Moonwell, a lending protocol operating across Base, Optimism, Moonbeam, Moonriver and Ethereum, is dealing with the aftermath of an exploit that turned a thin market into an exit. The attacker targeted MAMO, a relatively illiquid token, and artificially pushed its collateral value higher before using it to borrow real cbBTC from the Moonwell lending market.
According to CertiK, roughly $8.7 million in stolen funds have already been consolidated at an address linked to the attacker. The mechanics are as old as lending itself: make the thing you own look expensive, borrow against it, and let the lender keep the bag when the price snaps back.
And snap back it did. The protocol's WELL token, used for governance, staking and ecosystem incentives, spiked to $0.0045 from $0.00367 during the incident before reversing sharply to $0.0033 as the exploit unfolded.
Following the report, Moonwell temporarily restricted borrowing across its Base Core Markets while investigating the issue affecting the MAMO market. The project says the measures are precautionary and that it will provide another update as the investigation progresses.
A lending market believed a number because an oracle produced it, and $8.7 million walked out the door while the number was still green. Automated trust is still trust. The guarantee Vulpine offers points the other way - end-to-end encryption whose strength comes from standard math you can verify yourself, not from a feed that keeps insisting everything is fine.