T
iTokenly

Moonwell (cbETH oracle misconfiguration) hack — February 2026

Verified — 3 sourcesLast checked August 27, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$1,780,000Price at time of incident
MethodOracle or price manipulationA governance proposal wired the cbETH price to the raw cbETH/ETH exchange rate without multiplying by ETH/USD, so the protocol valued cbETH at about $1.12 instead of about $2,200
ChainsBase
OutcomeUnresolved

What happened

At 18:01 UTC on 15 February 2026, governance proposal MIP-X43 executed on Moonwell, enabling Chainlink OEV wrapper contracts across its Base and Optimism markets. The change also rewired how the protocol priced Coinbase Wrapped Staked ETH: instead of multiplying the cbETH/ETH feed by the ETH/USD price, it used the raw cbETH/ETH exchange rate alone. The protocol therefore believed one cbETH was worth about $1.12 rather than about $2,200.

Bots reached the mispriced market within minutes. Because the collateral was valued at just over a dollar, liquidators could repay roughly $1 of debt to seize a whole cbETH, and 1,096.317 cbETH left the protocol that way. Moonwell's monitoring caught the discrepancy quickly and risk managers cut the cbETH supply and borrow caps on Base to 0.01, which stopped new deposits and borrows, with a corrective governance vote to follow after the timelock. The protocol was left with $1.78m of bad debt.

The registry excludes ordinary liquidations, because money lost to markets is not money taken. This is recorded anyway, on the same basis as Moonwell's November 2025 wrsETH feed failure: the collateral was not seized at a market price but at a broken one, and the value moved out of the protocol because a price feed reported a figure that was never true.

The pull request behind the configuration change lists an AI coding assistant as a co-author, which drew wide comment about AI-assisted work in DeFi. Moonwell declined to comment on that point. Security auditor Pashov, who raised it, also said the mistake was one a senior Solidity developer could have made, and put the blame on missing integration testing rather than on how the code was written. The claim is recorded here as an observation by a named party, not as an established cause.

Sources

  1. The BlockSecondary · retrieved 2026-08-27
  2. DecryptSecondary · retrieved 2026-08-27
  3. FinanceFeedsSecondary · retrieved 2026-08-27

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Moonwell (cbETH oracle misconfiguration) hack — February 2026", iTokenly, accessed 2026-08-27, https://itokenly.com/hacks/moonwell-cbeth-oracle
https://itokenly.com/hacks/moonwell-cbeth-oracle

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.