Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Moonwell Loses $8.7 Million in Third Oracle Failure in Ten Months, More Than Its Entire Annual Revenue

An attacker drained roughly $8.7 million from Moonwell, a DeFi lending protocol on Coinbase's Base network, on Thursday, August 27. Security firms CertiK, PeckShield, and Blockaid all independently confirmed the loss figure, according to Tech Times.
No smart contract was hacked. The attacker exploited how Moonwell prices collateral.
How It Worked
MAMO is the governance token for Mamo, an AI-powered personal finance app built on Base. Before the attack it had a market cap of around $6-7.6 million and roughly $1.18 million in daily trading volume, according to Tech Times and beincrypto.
That's a thin market. CertiK reported the attacker pushed MAMO's price from about $0.0105 to roughly $0.088, an increase of nearly eight times, by aggressively trading against MAMO's two liquidity pools on Aerodrome SlipStream and Uniswap, per Coinpedia and PrimeXBT.
Moonwell's oracle used spot pricing rather than a time-weighted average, so it read the manipulated price as real. The attacker deposited the inflated MAMO as collateral and borrowed genuinely valuable assets against it: cbBTC (Coinbase's wrapped Bitcoin), USDC, wstETH, and ETH.
Blockaid's initial read showed 50.6 cbBTC drained from Moonwell's mCBTC market alone, worth more than $4 million, according to beincrypto. ExVul SkyEye separately flagged a single transaction moving 14.34 cbBTC, worth about $1.15 million, per Coinpedia. CryptoRank's analysts estimated the attacker spent roughly $7 million buying MAMO and later sold part of that position back for about $3.2 million.
The stolen funds, reported as 8,728,318 DAI, sat untouched at a single Ethereum address as of Thursday afternoon, according to Tech Times.
Moonwell's Emergency Response
Moonwell moved fast once the activity was flagged. The protocol slashed borrow caps on all Core Markets on Base to 1 wei, the smallest possible unit on Ethereum-compatible chains, effectively freezing new borrowing without blocking withdrawals, the team said in a public statement quoted by beincrypto: "We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact."
Supply caps on MAMO and Moonwell's own WELL governance token were also tightened. Moonwell's WELL token spiked to $0.0045 from $0.00367 before reversing sharply to $0.0033 amid the exploit, according to PrimeXBT.
As of the reporting on Thursday, Moonwell had not issued a full official accounting of the final losses.
A Pattern, Not an Accident
This is Moonwell's third oracle-related failure in under a year. In November 2025, a wrsETH oracle malfunction created about $3.7 million in bad debt, according to beincrypto. In February 2026, a faulty smart contract mispriced cbETH at $1.12 against its roughly $2,200 market value, leaving about $1.78 million to $1.8 million in bad debt, per Coinpedia and PrimeXBT. Coinpedia reported that bug traced to MIP-X43, a governance proposal enabling Chainlink Oracle Extractable Value wrapper contracts, with code partly written using Anthropic's Claude AI that missed a calculation step.
Tech Times reported that security observers had flagged the February shortfall as still unresolved just two days before Thursday's attack, meaning victims from the earlier incident were still waiting on compensation when the new exploit hit.
Combined, pricing failures have now cost Moonwell more than $14 million over roughly ten months, according to beincrypto's count. Tech Times calculated Moonwell's annualized fee revenue at approximately $8.6 million based on DeFiLlama data, meaning Thursday's single exploit cost the protocol more than a full year's earned income in one morning.
The Broader DeFi Problem
Moonwell isn't unique. beincrypto reported that Term Labs lost roughly $8.5 million to a governance exploit days earlier, and cited unnamed analysts saying DeFi's biggest recent losses increasingly stem from economic design flaws rather than broken code. A separate report cited by beincrypto found audited protocols account for 88% of crypto hack losses since 2025, underscoring that code audits don't catch oracle and collateral-design weaknesses.
The mechanical vulnerability here is straightforward and not seriously disputed by any source. Automated market makers price assets using pooled liquidity, and a pool with only about $1 million in daily volume can be moved dramatically by a well-capitalized attacker. A protocol that accepts a token like that as loan collateral, priced off the same thin market, is exposed by design unless it uses safeguards like time-weighted average pricing.
None of the sources reviewed indicate any law enforcement referral, SEC involvement, or criminal charges tied to this incident. The stolen assets remain unmoved in a single wallet, which leaves open whether the funds can be traced, frozen, or recovered before they're laundered through mixers or bridges. Moonwell's promised full official update on total losses and recovery plans had not been published as of Thursday's reporting.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.