
What happened
The attacker bypassed Moonwell's supply-cap check on Base by sending 53 million tokens directly to the market.
Why it matters
The incident shows how a supply-cap check limited to the standard operation may fail to account for alternative balance-changing paths.
According to Unchained, the Moonwell protocol lost $8,7 million on the Base network after the attacker bypassed the supply-cap check. The cap was checked during the normal deposit that issues shares.
The attacker first deposited funds, then directly sent 53 million tokens to the market. This increased the asset base accessible to the issued shares by roughly 3,7 times.
The situation is important as an example of the risk arising from a gap between the standard operation check and balance changes via an alternative path. The source is presented as an independent meta-data recap, so corroboration from other publications and primary protocol data are absent.
Confirmed facts
- Unchained reported Moonwell losses of $8,7 million on the Base network.
- The supply cap was checked during standard deposits that issue shares.
- The attacker after one deposit directly sent 53 million tokens to the market.
- These actions increased the assets available to redeem the issued shares by roughly 3,7 times.
Context
The sole source in the package is Unchained; the evidentiary basis is labeled as metadata and does not include the full material text or a primary Moonwell statement.
What remains unknown
- Are the incident and loss amount confirmed by Moonwell's primary data or blockchain transactions?
- Which assets and Moonwell features were affected?
- Were operations halted, funds returned, or were the supply-cap-check rules changed?
- What is the exact sequence of transactions and the status of the funds?
Editorial context
Confidence: medium
Possible consequence — a review of the supply-limit checks and methods of balance changes in the protocol. The nearest observable signal is an official Moonwell statement, a technical analysis, or on-chain confirmation of transactions. Substantial uncertainty remains due to the absence of a primary source and full incident documentation.