Moonwell Lending Hack

TOTAL LOST $1.8M
Medium Oracle Manipulation & Price Manipulation base

What happened

On February 15, 2026, a cbETH oracle misconfiguration in Moonwell's Base markets caused liquidations and borrowing at a severely incorrect price, leaving approximately $1.78 million in bad debt.

Technical Root Cause

The oracle configuration used the raw cbETH/ETH ratio instead of converting it to USD by multiplying it by ETH/USD. That caused cbETH to be reported near $1.12 rather than its intended market value of roughly $2,200.

Case & protocol details

Classification Protocol Logic / Borrowing and Lending / Oracle Manipulation
Protocol Type Lending
Smart Contract Language Solidity
Official Website moonwell.fi/
Protocol Twitter/X @MoonwellDeFi

Attack Timeline

Because cbETH was reported near one dollar, liquidation bots could repay minimal debt to seize cbETH collateral; some users also supplied minimal collateral to borrow cbETH at the distorted price.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.