On August 27, the decentralized lending protocol Moonwell, which runs on Coinbase's Base network, lost an estimated $8.7 million to an exploit. But here's the striking part: no smart contract was broken, no code was hacked, and no clever bug was found. The attacker simply made a cheap token look expensive, and borrowed real money against the illusion. Understanding how they did it is one of the most useful things a DeFi user can learn, because this exact attack keeps happening across the industry.
How the attack worked
Every lending protocol needs to know what your collateral is worth. If you want to borrow, it checks the value of what you've put up and lets you borrow against it. To get those prices, protocols rely on "oracles", systems that feed real-world market prices to the blockchain.
The attacker exploited that dependency. Here's the play, step by step:
First, they targeted MAMO, a small, thinly traded token used as collateral in one of Moonwell's markets. Because MAMO had very little trading liquidity, it didn't take much money to move its price dramatically, reportedly pushing it from around $0.01 to $0.43, an eightfold-plus inflation.
Second, with MAMO now appearing far more valuable, the attacker posted it as collateral at that fake, inflated price. Moonwell's oracle believed the pump.
Third, using that artificially inflated "borrowing power," the attacker borrowed genuinely valuable assets from the protocol, including Coinbase Wrapped Bitcoin (cbBTC), USDC, wstETH and ETH, and walked away with them, later consolidating the loot into DAI stablecoins in a single wallet.
That was the entire attack. Pump a cheap token on thin markets, post it as collateral at the fake price, borrow assets with real value, disappear. The trick was price, not code.
Moonwell's response
Security firms CertiK, PeckShield, and Blockaid each independently confirmed losses of roughly $8.7 million. Once flagged, Moonwell moved to contain the damage, setting borrow caps for all its Core Markets on Base to "1 wei", the smallest possible unit, which effectively froze all new borrowing without blocking existing users from withdrawing. It did the same to the supply caps for MAMO and its own governance token, WELL. Isolating a compromised market fast is exactly the right damage-control move, but by then the money was gone.
The uncomfortable context: this keeps happening to Moonwell
Here's what makes this more than a one-off. This was Moonwell's third oracle-related failure in under twelve months. A cbETH pricing misconfiguration in February 2026 created about $1.78 million in bad debt, and a wrsETH oracle malfunction added roughly $3.7 million in late 2025. Add this week's $8.7 million and pricing failures have now cost the protocol over $14 million in ten months. Even more stark: this single morning's exploit drained more than Moonwell's entire annual fee revenue of roughly $8.6 million. And the protocol was still in the middle of compensating victims from the February incident when this one hit.
Why this matters for every DeFi user
The Moonwell hack is a perfect illustration of a truth that's reshaping how experts think about DeFi risk: the biggest losses increasingly come from economic design flaws, not broken code. You can have flawless, audited smart contracts and still lose everything if your protocol trusts a price that can be manipulated. Oracle manipulation is now classified among the most common smart-contract attack types of 2026, and it's hit protocol after protocol this cycle.
For anyone using DeFi, there are concrete lessons here:
- Illiquid collateral is dangerous collateral. If a protocol accepts small, thinly traded tokens as collateral, that's a red flag, those are the easiest prices to manipulate. Prefer lending markets that only accept deep, liquid assets.
- Audits aren't everything. A "fully audited" protocol can still be drained through economic attacks that audits don't always catch. Security is about design, not just clean code.
- Track record matters. A protocol that has been exploited the same way repeatedly, as Moonwell now has, is telling you something about its risk controls. Past incidents are data.
- The tools exist to prevent this. Robust protocols use safeguards like time-weighted average prices (which make it far harder to move a price in a single instant) and refuse to accept easily manipulated tokens as collateral. Their absence is a warning sign.
Why it matters
DeFi's promise is a financial system without trusted middlemen, but that only works if the economic plumbing, especially the price feeds, is sound. The Moonwell exploit is a reminder that in decentralized finance, the attack surface isn't just the code; it's the incentives, the liquidity, and the assumptions baked into how a protocol values things. As the sector matures, protocols that treat oracle and collateral risk as seriously as smart-contract security will survive, and the ones that don't will keep donating their annual revenue to attackers. For users, the takeaway is simple: in DeFi, understanding how a protocol can break is the best protection you have.


