Moonwell Lending
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2WWzBM…njSFSummary
Moonwell is a decentralized, non-custodial lending and borrowing protocol deployed on Base, Optimism, Moonbeam, and Moonriver, operating as a fork of Compound v2. The protocol has suffered at least five distinct security incidents between 2022 and 2026, resulting in combined losses and bad debt exceeding $5 million, including repeated oracle failures, a flash loan exploit, a near-successful governance attack, and an AI-assisted smart contract misconfiguration. Despite multiple audits by Halborn and Code4rena, the pattern of recurring vulnerabilities and the removal of its Immunefi bug bounty program in early 2025 have raised significant security concerns.
Connected Entities
1 entities- + 2 more
Timeline(12 events)
2021
Moonwell founded by Luke Youngblood under Lunar Labs; built as a Compound v2 fork targeting Moonbeam network
17 March 2022
Moonwell raises $10 million in Strategic funding round
2 August 2022
Nomad bridge exploited for $190.7 million; Moonwell's Moonbeam deployment suffers collateral losses and bad debt including approximately $2.9 million in Frax-related bad debt
24 July 2023
Code4rena competitive audit identifies 17 medium severity vulnerabilities and 56 low/informational issues; no critical or high severity findings
31 December 2023
Non-binding governance plebiscite passes 98% in favor of using Nomad collateral and protocol reserves to address Frax bad debt, drawing community controversy over asset appropriation
December 2024
Flash loan exploit on Optimism USDC market drains approximately $320,000 via a malicious mToken contract; stolen funds swapped to DAI
February 2025
Moonwell removes its Immunefi bug bounty program; proposes migration to Code4rena bug bounty platform
10 October 2025
Oracle-DEX price gap during market volatility allows exploitation of liquidation mechanisms on Base deployment; approximately $1.7 million lost
4 November 2025
Chainlink oracle malfunction misprices wrsETH at $5.8 billion; attacker drains approximately $1 million (295 ETH) within 30 seconds; $3.7 million in bad debt accrues; WELL token drops ~13.5%
15 February 2026
Governance proposal MIP-X43 deploys misconfigured Chainlink OEV oracle; cbETH mispriced at ~$1.12 instead of ~$2,200; $1.78 million in bad debt generated; AI-assisted code co-authored by Claude Opus 4.6 implicated
24 March 2026
Governance attack on Moonriver deployment: attacker spends $1,808 to acquire voting tokens, submits malicious proposal, reaches quorum in ~11 minutes; $1.08 million in assets placed at risk; community votes defeated the proposal
6 April 2026
DAO approves MIP-X49, implementing fixes to Wormhole V3 cross-chain integration following March 2026 upgrade (MIP-X48)
Decision Log
- hash: CbNkcGJ5jSitcdjBSrzLC7EGQZaLcdwhjmXhb4uUdM72
This investigation is cryptographically anchored to the Solana blockchain (1 event). 26 of 35 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:20 AM
last updated: 8/30/2026, 3:54:59 AM
avoid.net — verified advice for a post-truth world