market pricing plus borrowing of real cbBTC, USDC and ETH-family assets — while on-chain analysts continue to argue over how much of the damage came from the price pump alone versus a direct donation into the mMAMO market. Overnight, a smaller but cleanly documented drain hit CashCowCoin on BNB Chain. Required monitors @Phalcon\_xyz and @BlockSecTeam posted no new exploit alerts in this window.

Figures below are USD estimates published by named firms. Treat them as working numbers, not final insurance tallies. Nothing in this briefing is an exploit recipe.

## 1\. Moonwell Core Markets on Base — \~$8.7M extracted, \~$9.15M bad-debt print

**Severity:** High | **Status:** Confirmed; new borrowing halted | **Window:** First reported 27 Aug 2026 \~08:43–10:10 UTC; official statement and follow-up analyses through 27–28 Aug

Moonwell, the Compound-style lending protocol on Base, acknowledged an issue in its MAMO Core Market and cut borrow caps on all Base Core Markets to 1 wei. Supply caps for MAMO and WELL were also set to 1 wei. Other supply caps were left unchanged. The team has not published a full post-mortem as of this briefing.

### What happened

MAMO, a relatively illiquid token tied to the Mamo yield layer built on Moonwell, was listed as collateral on Base with a 50% collateral factor. An attacker moved MAMO’s market price sharply higher, then used the inflated print to borrow real assets from Moonwell markets — principally cbBTC from mcbBTC, plus USDC, WETH/ETH and wstETH. CertiK, PeckShield, Blockaid, SlowMist and GoPlus all describe the same high-level path. PeckShield and CertiK independently put funds aggregated after bridging at about **$8.7 million**, sitting in DAI on Ethereum.

BlockWatchdog later published a more detailed on-chain reconstruction that is not yet an official protocol number. That write-up argues the price pump was only one lever: after the mMAMO supply cap rejected further mints, large ERC-20 transfers of MAMO were sent directly into the market contract. In Compound v2-style accounting, extra cash in the market raises the exchange rate of already-minted mTokens, which BlockWatchdog says multiplied the attacker’s borrowing power. That account puts assets drawn at 71.355 cbBTC, 623.60 WETH, 2,560,000 USDC and 368 wstETH, with protocol bad debt around **$9.15 million** after liquidations recovered roughly $1.8 million. The $8.7 million DAI figure is what reached Ethereum, not necessarily the full hole on Base. Treat the donation/exchange-rate claim as *analyst-confirmed on-chain, protocol-unconfirmed*.

### Protocol / chain / assets

- Protocol: Moonwell Core Markets
- Chain: Base, with proceeds bridged to Ethereum via Circle CCTP and swapped to DAI (Maker PSM)
- Collateral: MAMO ([0x7300b37dfdfab110d83290a29dfb31b1740219fe](https://basescan.org/token/0x7300b37dfdfab110d83290a29dfb31b1740219fe?ref=web3-daily-exploits.ghost.io))
- Borrowed: cbBTC, USDC, WETH/ETH, wstETH

### Attack type

Oracle / thin-market collateral manipulation, with a disputed second lever (direct donation into the mToken market that reprices existing collateral). Not presented by Moonwell or the major firms as a conventional implementation bug in the borrow function itself.

### Key addresses and transactions

- Operator / exploiter (Base): [0x719eae70d4A83f35bF82A2740699F5db84BE919D](https://basescan.org/address/0x719eae70d4A83f35bF82A2740699F5db84BE919D?ref=web3-daily-exploits.ghost.io)
- Attack contract cited by GoPlus: [0xAbDA3Cfe3ce2668b7829AAccBE594Abb326BCe4F](https://basescan.org/address/0xAbDA3Cfe3ce2668b7829AAccBE594Abb326BCe4F?ref=web3-daily-exploits.ghost.io)
- Funds aggregated (Ethereum): [0xD71dD9B6e634412713c47fe7aE02c628e338C384](https://etherscan.io/address/0xD71dD9B6e634412713c47fe7aE02c628e338C384?ref=web3-daily-exploits.ghost.io)
- mMAMO market: [0x2F90Bb22eB3979f5FfAd31EA6C3F0792ca66dA32](https://basescan.org/address/0x2F90Bb22eB3979f5FfAd31EA6C3F0792ca66dA32?ref=web3-daily-exploits.ghost.io)
- mcbBTC: [0xF877ACaFA28c19b96727966690b2f44d35aD5976](https://basescan.org/address/0xF877ACaFA28c19b96727966690b2f44d35aD5976?ref=web3-daily-exploits.ghost.io)
- mUSDC: [0xEdc817A28E8B93B03976FBd4a3dDBc9f7D176c22](https://basescan.org/address/0xEdc817A28E8B93B03976FBd4a3dDBc9f7D176c22?ref=web3-daily-exploits.ghost.io)
- mwstETH: [0x627Fe393Bc6EdDA28e99AE648fD6fF362514304b](https://basescan.org/address/0x627Fe393Bc6EdDA28e99AE648fD6fF362514304b?ref=web3-daily-exploits.ghost.io)
- Example borrow tx (\~14.34 cbBTC): [0xafb6f0fa257b115a5c813bf787b4c1535e63888b1d0dbeb1f3788f557f51798f](https://basescan.org/tx/0xafb6f0fa257b115a5c813bf787b4c1535e63888b1d0dbeb1f3788f557f51798f?ref=web3-daily-exploits.ghost.io)

Additional cbBTC borrows listed by Blockaid include [0x0968…593e](https://basescan.org/tx/0x09687d741d92a2607a1d63014104bbad663347a79d7949d0f3073c84a395593e?ref=web3-daily-exploits.ghost.io), [0xb1fc…4c53](https://basescan.org/tx/0xb1fc41909fed850b8ba0f26223fa6fb57d1ae8b9079b9c1244bdd7c9291e4c53?ref=web3-daily-exploits.ghost.io), [0x9282‧6e63](https://basescan.org/tx/0x9282f7ac2b98f4ac34ca64df6d5a69f10b64a954d1c876d2d4f7c2f9cb776e63?ref=web3-daily-exploits.ghost.io), [0xbf64…616d](https://basescan.org/tx/0xbf64f94b214243eda32a7504d03ccb477d4709803664c450fea5e7c6c544616d?ref=web3-daily-exploits.ghost.io) and [0x7391…2d341](https://basescan.org/tx/0x739108389c545d1f31172dd6ccfdfeb967794d11935c14246935197119f2d341?ref=web3-daily-exploits.ghost.io).

### Status

Moonwell froze new borrows on Base Core Markets. Liquidators, including activity BlockWatchdog attributes to Moonwell’s OEV wrapper, unwound part of the MAMO collateral; the residual position was described as effectively unliquidatable once the print collapsed. The DAI stash on Ethereum was last widely reported as unmoved. No recovery or attacker identification has been confirmed. This is at least the third Moonwell pricing-related incident in roughly ten months (prior public cases include a Nov 2025 wrsETH pricing issue and a Feb 2026 cbETH oracle misconfiguration of about $1.8M).

### Sources

- [Moonwell official statement](https://x.com/MoonwellDeFi/status/2092935617688805818?ref=web3-daily-exploits.ghost.io)
- [CertiKAlert](https://x.com/CertiKAlert/status/2092917519946539061?ref=web3-daily-exploits.ghost.io)
- [PeckShieldAlert](https://x.com/PeckShieldAlert/status/2092929813959049347?ref=web3-daily-exploits.ghost.io)
- [Blockaid detection thread](https://x.com/blockaid%5F/status/2092912022555902094?ref=web3-daily-exploits.ghost.io) and [mUSDC follow-up](https://x.com/blockaid%5F/status/2092914508666753081?ref=web3-daily-exploits.ghost.io)
- [SlowMist](https://x.com/SlowMist%5FTeam/status/2092949807912689915?ref=web3-daily-exploits.ghost.io)
- [GoPlus analysis](https://x.com/GoPlusSecurity/status/2092987438595551445?ref=web3-daily-exploits.ghost.io)
- [BlockWatchdog reconstruction](https://x.com/BlockWatchdog/status/2092935729848442976?ref=web3-daily-exploits.ghost.io)

## 2\. CashCowCoin (CCC) / BNB Chain — \~$117K pair drain

**Severity:** Medium (localized LP) | **Status:** Confirmed on-chain | **Window:** 27 Aug 2026 event; TenArmor, SlowMist and Defimon alerts through 28 Aug 06:08–08:07 UTC

CashCowCoin, a newly launched BNB Chain token/protocol that marketed permanently burned LP permissions, lost the bulk of WBNB in its CCC/WBNB Pancake pair. Independent alerts converge on a loss of about **$117,000 to $117,400**, or \~165.47 WBNB net after any flash-loan repayment.

### What happened

Two reputable monitors describe overlapping but not identical mechanics. They agree on the victim surface: an unverified trading-router proxy and implementation that prices against the spot CCC/WBNB pair and can move pair balances, then call `sync()`.

- TenArmor and SlowMist focus on a flawed `sell()` path. After a CCC o WBNB swap, privileged token logic transfers post-tax CCC out of the pair to the dead address and syncs reserves. That burns sell-side CCC while the reduced WBNB reserve stays in place. SlowMist says that loop was repeated across dozens of sell cycles (cited as 80 iterations).
- Defimon frames the same incident as oracle/reserve manipulation via flash loan: \~416,831 WBNB borrowed from a Moolah market, WBNB donated into the pair, `sync()` to inflate reserves, then buy/sell cycles against the manipulated spot price until the pair fell from \~165.5 WBNB to \~0.018 WBNB.

Those readings are compatible with a single attack that both distorted spot reserves and abused a privileged sell hook. We are not choosing a single root-cause label until the implementation is verified and a shared trace is published.

### Protocol / chain / assets

- Asset: CCC on BNB Chain ([0xb9b845f718c32f37e8af8b887ae4eec816c93ccc](https://bscscan.com/token/0xb9b845f718c32f37e8af8b887ae4eec816c93ccc?ref=web3-daily-exploits.ghost.io))
- Victim pair: CCC/WBNB ([0x1dbe9458a6840784d5defd62c6b71386100097c0](https://bscscan.com/address/0x1dbe9458a6840784d5defd62c6b71386100097c0?ref=web3-daily-exploits.ghost.io))
- Loss asset: WBNB, \~$117K

### Attack type

Reserve manipulation plus privileged sell-side token hook on an unverified router implementation. Flash-loan funding is alleged by Defimon.

### Key addresses and transactions

- Attack tx (TenArmor): [0x89d8050641019a5a75fa3dafb4f64fb153e4dd30c0f1f51d06a6cc206d3ead43](https://bscscan.com/tx/0x89d8050641019a5a75fa3dafb4f64fb153e4dd30c0f1f51d06a6cc206d3ead43?ref=web3-daily-exploits.ghost.io)
- Attacker EOA: [0x7977bdeee3a79dc85cc18739692e796b5d2513c4](https://bscscan.com/address/0x7977bdeee3a79dc85cc18739692e796b5d2513c4?ref=web3-daily-exploits.ghost.io)
- Attack contract: [0x7738b4d7c25e9a7092ae1ab402343b20340daeaf](https://bscscan.com/address/0x7738b4d7c25e9a7092ae1ab402343b20340daeaf?ref=web3-daily-exploits.ghost.io)
- Exploited proxy: [0xf523224c6171f81c54b93f474ed4c78de91241c7](https://bscscan.com/address/0xf523224c6171f81c54b93f474ed4c78de91241c7?ref=web3-daily-exploits.ghost.io)
- Vulnerable implementation (unverified): [0x4287742e50fad6d3351000fd31632412ab29a9ac](https://bscscan.com/address/0x4287742e50fad6d3351000fd31632412ab29a9ac?ref=web3-daily-exploits.ghost.io)
- Profit splitter: [0xbabf70e515ae71a2177e624994a68d10c61d7a9f](https://bscscan.com/address/0xbabf70e515ae71a2177e624994a68d10c61d7a9f?ref=web3-daily-exploits.ghost.io)
- Splitter owner: [0xca882106194ede1a5014c0fa1532234d084b72a9](https://bscscan.com/address/0xca882106194ede1a5014c0fa1532234d084b72a9?ref=web3-daily-exploits.ghost.io)

### Status

Pair liquidity is effectively gone. No official CashCow incident post was located on the required alert accounts. Funds were reported at the splitter contract. No recovery confirmed.

### Sources

- [TenArmorAlert](https://x.com/TenArmorAlert/status/2093164984092274886?ref=web3-daily-exploits.ghost.io)
- [SlowMist TI](https://x.com/SlowMist%5FTeam/status/2093219144896557483?ref=web3-daily-exploits.ghost.io)
- [Defimon Alerts](https://x.com/DefimonAlerts/status/2093248983942467612?ref=web3-daily-exploits.ghost.io)

## Also noted

### StealC loader in fake Qwen model repos — confirmed campaign, no protocol drain

SlowMist published a fresh threat-intel note on 28 August: GitHub repositories impersonating local quantized Qwen 3.8 27B weights. A real Q4\_K\_M 27B package should be tens of gigabytes; the delivered asset was 487 KB and contained a launcher, a renamed LuaJIT interpreter, and an obfuscated Lua script. SlowMist says the official Qwen project was not compromised. After first-stage collection, C2 responses delivered a payload attributed to StealC (browser credentials including a Chrome app-bound encryption bypass, email/WinSCP/Steam secrets, and wallet-related files/extensions). Fallback C2 is read from a Polygon contract via `eth_call`, which lets operators rotate infrastructure on-chain. MistEye clustered 29 similar ZIPs across 23 repos. This is a wallet-adjacent cyber incident, not a DeFi exploit. Source: [SlowMist](https://x.com/SlowMist%5FTeam/status/2093294554623754278?ref=web3-daily-exploits.ghost.io).

### Ledger Ethereum app 1.22.1 — lab reproduction of a patched bug

OneKey’s Anzen team reproduced a transaction-replacement race in Ledger Ethereum app 1.22.1: with a compromised host or malicious dApp, the device screen can show transaction A while signing transaction B. Ledger says the issue was already fixed in app 1.22.2 (13 August) and hardened in Secure SDK 26.6.1 (21 August); bulletin LSB-023 is public; there is no evidence of in-the-wild exploitation; private keys in the secure element were not exposed. Firmware-only updates are not sufficient — the Ethereum app must be updated via Ledger Live to 1.22.3+. This is a disclosed hardware-wallet defect, not a live drain. Sources: [Ledger](https://x.com/Ledger/status/2093293939155489228?ref=web3-daily-exploits.ghost.io); Decrypt coverage of the 27 August exchange.

### Outside this window / not elevated

- Realio.fund key-compromise (25 August, multi-chain RIO sweep) received recycled commentary, not a material new on-chain development in the last 24 hours.
- @DefimonAlerts also relayed an on-chain message from Match Systems claiming a Spanish IP and gambling spend on an unspecified theft. That outreach is unverified in this brief and is not treated as a new exploit.
- @Lookonchain, @ZachXBT and @CyversAlerts posted no new protocol-exploit confirmations in-window. @Phalcon\_xyz and @BlockSecTeam were silent. @Immunefi posted industry commentary (TRM: 201 hacks in H1 2026) rather than a fresh incident.

## Sources & references

- [https://x.com/MoonwellDeFi/status/2092935617688805818](https://x.com/MoonwellDeFi/status/2092935617688805818?ref=web3-daily-exploits.ghost.io)
- [https://x.com/CertiKAlert/status/2092917519946539061](https://x.com/CertiKAlert/status/2092917519946539061?ref=web3-daily-exploits.ghost.io)
- [https://x.com/PeckShieldAlert/status/2092929813959049347](https://x.com/PeckShieldAlert/status/2092929813959049347?ref=web3-daily-exploits.ghost.io)
- [https://x.com/blockaid\_/status/2092912022555902094](https://x.com/blockaid%5F/status/2092912022555902094?ref=web3-daily-exploits.ghost.io)
- [https://x.com/SlowMist\_Team/status/2092949807912689915](https://x.com/SlowMist%5FTeam/status/2092949807912689915?ref=web3-daily-exploits.ghost.io)
- [https://x.com/GoPlusSecurity/status/2092987438595551445](https://x.com/GoPlusSecurity/status/2092987438595551445?ref=web3-daily-exploits.ghost.io)
- [https://x.com/BlockWatchdog/status/2092935729848442976](https://x.com/BlockWatchdog/status/2092935729848442976?ref=web3-daily-exploits.ghost.io)
- [https://x.com/TenArmorAlert/status/2093164984092274886](https://x.com/TenArmorAlert/status/2093164984092274886?ref=web3-daily-exploits.ghost.io)
- [https://x.com/SlowMist\_Team/status/2093219144896557483](https://x.com/SlowMist%5FTeam/status/2093219144896557483?ref=web3-daily-exploits.ghost.io)
- [https://x.com/DefimonAlerts/status/2093248983942467612](https://x.com/DefimonAlerts/status/2093248983942467612?ref=web3-daily-exploits.ghost.io)
- [https://x.com/SlowMist\_Team/status/2093294554623754278](https://x.com/SlowMist%5FTeam/status/2093294554623754278?ref=web3-daily-exploits.ghost.io)
- [https://x.com/Ledger/status/2093293939155489228](https://x.com/Ledger/status/2093293939155489228?ref=web3-daily-exploits.ghost.io)
- [The Block — Moonwell investigates Base market issue](https://www.theblock.co/news/defi/2026-08-27-moonwell-investigates-base-lending-market-issue-412913?ref=web3-daily-exploits.ghost.io)
- [The Defiant — Moonwell loses $8.7M](https://thedefiant.io/news/hacks/moonwell-loses-8-7-million-to-mamo-price-manipulation-on-base?ref=web3-daily-exploits.ghost.io)
- [Basescan example Moonwell borrow](https://basescan.org/tx/0xafb6f0fa257b115a5c813bf787b4c1535e63888b1d0dbeb1f3788f557f51798f?ref=web3-daily-exploits.ghost.io)
- [Etherscan aggregation wallet](https://etherscan.io/address/0xD71dD9B6e634412713c47fe7aE02c628e338C384?ref=web3-daily-exploits.ghost.io)
- [BscScan CCC attack transaction](https://bscscan.com/tx/0x89d8050641019a5a75fa3dafb4f64fb153e4dd30c0f1f51d06a6cc206d3ead43?ref=web3-daily-exploits.ghost.io)

## Editor’s note

Two failure modes dominate this window, and neither is exotic. First: listing a thin token as borrowable collateral without a manipulation-resistant price and without treating direct donations into a cToken/mToken as an economic attack. Moonwell’s 1-wei cap response stopped further borrowing; it did not restore the hole already opened. Second: unverified router implementations that can pull tokens out of an AMM pair and then `sync()` are still shipping on BNB Chain, including on tokens that advertise “burned LP.” Burned LP tokens do not protect reserves if a privileged hook can remove inventory after a swap.

If you hold positions on Moonwell Base, assume Core Market borrowing remains frozen until the team publishes market-by-market solvency. If you traded CCC/WBNB, treat the pair as drained. Hardware-wallet users should confirm the Ethereum app version on-device, not only firmware. This desk will update if Moonwell releases a post-mortem or if the Ethereum DAI stash moves.

*Checked in this window: DefimonAlerts, CertiKAlert, Phalcon\_xyz (no new posts), GoPlusSecurity, SlowMist\_Team, PeckShieldAlert, BlockSecTeam (no new posts), Lookonchain, ZachXBT, CyversAlerts (no hits), Immunefi, Blockaid, TenArmorAlert, Moonwell official. Quiet monitors are recorded as quiet, not as all-clear.*