Moonwell Hack
What happened
On November 4, 2025, Moonwell DeFi on Base was exploited for approximately $3.7 million due to a catastrophic oracle malfunction that valued wrsETH at $5.8 billion. The same attacker from a previous October 10 exploit used minimal wrsETH collateral (flash loaned amounts as small as 0.00065 wrsETH) to borrow millions in various assets within 30 seconds of the oracle malfunction.
The vulnerability originated from Moonwell's wrsETH/ETH Chainlink oracle, which erroneously reported that 1 wrsETH equals 1,649,934.60732 ETH, valuing a single token at approximately $5.8 billion. Moonwell derives USD prices for wrsETH by multiplying two Chainlink feeds: an ETH/USD oracle and a wrsETH/ETH oracle. The faulty reading from the wrsETH/ETH oracle occurred at precisely 5:44:55 UTC, and the attacker executed the exploit within 30 seconds.
The attack involved 12 sequential transactions over 26 seconds, starting with a flash loan of just 0.00065 wrsETH to withdraw 1.206M cbXRP, followed by systematic borrowing of EURC, USDC, AERO, wstETH, and cbETH totaling $3.7M in bad debt. The attacker repeatedly borrowed over 20 wstETH using only 0.02 wrstETH as collateral, profiting approximately 295 ETH ($1M). All borrowed tokens were atomically swapped to WETH within the same transactions.
Moonwell immediately responded by zeroing supply and borrow caps for wrsETH and reducing all other market borrow caps to 0.1 to prevent further exploitation.
Attacker Contract:
Attacker EOA:
First Exploit Transaction:
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.