Moonwell Lost $8.7M, Then Froze Every Base Market to 1 Wei

Moonwell lost about $8.7 million on Base after an attacker inflated a thin collateral token, and its only fix was to freeze every market to 1 wei.

Jan Whitfield News

Moonwell lost roughly $8.7 million on August 27. The response tells you how little room the team had left. Borrow caps on every Core Market on the Base network were set to 1 wei, the smallest unit the chain recognizes, which halts new borrowing across the entire deployment.

The three security firms that flagged the drain, CertiK, PeckShield and Blockaid, put the loss at $8.7 million within hours of each other. None of them pointed at a bug in Moonwell's code. The weak point was a price.

The collateral did the damage

MAMO is a thinly traded token listed as collateral inside Moonwell's lending market on Base. That thinness was the opening. The attacker pushed MAMO's collateral value up, then borrowed real assets against the inflated position, pulling 50.6 cbBTC worth more than $4 million out of the mCBTC market. The proceeds were funneled into DAI and parked at a single address.

DetailFigure
Reported lossAbout $8.7 million
cbBTC borrowed out50.6, over $4 million
Borrow caps set to1 wei, all Base Core Markets
WELL price, 24 hoursDown about 13%
MAMO price, 24 hoursDown about 9%

Why the fix looked so blunt

Setting a borrow cap to 1 wei is not a routine risk parameter. It is a kill switch. Moonwell applied it to all Core Markets on Base, not only the MAMO pool, and dropped supply caps for MAMO and WELL to the same floor. New borrowing across the network stopped cold. WELL, the protocol's governance token, fell about 13% over the following day. MAMO slid roughly 9%.

Not a smart-contract flaw

This is the kind of loss that does not surface when auditors read the contracts line by line. The math held. The inputs did not. It is a familiar shape: an illiquid token accepted as collateral, a price feed that trusts whatever that token last traded at, and an attacker with enough capital to shove a shallow pool. Coinliva has traced the same setup on other chains, from the exploit that wiped out BounceBit's vault to Rhea Finance's lending drain. It also cuts against a comfortable assumption, one worth reading against the finding that code bugs cause most crypto hacks but only a sliver of the losses. The money tends to leave through economic design, not broken syntax.

Moonwell has not said when Base borrowing reopens or whether affected suppliers will be made whole. The 1 wei caps stay in place until it does. For anyone lending on the chain, the thing to watch is whether those caps lift, and what MAMO is allowed to be worth when they do.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Jan Whitfield
Author

Jan Whitfield

Jan Whitfield is the founder and Editor-in-Chief of Coinliva. His coverage focuses on the macro crypto landscape, including regulatory developments, institutional adoption, and structural shifts shaping the digital asset industry. He tracks how policy decisions, ETF flows, and corporate treasury moves connect to broader market dynamics, drawing on primary regulatory filings, official statements, and on-chain data.