The post Moonwell Protocol Loses $1M in Oracle Manipulation Exploit appeared on BitcoinEthereumNews.com. BlockSec Phalcon detects suspicious transactions targeting Moonwell contracts. Exploit stems from an incorrectly updated price feed from an off-chain oracle system. MEV bot possibly exploited an oracle issue, resulting in losses exceeding $1 million. On-chain threat detection platform BlockSec Phalcon has identified a series of suspicious transactions targeting Moonwell’s smart contracts. The platform issued an alert regarding the activity on Base and Optimism networks that resulted in losses exceeding $1 million. BlockSec’s analysis points to an issue with the token price feed for rsETH/ETH from the off-chain oracle. The exploit appears to have been carried out, possibly by a MEV bot that took advantage of incorrectly updated price data used by the protocol. ALERT! Our system detected a series of suspicious transactions targeting @MoonwellDeFi’s smart contracts on #Base and #Optimism. Our analysis indicates an issue with the token price (rsETH / ETH) feed from the off-chain oracle, which was exploited — possibly by a MEV bot —… pic.twitter.com/cNJFHI3xn3 — BlockSec Phalcon (@Phalcon_xyz) November 4, 2025 The attack exploited a vulnerability in how the protocol received and processed price information from external data sources. When the rsETH/ETH price feed failed to update correctly, the discrepancy between actual market prices and protocol prices created an arbitrage opportunity. MEV bots typically scan blockchain networks for profitable opportunities, including price discrepancies across protocols. In this case, the bot appears to have identified the oracle malfunction and executed transactions to extract value before the issue could be corrected. BlockSec noted that no direct contact method was available to reach the project team immediately. The platform requested that anyone with questions or relevant information reach out directly to them for coordination. The Moonwell incident follows a larger exploit targeting the Balancer protocol on November 3, 2025. That attack resulted in losses exceeding $70 million, making it… The post Moonwell Protocol Loses $1M in Oracle Manipulation Exploit appeared on BitcoinEthereumNews.com. BlockSec Phalcon detects suspicious transactions targeting Moonwell contracts. Exploit stems from an incorrectly updated price feed from an off-chain oracle system. MEV bot possibly exploited an oracle issue, resulting in losses exceeding $1 million. On-chain threat detection platform BlockSec Phalcon has identified a series of suspicious transactions targeting Moonwell’s smart contracts. The platform issued an alert regarding the activity on Base and Optimism networks that resulted in losses exceeding $1 million. BlockSec’s analysis points to an issue with the token price feed for rsETH/ETH from the off-chain oracle. The exploit appears to have been carried out, possibly by a MEV bot that took advantage of incorrectly updated price data used by the protocol. ALERT! Our system detected a series of suspicious transactions targeting @MoonwellDeFi’s smart contracts on #Base and #Optimism. Our analysis indicates an issue with the token price (rsETH / ETH) feed from the off-chain oracle, which was exploited — possibly by a MEV bot —… pic.twitter.com/cNJFHI3xn3 — BlockSec Phalcon (@Phalcon_xyz) November 4, 2025 The attack exploited a vulnerability in how the protocol received and processed price information from external data sources. When the rsETH/ETH price feed failed to update correctly, the discrepancy between actual market prices and protocol prices created an arbitrage opportunity. MEV bots typically scan blockchain networks for profitable opportunities, including price discrepancies across protocols. In this case, the bot appears to have identified the oracle malfunction and executed transactions to extract value before the issue could be corrected. BlockSec noted that no direct contact method was available to reach the project team immediately. The platform requested that anyone with questions or relevant information reach out directly to them for coordination. The Moonwell incident follows a larger exploit targeting the Balancer protocol on November 3, 2025. That attack resulted in losses exceeding $70 million, making it…

Moonwell Protocol Loses $1M in Oracle Manipulation Exploit

2025/11/05 03:34
  • BlockSec Phalcon detects suspicious transactions targeting Moonwell contracts.
  • Exploit stems from an incorrectly updated price feed from an off-chain oracle system.
  • MEV bot possibly exploited an oracle issue, resulting in losses exceeding $1 million.

On-chain threat detection platform BlockSec Phalcon has identified a series of suspicious transactions targeting Moonwell’s smart contracts. The platform issued an alert regarding the activity on Base and Optimism networks that resulted in losses exceeding $1 million.

BlockSec’s analysis points to an issue with the token price feed for rsETH/ETH from the off-chain oracle. The exploit appears to have been carried out, possibly by a MEV bot that took advantage of incorrectly updated price data used by the protocol.

The attack exploited a vulnerability in how the protocol received and processed price information from external data sources. When the rsETH/ETH price feed failed to update correctly, the discrepancy between actual market prices and protocol prices created an arbitrage opportunity.

MEV bots typically scan blockchain networks for profitable opportunities, including price discrepancies across protocols. In this case, the bot appears to have identified the oracle malfunction and executed transactions to extract value before the issue could be corrected.

BlockSec noted that no direct contact method was available to reach the project team immediately. The platform requested that anyone with questions or relevant information reach out directly to them for coordination.

The Moonwell incident follows a larger exploit targeting the Balancer protocol on November 3, 2025. That attack resulted in losses exceeding $70 million, making it one of the most damaging recent breaches in decentralized finance.

Balancer Suffers $110M in Rapid Drainage

Attackers compromised Balancer by quickly siphoning funds from multiple liquidity pools. The hackers consolidated stolen assets into a newly created wallet within minutes of initiating the attack.

Confirmed stolen assets from the Balancer breach included 6,850 OSETH, 6,590 WETH, and 4,260 wSTETH. The speed of the attack and consolidation suggests sophisticated planning and execution by the attackers.

Oracle vulnerabilities have become an increasing concern for DeFi protocols relying on external price feeds. These systems depend on accurate real-time data to function properly, and any manipulation or failure in the oracle mechanism can create exploitable conditions.

The incidents highlight ongoing security challenges facing decentralized finance platforms. Despite advances in smart contract security, oracle dependencies and price feed mechanisms remain potential attack vectors that require constant monitoring and robust failsafe systems.

Related: https://coinedition.com/stakewise-recovers-20-7-million-from-balancer-exploit-to-reimburse-users-pro-rata/

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/moonwell-protocol-loses-over-1m-in-oracle-price-feed-exploit-on-base-and-optimism/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

What Every Platform Eventually Learns About Handling User Payments Across Borders

What Every Platform Eventually Learns About Handling User Payments Across Borders

There is a moment almost every global platform hits. It rarely shows up in dashboards or board meetings. It reveals itself quietly, one payout del
Share
Medium2025/12/10 21:54
U.S. AI leaders form foundation to compete with China

U.S. AI leaders form foundation to compete with China

The post U.S. AI leaders form foundation to compete with China appeared on BitcoinEthereumNews.com. A group of leading U.S. artificial intelligence firms has formed a new foundation to establish open standards for “agentic” AI. The founding members, OpenAI, Anthropic, and Block, have pooled their proprietary agent- and AI-related technologies into a new open-source project called the Agentic AI Foundation (AAIF), under the auspices of the Linux Foundation. This development follows tensions in the global race for dominance in artificial intelligence, leading U.S. AI firms and policymakers to unite around a new push to preserve American primacy. Open standards like MCP drive innovation and cross-platform collaboration Cloudflare CTO Dane Knecht noted that open standards and protocols, such as MCP, are critical for establishing an evolving developer ecosystem for building agents. He added, “They ensure anyone can build agents across platforms without the fear of vendor lock-in.” American companies face a dilemma because they are seeking continuous income from closed APIs, even as they are falling behind in fundamental AI development, risking long-term irrelevance to China. And that means American companies must standardize their approach for MCP and agentic AI, allowing them to focus on building better models rather than being locked into an ecosystem. The foundation establishes both a practical partnership and a milestone for community open-sourcing, with adversaries uniting around a single goal of standardization rather than fragmentation. It also makes open-source development easier and more accessible for users worldwide, including those in China. Anthropic donated its Model Context Protocol (MCP), a library that allows AIs to utilize tools creatively outside API calls, to the Linux Foundation. Since its introduction a year ago, MCP has gained traction, with over 10,000 active servers, best-in-class support from platforms including ChatGPT, Gemini, Microsoft Copilot, and VS Code, as well as 97 million monthly SDK downloads. “Open-source software is key to creating a world with secure and innovative AI tools for…
Share
BitcoinEthereumNews2025/12/10 22:10