The post Chainlink oracle glitch costs Moonwell $1M as DeFi suffers another exploit appeared on BitcoinEthereumNews.com. Key Takeaways What caused the Moonwell exploit? A Chainlink oracle price feed malfunction incorrectly valued 0.02 wrstETH (worth pennies) at millions, allowing an attacker to drain funds before the protocol could respond. How does this relate to other recent DeFi hacks? Moonwell’s loss came just 24 hours after Balancer’s $128M exploit and marks Moonwell’s fourth major hack in three years. DeFi suffered its worst start to a month in a long time as two major protocols lost $129 million in 48 hours.  A Chainlink oracle malfunction enabled a $1 million Moonwell exploit on 4 November, just one day after hackers drained $128 million from Balancer across six blockchains. The Chainlink oracle exploit An attacker exploited Moonwell’s lending protocol on Base using a sophisticated oracle manipulation attack. The hacker flashloaned approximately 0.02 wrstETH, worth mere pennies, and deposited it as collateral. However, a Chainlink oracle price feed temporarily malfunctioned, valuing this tiny collateral at $5.8 million. The protocol accepted the inflated valuation. The attacker immediately borrowed over 20 wstETH against the artificially valued collateral. Source: CertiK The exploit was repeated seven times within three hours, and each cycle netted approximately 24.5-24.9 ETH. The attacker executed everything within single blocks, avoiding liquidation mechanisms, and made a total profit of 292 ETH [around $1.01 million]. CertiK detected the exploit and confirmed that the oracle pricing error enabled the attack. The incident highlights the risks of infrastructure dependency in DeFi lending protocols, although Chainlink’s core oracle network remained secure throughout. TVL crashes, token plummets Analysis of DefiLlama data revealed that Moonwell’s Total Value Locked [TVL] collapsed from $268 million to $213 million, a $55 million exodus in just hours.  Source: DefiLlama Additionally, the WELL token declined by over 12% to trade at approximately $0.012, while the broader cryptocurrency market decreased by more than 1%.… The post Chainlink oracle glitch costs Moonwell $1M as DeFi suffers another exploit appeared on BitcoinEthereumNews.com. Key Takeaways What caused the Moonwell exploit? A Chainlink oracle price feed malfunction incorrectly valued 0.02 wrstETH (worth pennies) at millions, allowing an attacker to drain funds before the protocol could respond. How does this relate to other recent DeFi hacks? Moonwell’s loss came just 24 hours after Balancer’s $128M exploit and marks Moonwell’s fourth major hack in three years. DeFi suffered its worst start to a month in a long time as two major protocols lost $129 million in 48 hours.  A Chainlink oracle malfunction enabled a $1 million Moonwell exploit on 4 November, just one day after hackers drained $128 million from Balancer across six blockchains. The Chainlink oracle exploit An attacker exploited Moonwell’s lending protocol on Base using a sophisticated oracle manipulation attack. The hacker flashloaned approximately 0.02 wrstETH, worth mere pennies, and deposited it as collateral. However, a Chainlink oracle price feed temporarily malfunctioned, valuing this tiny collateral at $5.8 million. The protocol accepted the inflated valuation. The attacker immediately borrowed over 20 wstETH against the artificially valued collateral. Source: CertiK The exploit was repeated seven times within three hours, and each cycle netted approximately 24.5-24.9 ETH. The attacker executed everything within single blocks, avoiding liquidation mechanisms, and made a total profit of 292 ETH [around $1.01 million]. CertiK detected the exploit and confirmed that the oracle pricing error enabled the attack. The incident highlights the risks of infrastructure dependency in DeFi lending protocols, although Chainlink’s core oracle network remained secure throughout. TVL crashes, token plummets Analysis of DefiLlama data revealed that Moonwell’s Total Value Locked [TVL] collapsed from $268 million to $213 million, a $55 million exodus in just hours.  Source: DefiLlama Additionally, the WELL token declined by over 12% to trade at approximately $0.012, while the broader cryptocurrency market decreased by more than 1%.…

Chainlink oracle glitch costs Moonwell $1M as DeFi suffers another exploit

Key Takeaways

What caused the Moonwell exploit?

A Chainlink oracle price feed malfunction incorrectly valued 0.02 wrstETH (worth pennies) at millions, allowing an attacker to drain funds before the protocol could respond.

How does this relate to other recent DeFi hacks?

Moonwell’s loss came just 24 hours after Balancer’s $128M exploit and marks Moonwell’s fourth major hack in three years.


DeFi suffered its worst start to a month in a long time as two major protocols lost $129 million in 48 hours. 

A Chainlink oracle malfunction enabled a $1 million Moonwell exploit on 4 November, just one day after hackers drained $128 million from Balancer across six blockchains.

An attacker exploited Moonwell’s lending protocol on Base using a sophisticated oracle manipulation attack. The hacker flashloaned approximately 0.02 wrstETH, worth mere pennies, and deposited it as collateral.

However, a Chainlink oracle price feed temporarily malfunctioned, valuing this tiny collateral at $5.8 million. The protocol accepted the inflated valuation.

The attacker immediately borrowed over 20 wstETH against the artificially valued collateral.

Source: CertiK

The exploit was repeated seven times within three hours, and each cycle netted approximately 24.5-24.9 ETH.

The attacker executed everything within single blocks, avoiding liquidation mechanisms, and made a total profit of 292 ETH [around $1.01 million].

CertiK detected the exploit and confirmed that the oracle pricing error enabled the attack. The incident highlights the risks of infrastructure dependency in DeFi lending protocols, although Chainlink’s core oracle network remained secure throughout.

TVL crashes, token plummets

Analysis of DefiLlama data revealed that Moonwell’s Total Value Locked [TVL] collapsed from $268 million to $213 million, a $55 million exodus in just hours. 

Source: DefiLlama

Additionally, the WELL token declined by over 12% to trade at approximately $0.012, while the broader cryptocurrency market decreased by more than 1%.

A troubling pattern

This marks Moonwell’s fourth major security incident in three years, according to reports. 

December 2024 saw a $320,000 flash loan exploit, and on 10 October 2025, a $1.7 million oracle incident occurred. Now, on 4 November, another $1 million loss is added, just 24 days after the previous one.

Most troubling: Moonwell removed its Immunefi bug bounty program in February 2025, months before suffering two exploits totaling $2.7 million.

The decision eliminated financial incentives for security researchers to find vulnerabilities before attackers did.

DeFi’s $129M week

The Moonwell exploit capped a devastating 48-hour period for DeFi. 

Balancer lost $128 million on 3 November when hackers exploited access control vulnerabilities across Ethereum, Arbitrum, Base, Optimism, Polygon, and Sonic. Berachain halted its entire network for an emergency hard fork.

Combined losses exceed $129 million across two protocols in two days. Both exploits exposed different vulnerabilities; Balancer suffered from faulty access controls, while Moonwell fell victim to oracle infrastructure issues.

This week’s carnage shows that even established protocols remain vulnerable to sophisticated attacks targeting infrastructure dependencies and protocol-level weaknesses.

Next: Bitcoin’s 14% slide mirrors 2022’s bottom, but in reverse! – Here’s why

Source: https://ambcrypto.com/chainlink-oracle-glitch-costs-moonwell-1m-as-defi-suffers-another-exploit/

Market Opportunity
DeFi Logo
DeFi Price(DEFI)
$0.000299
$0.000299$0.000299
+0.67%
USD
DeFi (DEFI) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

VanEck Targets Stablecoins & Next-Gen ICOs

VanEck Targets Stablecoins & Next-Gen ICOs

The post VanEck Targets Stablecoins & Next-Gen ICOs appeared on BitcoinEthereumNews.com. Welcome to the US Crypto News Morning Briefing—your essential rundown of the most important developments in crypto for the day ahead. Grab a coffee because the firms shaping crypto’s future are not just building products, but also trying to reshape how capital flows. Crypto News of the Day: VanEck Maps Next Frontier of Crypto Venture Investing VanEck, a Wall Street player known for financial “firsts,” is pushing that legacy into Web3. The firsts include pioneering US gold funds and launching one of the earliest spot Bitcoin ETFs. Sponsored Sponsored “Financial instruments have always been a kind of tokenization. From seashells to traveler’s checks, from relational databases to today’s on-chain assets. You could even joke that VanEck’s first gold mutual funds were the original ‘tokenized gold,’” Juan C. Lopez, General Partner at VanEck Ventures, told BeInCrypto. That same instinct drives the firm’s venture bets. Lopez said VanEck goes beyond writing checks and brings the full weight of the firm. This extends from regulatory proximity to product experiments to founders building the next phase of crypto infrastructure. Asked about key investment priorities, Lopez highlighted stablecoins. “We care deeply about three questions: How do we accelerate stablecoin ubiquity? What will users want to do with them once highly distributed? And what net new assets can we construct now that we have sophisticated market infrastructure?” Lopez added. However, VanEck is not limiting itself to the hottest narrative, acknowledging that decentralized finance (DeFi) is having a renaissance. The VanEck executive also noted that success will depend on new approaches to identity and programmable compliance layered on public blockchains. Backing Legion With A New Model for ICOs Sponsored Sponsored That compliance-first angle explains VanEck Ventures’ recent co-lead of Legion’s $5 million seed round alongside Brevan Howard. Legion aims to reinvent token fundraising by making early-stage access…
Share
BitcoinEthereumNews2025/09/18 03:52
Kaspa Price Prediction 2030: Can KAS Reach $1 or Will Traders Chase This 100x Crypto Presale Instead?

Kaspa Price Prediction 2030: Can KAS Reach $1 or Will Traders Chase This 100x Crypto Presale Instead?

What will Kaspa (KAS) be worth in 2025, 2026, or even 2030? That’s the question every trader asks as they look for the next breakout coin. Kaspa has already positioned itself as one of the most promising altcoin undervalued 2025 projects, with analysts expecting a steady climb backed by real adoption. Forecasts suggest it could
Share
Coinstats2025/09/19 01:30
STOCK NEWS: Oracle Corporation Sued for Securities Fraud after 11% Stock Drop — Investors Notified to Contact BFA Law by April 6 Class Action Deadline

STOCK NEWS: Oracle Corporation Sued for Securities Fraud after 11% Stock Drop — Investors Notified to Contact BFA Law by April 6 Class Action Deadline

NEW YORK–(BUSINESS WIRE)–$ORCL #AI–Leading securities law firm Bleichmar Fonti & Auld LLP announces that a class action lawsuit has been filed against Oracle Corporation
Share
AI Journal2026/02/14 05:02