Moola Market hack — October 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 18, 2022 |
| Target type | Lending protocol |
| Loss | $8,400,000Published estimates range $8,400,000 to $10,000,000Price at time of incident |
| Method | Oracle or price manipulationThe lending market priced its own thinly traded governance token MOO from a live on-chain feed. The attacker cycled CELO into MOO and MOO back into collateral, inflating the MOO price by a reported 6,400%, then borrowed the protocol's other assets against the inflated collateral. |
| Chains | Other |
| Outcome | Settled as bug bounty |
What happened
On 18 October 2022 an attacker drained the Celo-based lending protocol Moola Market by inflating the price of its own governance token, MOO, and borrowing against it.
The Block Research's Igor Igamberdiev traced the sequence: the attacker started with 243,000 CELO from Binance, lent 60,000 CELO to Moola to borrow 1.8 million MOO, then used the remaining CELO to pump the price of MOO, and used the borrowed MOO as inflated collateral to borrow further assets. AnChain describes the same loop, noting that the lending contract used real-time prices and that MOO rose from about 0.02 to 0.73 CELO before liquidity was drained. Cointelegraph puts the inflation at about 6,400% on a starting outlay of roughly $45,000.
The size of the loss is disputed because the stolen MOO is hard to value at a price the attack itself created. The Block's itemisation - 8.8 million CELO ($6.5m), 765,000 cEUR ($700k), 1.8 million MOO ($600k) and 644,000 cUSD ($600k) - totals about $8.4 million. Cointelegraph and AnChain value the same haul at about $9.1 million, mainly by pricing the MOO higher. CoinDesk reported the loss as over $10 million without an itemised breakdown, which sets the upper bound recorded here.
Moola paused the protocol, said it discovered the issue at 16:54 UTC and contacted law enforcement, and publicly invited the attacker to make contact. The attacker did, and after negotiation returned 93.1% of the funds to Moola's governance multisig, according to CoinDesk roughly twelve hours after the attack, though Cointelegraph puts the return within about five hours of the exploit being confirmed. Estimates of what the attacker kept also differ: Cointelegraph says about $500,000, while AnChain computes the retained share at roughly $637,000.
Sources
- The BlockSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- AnChain.AISecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Moola Market hack — October 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/moola-markethttps://itokenly.com/hacks/moola-marketPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.