Decentralized finance lending protocol Moonwell has suffered an exploit on Base with estimated losses of approximately $8.7 million, according to blockchain security researchers monitoring th
Decentralized finance lending protocol Moonwell has suffered an exploit on Base with estimated losses of approximately $8.7 million, according to blockchain security researchers monitoring the incident. PeckShieldAlert flagged the suspicious activity on August 27, reporting that roughly $8.7 million had been drained and identifying an address holding the affected funds. Other blockchain security researchers subsequently reported activity involving Moonwell’s MAMO market on Base.
Moonwell acknowledged an issue affecting its MAMO Core Market on Base and said it was actively investigating the incident. The protocol did not immediately confirm the final amount lost or publish a full technical post-mortem. As an emergency measure, Moonwell sharply reduced borrowing limits across its Base Core Markets and restricted supply for MAMO and WELL while the investigation continues.
Moonwell Restricts Base Markets Following $8.7M Exploit
In its initial response, Moonwell said it had introduced precautionary restrictions designed to prevent additional borrowing while developers investigate the incident. The protocol stated:
“As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged.”
Setting a borrow cap to 1 wei — the smallest denomination of an Ethereum-compatible asset — effectively prevents meaningful new borrowing from the affected markets without necessarily shutting down every function of the protocol.
Moonwell said it would provide another update later in the day.
Security firm Blockaid separately reported detecting suspicious activity involving Moonwell on Base. Its initial analysis said an attacker manipulated the valuation of MAMO collateral and used it to borrow cbBTC, with more than $4 million in cbBTC observed as affected during the early stages of the investigation. Subsequent reports put total losses at approximately $8.7 million and indicated that additional liquid assets were involved.
Because Moonwell has not yet released its final incident report, the exact exploit mechanism and definitive loss figure should still be treated as preliminary.
What Is Moonwell and How Does Its DeFi Lending Protocol Work?
Moonwell is a decentralized lending and borrowing protocol that allows users to supply digital assets to earn yield or deposit cryptocurrency as collateral to borrow other assets.
According to Moonwell’s documentation, borrowers generally take overcollateralized loans, with borrowing capacity determined by the value of their supplied collateral and risk parameters established through Moonwell governance. The protocol operates across networks including Base, OP Mainnet, Moonbeam and Moonriver, while Moonwell has also expanded lending and borrowing services to Ethereum mainnet.
Moonwell is non-custodial, meaning users interact with smart contracts rather than handing their funds to a centralized financial institution. Onchain lending protocols use parameters such as collateral factors, supply caps and borrow caps to control how much exposure individual markets can create.
Before the latest incident, Moonwell documentation listed MAMO as a supported Base asset with a 50% collateral factor. Such risk parameters are particularly important for assets with limited liquidity because sharp or manipulated price movements can potentially distort the value of collateral used by lending markets.
The Moonwell ecosystem also uses WELL as a governance token. Delegated WELL holders can participate in governance proposals and vote on changes affecting the protocol.
DeFi Hacks Remain a Major Crypto Security Risk in 2026
The Moonwell exploit comes during another difficult year for crypto and DeFi security.
Different security companies use different methodologies for counting exploits, phishing incidents, wallet compromises and other forms of crypto theft, meaning industry-wide loss estimates vary. CertiK calculated that the broader Web3 ecosystem lost more than $1.31 billion across 344 security incidents in the first half of 2026. Wallet compromises alone accounted for more than $444 million of those losses.
Immunefi produced a lower figure using its own methodology, estimating approximately $972 million in losses across 207 hacks during H1 2026. It estimated that DeFi exploits accounted for roughly $680.3 million. The number of incidents was nevertheless the highest the company had recorded for a first-half period.
The differences underline why crypto hack statistics should be attributed to individual security trackers rather than presented as one universally accepted total.
April was particularly damaging. Binance Research, citing DeFiLlama data, reported approximately $635 million in losses from 28 hack events during the month.
Kelp DAO and Drift Rank Among 2026’s Biggest DeFi Exploits
Two incidents accounted for a large portion of 2026’s DeFi losses. In April, Kelp DAO suffered an exploit worth approximately $292 million involving its cross-chain infrastructure. An attacker drained about 116,500 rsETH, prompting emergency responses across several DeFi platforms exposed to the asset. The incident became one of the largest DeFi exploits recorded in 2026.
Earlier that month, Solana-based Drift Protocol lost approximately $285 million. Chainalysis said attackers obtained administrative control following an extended social-engineering operation involving pre-signed transactions using Solana’s durable nonce functionality. The attackers were then able to use artificially valued collateral to extract real assets from the protocol.
The incidents demonstrate that DeFi risks extend beyond conventional smart-contract bugs. Oracle and collateral-price manipulation, compromised administrative permissions, cross-chain infrastructure, governance systems, private keys and social engineering can all become attack vectors.
For lending protocols in particular, collateral pricing and liquidity controls are critical because the system depends on correctly determining how much a deposited asset is worth relative to what a user can borrow against it. Moonwell’s decision to reduce Base borrow caps to 1 wei therefore represents an attempt to limit additional exposure while investigators determine exactly how the MAMO market was affected.
As of Moonwell’s first public statement, the investigation remained ongoing, and the protocol said additional information would be released later on August 27. A complete assessment of the exploit, including the final losses, root cause and any potential recovery plan, will depend on Moonwell’s subsequent technical findings.