Moola Market Hack

TOTAL LOST $9.1M
Medium Oracle Manipulation & Price Manipulation Celo

What happened

Moola Market, a Celo lending protocol, was drained after an attacker manipulated the low-liquidity MOO market on Ubeswap. Moola accepted the resulting MOO price as collateral value, allowing the attacker to make borrowed MOO appear far more valuable and borrow the protocol's CELO, cUSD, and cEUR liquidity. The protocol paused, negotiated with the attacker, and reported that 93.1% of the funds were returned to its governance multisig.

Technical Root Cause

Moola's collateral risk model trusted a manipulable, low-liquidity MOO price. A time-weighted price alone did not make the input safe because the underlying Ubeswap market could be moved materially for long enough to affect borrowing power. This was an economic and oracle-design failure, not a code-bug or flash-loan exploit.

Case & protocol details

Classification Oracle Manipulation / Lending Collateral
Protocol Type Lending
Affected asset / contract MOO
Smart Contract Language Solidity
Official Website moola.market/

Attack Timeline

The attacker funded an initiating wallet from Binance, supplied CELO to Moola, and borrowed MOO. They used CELO to buy and repeatedly trade MOO on Ubeswap's thin market, lifting the MOO price. Moola's collateral valuation reflected the manipulated price.

The attacker then used inflated MOO collateral to borrow CELO, cUSD, and cEUR, repeating the borrow-and-buy cycle until the lending pool's liquidity was drained. Funds were consolidated into a wallet publicly labeled by CeloScan as the Moola Market Exploiter. Following negotiation, that wallet returned assets to Moola's governance multisig. The attacker retained the unreturned portion as a negotiated bounty, including a donation to ImpactMarket.

Funds Recovery

93.1%

Recovered

$8.5M

Net Loss

$627,900

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.