Decentralized lending protocol Moonwell, operating on the Base network, has reduced the borrow cap in its MAMO Core Market to 1 wei, which is the smallest possible unit of value on Ethereum-compatible chains. This emergency measure effectively freezes borrowing in the market.
The protocol implemented the restriction following a price manipulation attack involving the MAMO token. The exploit allowed an adversary to borrow an estimated $10 million in assets using artificially inflated collateral. Among the drained assets was over $4 million worth of cbBTC, Coinbase's wrapped Bitcoin product on Base. Additionally, supply caps for MAMO and Moonwell's governance token, WELL, were tightened to prevent further exposure.
How the Exploit Worked
MAMO serves as the utility and governance token for an AI-driven yield optimization tool integrated with Moonwell. Due to limited trading volume and shallow order books, the token's price was susceptible to manipulation. The attacker inflated MAMO's market price, deposited the tokens as collateral into the Moonwell lending market, and borrowed high-value assets against them.
Before the emergency response, the MAMO market maintained a borrow cap of 3 million tokens, a supply cap of 20 million, a 50% collateral factor, and a 30% reserve factor. The new supply cap restrictions prevent users from depositing additional MAMO and WELL tokens while protocol teams assess the damage.
Oracle Risk in DeFi
The incident underscores ongoing vulnerabilities related to oracle risk in decentralized finance. Lending protocols rely on price feeds to value collateral. While large-cap assets like Bitcoin or Ethereum require prohibitive capital to manipulate, low-volume tokens like MAMO present lower barriers for attackers to skew spot prices and disrupt system operations.
Moonwell is currently conducting a review of the exploit's impact to determine whether and how the MAMO market might eventually reopen, alongside necessary safety measures.


