The post Chainlink oracle glitch costs Moonwell $1M as DeFi suffers another exploit appeared on BitcoinEthereumNews.com. Key Takeaways What caused the Moonwell exploit? A Chainlink oracle price feed malfunction incorrectly valued 0.02 wrstETH (worth pennies) at millions, allowing an attacker to drain funds before the protocol could respond. How does this relate to other recent DeFi hacks? Moonwell’s loss came just 24 hours after Balancer’s $128M exploit and marks Moonwell’s fourth major hack in three years. DeFi suffered its worst start to a month in a long time as two major protocols lost $129 million in 48 hours.  A Chainlink oracle malfunction enabled a $1 million Moonwell exploit on 4 November, just one day after hackers drained $128 million from Balancer across six blockchains. The Chainlink oracle exploit An attacker exploited Moonwell’s lending protocol on Base using a sophisticated oracle manipulation attack. The hacker flashloaned approximately 0.02 wrstETH, worth mere pennies, and deposited it as collateral. However, a Chainlink oracle price feed temporarily malfunctioned, valuing this tiny collateral at $5.8 million. The protocol accepted the inflated valuation. The attacker immediately borrowed over 20 wstETH against the artificially valued collateral. Source: CertiK The exploit was repeated seven times within three hours, and each cycle netted approximately 24.5-24.9 ETH. The attacker executed everything within single blocks, avoiding liquidation mechanisms, and made a total profit of 292 ETH [around $1.01 million]. CertiK detected the exploit and confirmed that the oracle pricing error enabled the attack. The incident highlights the risks of infrastructure dependency in DeFi lending protocols, although Chainlink’s core oracle network remained secure throughout. TVL crashes, token plummets Analysis of DefiLlama data revealed that Moonwell’s Total Value Locked [TVL] collapsed from $268 million to $213 million, a $55 million exodus in just hours.  Source: DefiLlama Additionally, the WELL token declined by over 12% to trade at approximately $0.012, while the broader cryptocurrency market decreased by more than 1%.… The post Chainlink oracle glitch costs Moonwell $1M as DeFi suffers another exploit appeared on BitcoinEthereumNews.com. Key Takeaways What caused the Moonwell exploit? A Chainlink oracle price feed malfunction incorrectly valued 0.02 wrstETH (worth pennies) at millions, allowing an attacker to drain funds before the protocol could respond. How does this relate to other recent DeFi hacks? Moonwell’s loss came just 24 hours after Balancer’s $128M exploit and marks Moonwell’s fourth major hack in three years. DeFi suffered its worst start to a month in a long time as two major protocols lost $129 million in 48 hours.  A Chainlink oracle malfunction enabled a $1 million Moonwell exploit on 4 November, just one day after hackers drained $128 million from Balancer across six blockchains. The Chainlink oracle exploit An attacker exploited Moonwell’s lending protocol on Base using a sophisticated oracle manipulation attack. The hacker flashloaned approximately 0.02 wrstETH, worth mere pennies, and deposited it as collateral. However, a Chainlink oracle price feed temporarily malfunctioned, valuing this tiny collateral at $5.8 million. The protocol accepted the inflated valuation. The attacker immediately borrowed over 20 wstETH against the artificially valued collateral. Source: CertiK The exploit was repeated seven times within three hours, and each cycle netted approximately 24.5-24.9 ETH. The attacker executed everything within single blocks, avoiding liquidation mechanisms, and made a total profit of 292 ETH [around $1.01 million]. CertiK detected the exploit and confirmed that the oracle pricing error enabled the attack. The incident highlights the risks of infrastructure dependency in DeFi lending protocols, although Chainlink’s core oracle network remained secure throughout. TVL crashes, token plummets Analysis of DefiLlama data revealed that Moonwell’s Total Value Locked [TVL] collapsed from $268 million to $213 million, a $55 million exodus in just hours.  Source: DefiLlama Additionally, the WELL token declined by over 12% to trade at approximately $0.012, while the broader cryptocurrency market decreased by more than 1%.…

Chainlink oracle glitch costs Moonwell $1M as DeFi suffers another exploit

2025/11/05 01:09

Key Takeaways

What caused the Moonwell exploit?

A Chainlink oracle price feed malfunction incorrectly valued 0.02 wrstETH (worth pennies) at millions, allowing an attacker to drain funds before the protocol could respond.

How does this relate to other recent DeFi hacks?

Moonwell’s loss came just 24 hours after Balancer’s $128M exploit and marks Moonwell’s fourth major hack in three years.


DeFi suffered its worst start to a month in a long time as two major protocols lost $129 million in 48 hours. 

A Chainlink oracle malfunction enabled a $1 million Moonwell exploit on 4 November, just one day after hackers drained $128 million from Balancer across six blockchains.

The Chainlink oracle exploit

An attacker exploited Moonwell’s lending protocol on Base using a sophisticated oracle manipulation attack. The hacker flashloaned approximately 0.02 wrstETH, worth mere pennies, and deposited it as collateral.

However, a Chainlink oracle price feed temporarily malfunctioned, valuing this tiny collateral at $5.8 million. The protocol accepted the inflated valuation.

The attacker immediately borrowed over 20 wstETH against the artificially valued collateral.

Source: CertiK

The exploit was repeated seven times within three hours, and each cycle netted approximately 24.5-24.9 ETH.

The attacker executed everything within single blocks, avoiding liquidation mechanisms, and made a total profit of 292 ETH [around $1.01 million].

CertiK detected the exploit and confirmed that the oracle pricing error enabled the attack. The incident highlights the risks of infrastructure dependency in DeFi lending protocols, although Chainlink’s core oracle network remained secure throughout.

TVL crashes, token plummets

Analysis of DefiLlama data revealed that Moonwell’s Total Value Locked [TVL] collapsed from $268 million to $213 million, a $55 million exodus in just hours. 

Source: DefiLlama

Additionally, the WELL token declined by over 12% to trade at approximately $0.012, while the broader cryptocurrency market decreased by more than 1%.

A troubling pattern

This marks Moonwell’s fourth major security incident in three years, according to reports. 

December 2024 saw a $320,000 flash loan exploit, and on 10 October 2025, a $1.7 million oracle incident occurred. Now, on 4 November, another $1 million loss is added, just 24 days after the previous one.

Most troubling: Moonwell removed its Immunefi bug bounty program in February 2025, months before suffering two exploits totaling $2.7 million.

The decision eliminated financial incentives for security researchers to find vulnerabilities before attackers did.

DeFi’s $129M week

The Moonwell exploit capped a devastating 48-hour period for DeFi. 

Balancer lost $128 million on 3 November when hackers exploited access control vulnerabilities across Ethereum, Arbitrum, Base, Optimism, Polygon, and Sonic. Berachain halted its entire network for an emergency hard fork.

Combined losses exceed $129 million across two protocols in two days. Both exploits exposed different vulnerabilities; Balancer suffered from faulty access controls, while Moonwell fell victim to oracle infrastructure issues.

This week’s carnage shows that even established protocols remain vulnerable to sophisticated attacks targeting infrastructure dependencies and protocol-level weaknesses.

Next: Bitcoin’s 14% slide mirrors 2022’s bottom, but in reverse! – Here’s why

Source: https://ambcrypto.com/chainlink-oracle-glitch-costs-moonwell-1m-as-defi-suffers-another-exploit/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48