Invest1 distinct publisher3 min readPublished
Estimates of the loss run from $4M to $9M against the $72.77M locked in Moonwell, and the remedy was a borrow cap set to 1 wei, which is the tell that this was an underwriting choice rather than a bug.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The mechanism deserves precision, because it decides what actually gets fixed. Nothing here needed a broken contract: the attacker bought roughly $7 million of a thinly traded token, MAMO went from about $0.0105 to nearly $0.088, and the oracle published that figure because for a few blocks it was the figure [5][3]. Against the swollen collateral, about $10 million of real assets left the protocol and did not come back [6]. The $3.8 million surrendered on the round trip through MAMO was the entry fee, and $10 million out for $3.8 million in is a 2.6-times return on slippage [2], which is the ratio a risk committee is really underwriting whenever it approves a long-tail market, since a borrow cap protects depositors only while it sits below the cost of moving the price.
The remedy points at the same place. Moonwell cut the MAMO borrowing limit to 1 wei and lowered supply caps on MAMO and its own WELL token [12], and a parameter that can be set to effectively zero after the loss could have been set there before it. A protocol whose last nine months contain three incidents [13] is spending its governance bandwidth on caps and post-mortems instead of new markets, which is the durable cost of the listing rather than the headline one.
The counter-reading sits in February, when a misconfigured cbETH oracle reported about $1.12 for an asset worth roughly $2,200, an understatement of about 1,964 times, and left $1.78 million of bad debt [15][3]. That is a configuration failure a bounds check catches, and it is the incident that drew the argument about AI-assisted coding, since the relevant commits listed Anthropic's Claude Opus 4.6 as a co-author, per Cryptopolitan [16]. So "third oracle failure" bundles two problems with two different owners: November's spot-price manipulation [14] and Wednesday's belong to whoever approved the collateral.
Scaled against the balance sheet, $4 million to $9 million is 5.5% to 12.4% of the $72.77 million DeFiLlama shows locked in Moonwell [2][11][1], and adding February's shortfall puts nine months of disclosed losses at 7.9% to 14.8% of everything currently on deposit [5]. Interest spreads on an illiquid governance-adjacent market do not fund that.
WELL spiked about 25% on the news before correcting roughly 13% to around $0.0032 [10], so whatever the first hour was pricing, it was not the bad debt. The spread among observers is instructive too, or rather its composition is: Blockaid counted 50.6 cbBTC and ExVul 71.36, about 41% more units [7][8][4], a disagreement about how many transactions had cleared and not about what bitcoin costs. This is probably wrong in one specific way, and it is the way to check it: if the post-mortem shows a time-weighted or depth-aware feed was available and the market was pointed at spot anyway, then the failure is implementation and the listing thesis loses. By then the attacker's wallet held just over $4,600 [9], which is what a finished exit looks like.
Ranked by verification strength, evidence, and original report placement.
An attacker manipulated the price of the illiquid MAMO token on Moonwell's Base lending market on August 27, 2026, and used the inflated collateral to borrow real assets that were never repaid.
The MAMO token's value was driven up about eightfold, from around $0.0105 to nearly $0.088.
The attack drained cbBTC, USDC, wstETH and ETH out of real depositor liquidity on Moonwell.
The attacker's wallet moved most of the stolen funds, holding just over $4,600 hours later.
Moonwell's governance token WELL initially spiked about 25% but later corrected downward by roughly 13% to around $0.0032.
Moonwell has about $72.77 million in total value locked, according to DeFiLlama.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Anthropic's usage policy says no explicit content. Opus 4.6 said yes 10 times out of 10.1 distinct publisher
invest
Phantom prunes Sui and Monad, and the exit fee points to Solana1 distinct publisher
product
A 27B laptop model scores like a rented one, and thinks three times as hard to do it1 distinct publisher
security
An agent beat a client-side booking limit in 9 of 10 runs, and cancelled strangers twice1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete on-chain event, one newsroom, unreconciled numbers
The core facts — a live manipulation of an illiquid collateral token, drained depositor assets, and a same-day parameter clampdown — are specific, dated and attributed to named security firms (Blockaid, ExVul, CertiK) plus DeFiLlama for TVL and incident history. What holds the score down is that everything reaches us through a single publisher, the magnitude figures differ by more than 2x, and no protocol post-mortem or independent trace is cited.
Live mid-size market, repeat exposure
Adoption is evidenced by real capital at risk rather than by growth: about $72.77 million of TVL, real depositor cbBTC, USDC, wstETH and ETH borrowed away, and three dated incidents across the same protocol between November 2025 and August 2026. That establishes a genuinely used but mid-tier lending venue; there are no user counts, market-share figures, or post-incident deposit-flow data in the source.
Headline anchors the top of a wide range
Framing leans on the upper bound: the source's own headline says 'almost $9M' and 'up to $9M' while its lowest cited observation is just over $4 million and the mid-range firm estimate is about $5.7 million. The mechanism claims and the parameter fix are not overstated, so the gap is modest rather than large — the direction is toward the biggest available number while the loss was still being counted.
Competing security vendors and a live news cycle
Visible in the source itself: four security-analytics brands publishing rival loss estimates during an unfolding incident, each of which gains attribution from being first or largest; a protocol team whose fastest available action (a 1-wei borrow cap) also limits reputational exposure; and a publisher attaching a newsletter subscription pitch and investment disclaimer to the piece. These are documented incentive structures, not inferred motives.
Single publisher, incident still open
One publisher, no protocol post-mortem, an investigation described as ongoing, and loss figures that were explicitly shifting in real time. The qualitative shape of the story — illiquid collateral, oracle-priced borrow, third repeat — is well supported; the quantities and the final incidence of loss are not yet firm.