Share on XShare on LinkedInShare on Telegram
Hack Analysis

Moonwell $8.7M mMAMO Exchange Rate Inflation Exploit (Explained)

Moonwell's supply cap only guarded deposits, so a direct MAMO donation inflated mMAMO's exchange rate and the same thin market priced that fake collateral.

Author
Anmol
September 2, 2026
Moonwell $8.7M mMAMO Exchange Rate Inflation Exploit (Explained)
Share on XShare on LinkedInShare on Telegram

On August 27, 2026, an attacker inflated the exchange rate behind Moonwell's MAMO market by donating tokens directly into the mMAMO contract rather than depositing through it, then pumped MAMO's price on thin liquidity to multiply the effect. No key was stolen and no contract was hacked, the market just valued fake collateral at a real price. The attacker borrowed $11 million against it and moved $8.7 million off Base as DAI before liquidations caught up.

Protocol Background

Moonwell's MAMO market works like any Compound-style lending market, deposit MAMO, receive mMAMO receipt tokens, and the mMAMO-to-MAMO exchange rate tracks how much underlying MAMO backs each share. Moonwell prices a position by multiplying mMAMO shares held by that exchange rate, then by MAMO's oracle price, to get a collateral value that sets how much a wallet can borrow. MAMO had been listed under MIP-B48 with a 50% collateral factor, a 20,000,000 MAMO supply cap on new mints, and a 3,000,000 MAMO borrow cap.

Hack Analysis

The attack was funded through Tornado Cash. The linked account, 0xd71dd9b6e634412713c47fe7ae02c628e338c384, received 800.098 ETH through several withdrawals, sold 799 ETH through CoW Swap for 1,947,391 USDC, and bridged that USDC to Base through Circle's CCTP. It passed a smaller share of MAMO, USDC, and gas ETH to the attacker account, 0x719eae70d4A83f35bF82A2740699F5db84BE919D, which carried out the rest of the exploit.

mamo-1.png
mamo-2.png
mamo-3.png

The attacker spent about $7.50 million buying roughly 94.3 million MAMO across dozens of trades on decentralized exchanges where liquidity was thin, and formally supplied 15,089,595 MAMO to Moonwell in exchange for mMAMO. At Moonwell's initial reference price of $0.010597, that supply was worth a modest $159,904.

mamo-4.png

The attacker sent 53,393,290 MAMO directly to the mMAMO contract in two transfers, 34,910,396.68 MAMO and 18,482,893.63 MAMO. Every mMAMO share now represented more MAMO than before, and the exchange rate jumped from about 0.020513 to 0.075460, roughly 3.68 times higher, without a single new share being issued.

mamo-5.png
mamo-6.png

Because the attacker already held about three-quarters of all outstanding mMAMO, it captured most of that inflation as paper collateral. It then pushed MAMO's price higher by buying into the same thin liquidity, driving the oracle's source feed from roughly $0.0106 up to a peak of $0.43127363, with Moonwell's own accepted price reaching $0.40248571 at its highest.

mamo-7.png

Multiplying an inflated mMAMO balance by an inflated exchange rate by an inflated price turned a real deposit worth a few hundred thousand dollars into a claim valued at roughly $22.3 million to $23.9 million, worth $11.1 million to $12 million of borrowing power at the market's 50% collateral factor.

The attacker drew on that borrowing power in 18 separate borrows across cbBTC, WETH, USDC, and wstETH, pulling out $11,028,762 of real assets in total before the price and exchange rate could move against it.

mamo-8.png
mamo-9.png

Liquidators moved in almost immediately, running 595 liquidation events and seizing nearly all of the attacker's mMAMO. But the borrowed assets and MAMO sale proceeds were already being converted and moved off Base by then.

Root Cause

This wasn't a broken oracle contract, or a bug in Moonwell's core lending code. The root failure is that Moonwell's supply cap only guarded the deposit path into mMAMO, so an attacker could send MAMO directly to the mMAMO contract and inflate every existing share's backing without minting a single new one or ever touching the cap meant to limit exactly that kind of exposure.

That inflated exchange rate turned into inflated collateral because the market priced positions using MAMO's own spot-derived oracle feed, which the same attacker could move by trading into MAMO's own thin liquidity. Combining an unguarded donation path with a manipulable price feed meant the attacker could set both halves of the collateral-value calculation, shares and price, in the same sequence of transactions.

Whether the supply cap's deposit-only scope was a deliberate design choice or an oversight in how MIP-B48 was implemented hasn't been publicly addressed.

How QuillAudits Infrastructure Review Could Have Prevented This

Cap the receipt token's backing, not just its mint path. Moonwell's 20 million MAMO supply cap only checked tokens flowing in through the deposit function. A cap enforced against the mMAMO contract's actual token balance, regardless of how tokens arrived, would have caught the direct transfer that inflated the exchange rate.

Don't let a single asset's own market set its own collateral price uncontested. MAMO's oracle tracked a feed sourced from the same thin on-chain liquidity the attacker was trading against. A review should flag any listed asset where the price source and the venue an attacker could realistically manipulate are the same market, and require a TWAP window, a liquidity floor, or a secondary feed before that asset can back real borrowing.

Treat a sudden receipt-token exchange-rate jump as an incident trigger, not a data point. The exchange rate moved 3.68 times in two transactions with no mint event attached. A monitor watching for exchange-rate deltas disconnected from mint or redeem activity would have flagged the inflation before the borrows against it went through.

Funds Flow After Attack

Attacker Swapped all the token to USDC and the used Circle CCTP bridge to turn USDC token on base and mint them on ethereum. $8.7M had been bridged using this.

mamo-10.png

Later Attacker converted these USDC tokens into DAI and trasfered them to another wallet 0xD71dD9B6e634412713c47fe7aE02c628e338C384 as of now funds are still siting in attacker wallet.

Post-Attack Mitigation

Moonwell has acknowledged the exploit and, as a precaution, reduced borrow caps for all Base Core Markets and supply caps for MAMO and WELL to 1 wei, while leaving caps for all other markets unchanged.

Moonwell shares a post-mortem covering the incident on its governance forum, and says it will keep posting updates as more information becomes available.

Relevant Addresses and Transactions

Attacker Wallets / EOAs

Borrow Transactions

Bridge Transactions

Conclusion

A cap built to limit how much MAMO could be minted into collateral didn't cover MAMO sent straight to the contract, and the same attacker who inflated the exchange rate that way also had the liquidity to move the price backing it. Both halves of a collateral calculation, shares and price, sat within reach of the same wallet. A cap that only watches one door isn't a cap, it's a suggestion for the door the attacker didn't use.

Anmol

Anmol

Security Research Writer

Contents

Tell Us About Your Project
Subscribe to Newsletter
hashing bits image
Loading...
Loading...
cta-bg

WE SECURE EVERYTHING YOU BUILD.

From day-zero risk mapping to exchange-ready audits — QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance — secured end-to-end.

QuillAudits Logo


ISO 27001Circle Alliance Program
Uniswap FoundationAethiropt-collectivePolygon SPNBNB Chain Kickstart

All Rights Reserved. © 2026. QuillAudits - LLC