The Moonwell Incident: What Happened and What It Means for MAMO
On 27 August 2026, Moonwell's MAMO lending market was exploited. Who was affected, how it worked and why the token's basics did not change.
What happened
On 27 August 2026, an attacker exploited Moonwell's MAMO market on Base [1]. Moonwell is a lending app. In this market, people could supply MAMO and borrow other assets against it, up to half of its value [1].
The attack had two parts. First, the attacker sent about 53 million MAMO straight into the market contract without receiving new shares for it. That made each existing share worth about 3.7 times more MAMO. The attacker owned roughly three quarters of those shares [1]. Second, the attacker's wallets bought about 94 million MAMO while trading was thin. The price feed the market relied on rose from about 0.011 USD to 0.43 USD in about 20 minutes [1]. Against this inflated collateral, the attacker borrowed about 11 million USD in cbBTC, ETH, USDC and wstETH [1].
Who was affected
Real people were hurt by this. We feel for everyone affected.
After the liquidations, about 9.1 million USD of the attacker's debt was still open on Moonwell [1]. People who supplied MAMO to Moonwell's market (the mMAMO market) are affected most directly. On 31 August, one supplier reported being able to withdraw just 0.24% of their position [2]. Our check of the market contract on 21 September shows it holds practically no MAMO to pay out [3]. We found open questions on the Moonwell forum but no final plan for these suppliers yet [2].
Users of the Mamo USDC Account were affected too, because their withdrawals depend on how much USDC is available at Moonwell [4]. Mamo gave eligible USDC depositors 1 MAMO per dollar deposited as a thank-you for their patience, 3,674,546 MAMO in total [5]. One user reports depositing USDC through Mamo on 2 September, after the incident, without seeing a prominent warning. That user has filed a formal governance request [6].
What the attack did not change
Moonwell's post-mortem describes a problem in how its market counted collateral and in the price it accepted for MAMO [1]. It does not describe a flaw in the MAMO token contract. The Cryptonomist put it this way: the exploit "didn't need a single line of malicious code" and came from "a collateral-pricing weakness tied directly to a token's shallow liquidity" [7]. The second half is fair. Thin trading made MAMO's price easy to push for a few minutes, which is why lending markets need careful limits for smaller tokens. An emergency transaction cut Moonwell's borrow caps to almost zero within 90 minutes of the last borrow. Moonwell later passed new caps for markets with limited liquidity or elevated oracle risk [1][8].
It was not Moonwell's first problem. TechTimes counted the third failure in 11 months and reported that the loss exceeded Moonwell's full annual revenue [9]. Lunar Labs builds Mamo and also contributes to Moonwell, so the two share a reputation [10][11].
The token itself works as before. Its supply is still exactly one billion [12]. The MAMO Account is also separate from Moonwell's MAMO market: Mamo places USDC and cbBTC with lending apps, while deposited MAMO earns a share of platform revenue [13]. That revenue comes from Aerodrome trading fees [14]. The payouts continued. By 4 September, Mamo had paid more than 638,000 USD in rewards to depositors [15].
Where the tokens went
Liquidation bots stepped in 32 seconds after the attacker's last borrow and had seized nearly all of the attacker's shares by 09:46 UTC [1]. We followed the public transfer records ourselves. The bots redeemed about 54 million MAMO and sold nearly all of it into MAMO pools on Aerodrome that same morning, almost all within about a quarter of an hour [3]. Today, those wallets hold only small leftovers. The attacker's main wallet holds no MAMO at all [3][16]. No pile of tokens from the attack is waiting to be sold.
The price feed was back close to its starting level by 09:45 UTC [1]. The "all-time high" of 27 August that CoinGecko shows comes from those few manipulated minutes, not from normal trading [17].
Our take
The incident hurt real people, mostly Moonwell's MAMO suppliers and those waiting on USDC withdrawals. It did not change what MAMO is: a token with a fixed supply whose depositors receive Mamo's trading-fee revenue, held in vaults that only they control [12][14][18].
Sources
- Post-Mortem: MAMO Market Incident on Base (Moonwell Forum, Anthias Labs), https://forum.moonwell.fi/t/post-mortem-mamo-market-incident-on-base/2208, retrieved 21 Sep 2026
- Supplier question in the post-mortem thread (Moonwell Forum, 31 Aug 2026), https://forum.moonwell.fi/t/post-mortem-mamo-market-incident-on-base/2208/3, retrieved 21 Sep 2026
- Moonwell mMAMO market contract and token transfers (Basescan), https://basescan.org/address/0x2f90bb22eb3979f5ffad31ea6c3f0792ca66da32, retrieved 21 Sep 2026
- Mamo on X, update on USDC withdrawals (8 Sep 2026), https://x.com/mamo/status/2097387257963655499, retrieved 21 Sep 2026
- Mamo on X, MAMO for eligible USDC depositors (11 Sep 2026), https://x.com/mamo/status/2098453633042092320, retrieved 21 Sep 2026
- Formal Governance Request: Treatment of Post-Incident Depositors (Moonwell Forum, 4 Sep 2026), https://forum.moonwell.fi/t/formal-governance-request-treatment-of-post-incident-depositors-and-recovery-plan-for-the-base-musdc-core-market/2224, retrieved 21 Sep 2026
- Moonwell MAMO Exploit Reveals $8.7M Lending Flaw (The Cryptonomist), https://en.cryptonomist.ch/2026/08/28/moonwell-mamo-exploit/, retrieved 21 Sep 2026
- Moonwell on X, MIP-X66 executed (8 Sep 2026), https://x.com/MoonwellDeFi/status/2097371661154898398, retrieved 21 Sep 2026
- Moonwell Oracle Exploit Exceeds Full Annual Revenue: Third Failure in 11 Months (TechTimes), https://www.techtimes.com/articles/325839/20260827/moonwell-oracle-exploit-exceeds-full-annual-revenue-third-failure-11-months.htm, retrieved 21 Sep 2026
- Mamo website, https://mamo.bot, retrieved 21 Sep 2026
- Moonwell website, contributors section, https://moonwell.fi, retrieved 21 Sep 2026
- MAMO token contract (Basescan), https://basescan.org/token/0x7300b37dfdfab110d83290a29dfb31b1740219fe, retrieved 21 Sep 2026
- How It Works (Mamo Docs), https://docs.mamo.bot/behind-the-scenes/how-mamo-works, retrieved 21 Sep 2026
- Mamo (MAMO) Account (Mamo Docs), https://docs.mamo.bot/grow/mamo-mamo, retrieved 21 Sep 2026
- Mamo on X, rewards distributed to date (4 Sep 2026), https://x.com/mamo/status/2095891933675876671, retrieved 21 Sep 2026
- Attacker's main wallet (Basescan), https://basescan.org/address/0x719eae70d4A83f35bF82A2740699F5db84BE919D, retrieved 21 Sep 2026
- Mamo (MAMO) on CoinGecko, https://www.coingecko.com/en/coins/mamo, retrieved 21 Sep 2026
- Security and Risk (Mamo Docs), https://docs.mamo.bot/behind-the-scenes/how-mamo-keeps-you-safe, retrieved 21 Sep 2026
Written by an independent fan. Run by MAMO & Bitcoin holders. Not financial advice.