Moonwell Hack

TOTAL LOST $3.7M
Medium Oracle Issue

Summarize with AI

Affected Chain 2025 Incident surface
Recovered - No recovery reported
All-Time Rank #499 By amount stolen
Protocol Type Exploit/Oracle Issue Target category

Incident Overview

On November 4, 2025, Moonwell DeFi on Base was exploited for approximately $3.7 million due to a catastrophic oracle malfunction that valued wrsETH at $5.8 billion. The same attacker from a previous October 10 exploit used minimal wrsETH collateral (flash loaned amounts as small as 0.00065 wrsETH) to borrow millions in various assets within 30 seconds of the oracle malfunction.

The vulnerability originated from Moonwell's wrsETH/ETH Chainlink oracle, which erroneously reported that 1 wrsETH equals 1,649,934.60732 ETH, valuing a single token at approximately $5.8 billion. Moonwell derives USD prices for wrsETH by multiplying two Chainlink feeds: an ETH/USD oracle and a wrsETH/ETH oracle. The faulty reading from the wrsETH/ETH oracle occurred at precisely 5:44:55 UTC, and the attacker executed the exploit within 30 seconds.

The attack involved 12 sequential transactions over 26 seconds, starting with a flash loan of just 0.00065 wrsETH to withdraw 1.206M cbXRP, followed by systematic borrowing of EURC, USDC, AERO, wstETH, and cbETH totaling $3.7M in bad debt. The attacker repeatedly borrowed over 20 wstETH using only 0.02 wrstETH as collateral, profiting approximately 295 ETH ($1M). All borrowed tokens were atomically swapped to WETH within the same transactions.

Moonwell immediately responded by zeroing supply and borrow caps for wrsETH and reducing all other market borrow caps to 0.1 to prevent further exploitation.

Attacker Contract:

0x42ecd332…9734bb

Attacker EOA:

0x6997a8c8…5658ff

First Exploit Transaction:

0x229caeb8…8f6cc6

Incident Report

Protocol / Project Moonwell
Date of Incident
Attack Technique Oracle Issue
Classification Borrowing and Lending

Protocol Information

Protocol Type Exploit/Oracle Issue
Official Website moonwell.fi/
Protocol Twitter/X @MoonwellDeFi
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Price at Hack $0.0133
Market Cap at Hack $59.6M
% of Market Cap Stolen 6.21%
Token Categories
Polkadot Polkadot Ecosystem Moonbeam Ecosystem Base Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of oracle issue and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Moonwell's contract logic - root cause: borrowing and lending
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Yes — skilled auditors routinely flag Oracle Issue vulnerabilities in code review

If you're auditing a protocol with similar architecture to Moonwell, these are the critical security checks that could have prevented this incident (November 2025).

  • Verify all logic paths related to Oracle Issue are guarded by proper access controls and input validation - see the Oracle Manipulation & Price Manipulation attack class for patterns
  • Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Related Attack Classes

The technique used in this hack maps to these vulnerability classes in our security curriculum:

See all Oracle Manipulation & Price Manipulation examples →

Sources & References

Learn to Prevent the Next Moonwell

The Moonwell hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial