Skip to main content
Sign in

Moonwell Lending

avoid.net/moonwell-lending28/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2WWzBM…njSF

Summary

Moonwell is a decentralized, non-custodial lending and borrowing protocol deployed on Base, Optimism, Moonbeam, and Moonriver, operating as a fork of Compound v2. The protocol has suffered at least five distinct security incidents between 2022 and 2026, resulting in combined losses and bad debt exceeding $5 million, including repeated oracle failures, a flash loan exploit, a near-successful governance attack, and an AI-assisted smart contract misconfiguration. Despite multiple audits by Halborn and Code4rena, the pattern of recurring vulnerabilities and the removal of its Immunefi bug bounty program in early 2025 have raised significant security concerns.

Connected Entities

1 entities
Organizations
Moonwell Lending
Relationships
  • + 2 more
Have evidence about Moonwell Lending?

Timeline(12 events)

2021

Moonwell founded by Luke Youngblood under Lunar Labs; built as a Compound v2 fork targeting Moonbeam network

17 March 2022

Moonwell raises $10 million in Strategic funding round

2 August 2022

Nomad bridge exploited for $190.7 million; Moonwell's Moonbeam deployment suffers collateral losses and bad debt including approximately $2.9 million in Frax-related bad debt

24 July 2023

Code4rena competitive audit identifies 17 medium severity vulnerabilities and 56 low/informational issues; no critical or high severity findings

31 December 2023

Non-binding governance plebiscite passes 98% in favor of using Nomad collateral and protocol reserves to address Frax bad debt, drawing community controversy over asset appropriation

December 2024

Flash loan exploit on Optimism USDC market drains approximately $320,000 via a malicious mToken contract; stolen funds swapped to DAI

February 2025

Moonwell removes its Immunefi bug bounty program; proposes migration to Code4rena bug bounty platform

10 October 2025

Oracle-DEX price gap during market volatility allows exploitation of liquidation mechanisms on Base deployment; approximately $1.7 million lost

4 November 2025

Chainlink oracle malfunction misprices wrsETH at $5.8 billion; attacker drains approximately $1 million (295 ETH) within 30 seconds; $3.7 million in bad debt accrues; WELL token drops ~13.5%

15 February 2026

Governance proposal MIP-X43 deploys misconfigured Chainlink OEV oracle; cbETH mispriced at ~$1.12 instead of ~$2,200; $1.78 million in bad debt generated; AI-assisted code co-authored by Claude Opus 4.6 implicated

24 March 2026

Governance attack on Moonriver deployment: attacker spends $1,808 to acquire voting tokens, submits malicious proposal, reaches quorum in ~11 minutes; $1.08 million in assets placed at risk; community votes defeated the proposal

6 April 2026

DAO approves MIP-X49, implementing fixes to Wormhole V3 cross-chain integration following March 2026 upgrade (MIP-X48)

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 26 of 35 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:20 AM

last updated: 8/30/2026, 3:54:59 AM

avoid.net — verified advice for a post-truth world