
An unknown attacker exploited a vulnerability in the Moonwell protocol on the L2 network Base, stealing assets worth approximately $8.7 million. Researchers at CertiK highlighted the incident.
#CertiKInsight 🚨
We have seen an exploit of @MoonwellDeFi lending market on Base.
Attacker manipulated relatively illiquid MAMO’s collateral price, then borrowed real cbBTC
eg. https://t.co/yOBrkzXzfn~$8.7M has now been aggregated athttps://t.co/7nIcZ59jpw
Stay Vigilant!
— CertiK Alert (@CertiKAlert) August 27, 2026
The attacker allegedly manipulated the illiquid collateral of the MAMO token to borrow cbBTC, USDC, wstETH, and ETH, leaving the protocol with unsecured debt.
Coinminutes noted that loss estimates vary and are likely to increase.
Initial on-chain estimates indicated losses of about 50.6 cbBTC, or more than $4 million. Analysts at ExVul estimated the damage at approximately 71.36 cbBTC (around $5.7 million), CertiK at $8.7 million, and several other observers at about $9 million.
Moonwell representatives confirmed the incident, linking it to the main MAMO market. Developers limited lending on the Base network to 1 wei to prevent further debt accumulation.
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating.
As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and…
— Moonwell (@MoonwellDeFi) August 27, 2026
Additionally, supply limits were introduced for MAMO and WELL tokens.
In the hours following the attack, MAMO showed growth, likely due to artificially increased trading volume. Prices later fell, but there was no significant crash.

The native WELL token corrected by 13% to $0.0032.

Earlier, on August 19, developers of the Maya Protocol suspended operations following a hack that resulted in approximately $1.7 million in damages.
