Moonwell Lending Hack
What happened
On February 15, 2026, a cbETH oracle misconfiguration in Moonwell's Base markets caused liquidations and borrowing at a severely incorrect price, leaving approximately $1.78 million in bad debt.
The oracle configuration used the raw cbETH/ETH ratio instead of converting it to USD by multiplying it by ETH/USD. That caused cbETH to be reported near $1.12 rather than its intended market value of roughly $2,200.
Case & protocol details
Attack Timeline
Because cbETH was reported near one dollar, liquidation bots could repay minimal debt to seize cbETH collateral; some users also supplied minimal collateral to borrow cbETH at the distorted price.
Security review history
- Halborn Report
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis Website reference forum.moonwell.fi
- analysis Website reference x.com
- analysis Website reference x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.