August 28, 2026
Moonwell’s Base lending markets reportedly lost approximately $8.7 million after an attacker manipulated the price of thinly traded MAMO collateral and borrowed liquid assets against the inflated valuation. Moonwell responded by setting Base Core Market borrow caps and MAMO/WELL supply caps to 1 wei.
Our SentinelTX-assisted review anchors several material movements at transaction level, but it does not independently reconstruct every exploit call. The address 0xD71dD9B6e634412713c47fe7aE02c628e338C384 received 8,728,318.997396 DAI on Ethereum in transaction 0x58399aaf…4125d and still held that DAI at the investigation cutoff, alongside 0.896953 ETH. On Base, transaction 0x840bf521…befd shows 75,000 USDC routed through KyberSwap while 7,407,608.308454132 MAMO reached the address. Three later transactions anchor large mUSDC withdrawals.
SentinelTX detected two Wormhole Base-to-Ethereum source transfers of 4,364,726.913196 USDC each, but the destination-chain transaction hashes were unavailable. That makes Wormhole a strong routing lead—not a completed cross-chain proof. A Tornado Cash funding path, the reported 14.33 cbBTC withdrawal, and any direct Coinbase or OKX deposit were not confirmed.
Moonwell is a lending protocol operating on Base. Moonwell’s official response said it was investigating the MAMO Core Market incident and had restricted borrowing. Public alerts from PeckShield, CertiK, and Blockaid described a collateral-oracle failure: an attacker allegedly inflated the market price of MAMO, a thinly traded collateral asset, and used the distorted value to borrow liquid assets.
This is best understood as a collateral-admission and pricing-control failure. When an illiquid asset can materially increase borrowing capacity, protocol safety depends on market depth, price-deviation limits, time-weighted resistance, conservative loan-to-value settings, and rapid cap controls.

Claim or observation | Status | Basis |
|---|---|---|
Approximately $8.7M was lost | Reported | Public incident reporting |
MAMO collateral price was manipulated | Reported | Public incident reporting |
8,728,318.997396 DAI was received in | Confirmed | Ethereum transaction and balance |
7,407,608.308454132 MAMO reached the address after a 75,000 USDC KyberSwap route | Confirmed transfer / inferred intent | Base transaction |
Three mUSDC withdrawal transactions occurred at 09:15:23–09:15:25 UTC | Confirmed | Base transaction hashes |
Two 4,364,726.913196 USDC Wormhole source transfers | Strong lead | Protocol detected; destination hashes unavailable |
Reported 14.33 cbBTC withdrawal | Not confirmed | No cbBTC transfer in target address history |
Direct Tornado Cash funding or CEX deposit | Not confirmed | No direct transaction anchor |

At 09:45:47 UTC on August 27, 0xD71dD9B6e634412713c47fe7aE02c628e338C384 received 8,728,318.997396 DAI from 0x719eae70d4a83f35bf82a2740699f5db84be919d in Ethereum transaction 0x58399aaf393f7d2f0671240f404df88c66db594dad6801bac87f1658b4e4125d. At the investigation cutoff it still held that DAI and 0.896953 ETH.
DAI is not directly freezeable by an issuer in the same way as centrally administered stablecoins. Recovery therefore depends on detecting the next transfer, preserving evidence, and rapidly coordinating with any intermediary that receives the funds.
SentinelTX observed the address’s first Base transaction at 02:39:35 UTC on August 21 and 20 outbound Base transactions through August 27. On August 26, transaction 0x840bf52106d58bf22d1c902f208fd9db34930a65fb99b177836ef883f7e5befd routed 75,000 USDC through KyberSwap’s Meta Aggregation Router v2 while 7,407,608.308454132 MAMO reached the address. The transfer is confirmed; describing it as manipulation remains analytical inference until the price-impacting pool events are reconstructed.
At 09:15:23–09:15:25 UTC on August 27, three transactions—0x911cd7a92be883aaaccc10b5dea237a5869c98dc800a9b80a66809c31405f87e, 0x6987867466fa9da911639db61c721513609338992e4701a4a837025f81d56224, and 0x4c0401ee4444fb0306783ed3ae90ff78e301078b710f9796f78d9f182430eaaf—anchor mUSDC withdrawals to two recipient addresses. A residual 7.47302 mUSDC position also appeared at Moonwell’s Base USDC market contract 0xedc817a28e8b93b03976fbd4a3ddbc9f7d176c22.
The complete collateral-deposit and borrow sequence remains missing. The widely repeated 14.33 cbBTC withdrawal was not present in the target address’s 85 Base token-transfer records. It may belong to another helper contract or wallet, or the secondary reporting may be inaccurate.
Time (UTC) | Event | Confidence |
|---|---|---|
2026-08-21 02:39:35 | First observed Base activity for | Confirmed |
2026-08-26 00:55:11 | 75,000 USDC routed through KyberSwap; 7,407,608.308454132 MAMO received | Confirmed transfer |
2026-08-27 09:15:23–09:15:25 | Three mUSDC withdrawal transactions | Confirmed |
2026-08-27 09:20:11 | 14.33 cbBTC withdrawal reported by secondary sources | Not confirmed |
2026-08-27 09:45:47 | 8,728,318.997396 DAI received on Ethereum | Confirmed |
SentinelTX detected Wormhole as the only cross-chain protocol in this session. Two Base source hashes—0xfcb2ff810dd3ce09577ebd34c4c6a3b3798396221483bacf1ddd137e40ecac03 and 0x9cd2fbe0991a75a11fb9dbf241aca841e45b1878837bc1f049d6e608567f1dec—were each associated with 4,364,726.913196 USDC. Their combined 8,729,453.826392 USDC differs from the final DAI amount by about 0.013%, economically consistent with fees and slippage. But the destination hashes were null, so amount matching cannot replace transaction-to-transaction proof.
No Circle CCTP, Stargate, or Across route was detected. Coinbase- and OKX-labeled addresses appeared only in the broader graph, with no direct deposit transaction from the target address. Tornado Cash likewise had no confirmed direct connection after 101 token transfers were reviewed.

0xD71dD9B6e634412713c47fe7aE02c628e338C384 across Base and Ethereum.0xfcb2ff81…ac03 and 0x9cd2fbe0…1dec.0xD71d…C384.The incident illustrates why collateral policy is part of protocol security. A price feed can be technically functional and still be unsafe if the referenced market is too shallow for the borrowing power it supports.
Defenses should combine liquidity-sensitive collateral caps, conservative loan-to-value ratios, time-weighted or multi-source pricing, deviation and staleness circuit breakers, and real-time monitoring of sudden collateral-value changes. Emergency caps are useful after detection, but they should not be the first line of defense.
The SentinelTX investigation reached a partial-result boundary. The deterministic graph covered 806 addresses and 2,593 flows, while the visible live graph contained 574 nodes at two hops. The Base trace was incomplete at three hops and the session reached a data cap. Noisy terminal balances and auto-ranked “largest flows” were excluded because DEX and routing activity can create misleading aggregates.
This report does not identify a real-world attacker, prove a Tornado Cash funding source, complete the Wormhole cross-chain pairing, verify the reported 14.33 cbBTC withdrawal, or establish a direct exchange deposit. Wallet association alone is not identity attribution.
Public reporting points to a thin-liquidity collateral manipulation. On-chain review anchors a 7.4 million MAMO acquisition, three mUSDC withdrawals, and the final receipt of approximately 8.728 million DAI at a known Ethereum address, leaving a meaningful monitoring and intervention window.
The next breakthrough will come from the missing event-level anchors: the collateral and borrow calls, the cbBTC helper address if one exists, and the destination side of the Wormhole transfers. Until then, investigators should monitor the stationary DAI while resisting speculative attribution.
Analytical disclaimer: This report separates transaction-level observations from public reporting and analytical inference. Balances and endpoints can change after the stated cutoff.
5 reads