Logo
My Crypto News AI

How Thinly Traded Tokens Became a $8.7M Backdoor Into DeFi Lending

On August 27, decentralized lending protocol Moonwell lost approximately $8.7 million after an attacker exploited a weakness that had nothing to do with buggy code and everything to do with how thinly traded tokens can be weaponized as collateral. The attacker inflated the price of MAMO, a relatively illiquid token on the Base network, then used that artificially puffed-up collateral to borrow real cbBTC (Coinbase's wrapped bitcoin) from Moonwell's lending market. The incident marks Moonwell's third security breach in 2026 and highlights a blind spot in DeFi that even well-audited protocols struggle to defend against.

What Happened in the Moonwell MAMO Exploit?

The attack unfolded in a straightforward but devastating way. The attacker manipulated MAMO's collateral price to inflate its apparent value on Moonwell's platform, then leveraged that inflated collateral to borrow real cbBTC from the protocol's mCBTC market. Once the attacker had the borrowed cbBTC in hand, the funds were converted into DAI stablecoin (a cryptocurrency pegged to the US dollar) and funneled into a single wallet address. Security firms CertiK, PeckShield, and Blockaid independently traced the same attack path and converged on a final damage estimate of $8.7 million, removing much of the ambiguity that usually surrounds early exploit reports.

What makes this exploit particularly notable is that it required no malicious smart contract code, no flash loan tricks, and no oracle manipulation in the traditional sense. Instead, it exploited a collateral-pricing weakness tied directly to MAMO's shallow liquidity. When a token trades on thin order books, its price becomes easier to move with concentrated buying pressure, and Moonwell's collateral valuation system followed that manipulated price upward without sufficient safeguards.

How Did Moonwell Respond to Contain the Damage?

Moonwell moved within hours to choke off further bleeding, effectively freezing new borrowing across its Base markets rather than waiting for a full diagnosis. The protocol implemented emergency measures designed to stop the attack in its tracks:

  • Borrow Caps: Moonwell set borrow caps for all Core Markets on Base down to 1 wei, an amount so small it functions as a hard stop and prevents any new borrowing activity platform-wide.
  • Supply Caps: The protocol reduced supply caps for both MAMO and WELL tokens to 1 wei, directly targeting the two assets tied to the exploit while leaving supply limits for every other asset untouched.
  • Narrowly Scoped Response: Rather than implementing a blanket lockdown across all Base markets, Moonwell's response was narrowly scoped to the compromised markets, suggesting a measured approach to containing the breach without disrupting unaffected users.

Markets reacted almost immediately once the exploit became public. Moonwell's native WELL token dropped around 13% within 24 hours, according to CoinGecko data, while MAMO itself fell roughly 9% over the same window, per DEX Screener figures. For a token that already carried a volatile history, the exploit added fresh pressure to an asset investors were already watching closely.

Why Does This Matter for DeFi Security?

This isn't Moonwell's first brush with trouble in 2026, and that pattern matters for anyone assessing the protocol's risk profile going forward. In February, an oracle error mispriced Coinbase Wrapped ETH at around $1.12 when it was actually trading near $2,200, leaving Moonwell with about $1.78 million in bad debt. Then in March, an attacker spent roughly $1,800 buying MFAM tokens to push a malicious governance proposal through quorum on Moonwell's Moonriver deployment. An emergency multisig mechanism (a security feature requiring multiple approvals) was in place to block the attack and protect approximately $1.08 million that faced risk across seven lending markets.

Three separate incidents in a single year, each exposing a different attack surface, point to a broader pattern rather than one-off bad luck. The oracle bug targeted pricing infrastructure, the governance attack exploited voting mechanics, and now the collateral manipulation exploit reveals weaknesses in how thinly traded assets are valued. For a lending protocol, that breadth of exposure raises harder questions about how deeply security reviews cover every asset a market chooses to list, not just the flagship ones.

Moonwell has said it will share further updates as its investigation continues, but the protocol has not yet published a full post-mortem or confirmed whether any of the stolen funds can be recovered. That leaves an open question hanging over the incident: whether the DAI sitting in that single wallet ever makes its way back to the protocol or its users.

How Does This Fit Into the Broader DeFi Landscape?

Moonwell's August exploit lands inside a rougher stretch for decentralized finance generally. By April 18, 2026, crypto protocols had already lost more than $606 million across at least 12 separate incidents that month alone, with the largest being the $292 million Kelp DAO exploit linked to North Korea's Lazarus Group. Binance Research later estimated that April's exploits contributed to roughly $13 billion in total value locked outflows from on-chain protocols, a reminder that individual hacks rarely stay isolated; they tend to spook capital across the whole sector.

Set against that backdrop, the Moonwell MAMO exploit looks less like an isolated failure and more like one entry in a longer ledger of DeFi lending vulnerabilities tied to collateral pricing and illiquid tokens. Whether Moonwell's rapid-response caps restore user confidence, or whether repeated incidents push liquidity elsewhere on Base, will likely depend on what the pending post-mortem actually reveals and whether the protocol can demonstrate that it has addressed the root causes of its three 2026 security breaches.