Moonwell hack — November 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 4, 2025 |
| Target type | Lending protocol |
| Loss | $3,700,000Published estimates range $1,000,000 to $3,700,000Price at time of incident |
| Method | Oracle or price manipulationThe wrsETH/ETH price feed malfunctioned rather than being manipulated by the attacker, returning 1 wrsETH = 1,649,934.60732 ETH. Moonwell multiplied that by its ETH/USD feed, pricing wrsETH near $5.8 billion a token, and the attacker borrowed against fractions of a wrsETH deposited as collateral. |
| Chains | Base |
| Outcome | Unresolved |
What happened
At 05:44:55 UTC on 4 November 2025 the wrsETH/ETH price feed used by Moonwell, a lending protocol deployed on Base and Optimism, reported that one wrsETH was worth 1,649,934.60732 ETH. Moonwell derives a USD price by multiplying that feed by a separate ETH/USD feed, so wrsETH was briefly valued at roughly $5.8 billion per token. Two seconds later, in block 37722875 on Base, an attacker began borrowing against it.
Across about a dozen transactions in under half a minute, the attacker flash-loaned fractions of a wrsETH, as little as 0.00065 in one case, deposited them as collateral and drew out other assets. The incident write-up posted to Moonwell's governance forum by Anthias Labs lists borrows of 1.206 million cbXRP, 153,300 EURC, 80,000 USDC, 202,000 AERO, 82 wstETH and 48 cbETH, and states a total bad debt of $3.7 million.
The published figures differ because they measure different things. Same-day coverage, drawing on detection by BlockSec's Phalcon system and alerts from CertiK, described a roughly $1 million loss, which corresponds to the approximately 295 ETH the attacker realised after swapping the borrowed assets. The $3.7 million is the value that left Moonwell's markets and was left behind as unrecoverable debt against lenders.
Moonwell zeroed supply and borrow caps for wrsETH on Base and Optimism and cut borrow caps across all markets on both chains; caps were restored on 12 November after oracle changes. No reimbursement, recovery or attribution has been published. Moonwell had suffered a separate oracle incident the previous month.
Sources
- Moonwell governance forum (Anthias Labs)Primary · retrieved 2026-08-01
- Coin EditionSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- Smart Contract HackingSecondary · retrieved 2026-08-01
Official post-mortem: https://forum.moonwell.fi/t/wrseth-oracle-malfunction-11-4-25/2017
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Moonwell hack — November 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/moonwellhttps://itokenly.com/hacks/moonwellPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.