Moonwell, a decentralized lending protocol on Base, has suspended new lending across its Core markets after a suspected price manipulation exploit involving the MAMO token. The attack reportedly allowed a malicious actor to inflate MAMO’s price, borrow approximately $10 million in other assets, and walk away with a net profit of about $6 million.
According to blockchain analyst CJ_Blockchain, the attacker bought roughly $7 million worth of MAMO, pushing up the token’s price. The inflated MAMO was then deposited as collateral on Moonwell, enabling the attacker to borrow a mix of cbBTC, USDC, WETH, and wstETH worth around $10 million. After securing those borrowed assets, the attacker sold the remaining MAMO for about $3.2 million, absorbing a roughly $3.8 million loss on the MAMO trades but still extracting about $6 million in net value.
In response, Moonwell announced emergency measures on March 24, 2025, reducing borrowing caps across all Core markets on Base to one wei and lowering supply caps for MAMO and its governance token, WELL, to one wei. Existing positions remain unaffected while the team investigates the root cause and prepares a post-mortem.
The incident highlights persistent vulnerabilities in DeFi lending protocols, particularly around price oracles and low-liquidity collateral assets, and adds to a growing list of exploits that have increased scrutiny on the sector.