Moonwell’s exploit stemmed from a critical smart‑contract pricing bug—partly introduced through AI‑generated code—that misvalued cbETH and enabled attackers to Moonwell’s exploit stemmed from a critical smart‑contract pricing bug—partly introduced through AI‑generated code—that misvalued cbETH and enabled attackers to

Moonwell Lost $1.78M After Smart Contract Bug Linked To AI-Generated Code

2026/02/24 00:00
Okuma süresi: 6 dk
Moonwell Lost $1.78M After Smart Contract Bug Linked To AI-Generated Code

Moonwell, a DeFi lending protocol, suffered a major financial blow in the same week when a critical smart contract bug mispriced the Coinbase Wrapped Staked Ether token (cbETH), allowing assailants and liquidation bots to empty the wallet and amass about $1.78 million of bad debt. 

The initial post-mortem analysis shows the logic error was added in code that was co-written by the AI model Claude Opus 4.6, which has again raised concerns about the dangers of going directly to production with AI-written code, without the intensive human scrutiny of its code.

The pricing mistake took place following a governance update that revamped the on-chain oracle of Moonwell, the protocol, converting the off-chain market pricing into information that can be utilized in its lending logic. The system incorrectly calculated the dollar value of cbETH, which is supposed to be calculated by multiplying the exchange rate of both by the current ETH/USD price, and therefore wrongly used only the ratio between the two, which quoted the price of the cbETH at approximately $1.12 instead of the actual price in the market, which was approximately $2,200. Having such a discrepancy led to a 2,000× undervaluation that was immediately used by liquidation bots and opportunistic traders. 

The smart contract traders and bots paid back a little in minutes to get a full cbETH collateral of thousands of dollars. Overall, Moonwell has lost a substantial amount of unrecoverable loans in the form of bad debt due to the distorted price of more than 1,096 cbETH that have been liquidated. 

The team of Moonwell responded quickly after the problem was identified and reduced by far the number of borrowing and supplying limits of the cbETH markets to avoid additional exploitation. Nevertheless, since the fix takes a five-day period of governance voting and timelock, liquidations kept piling up in the interim. The protocol has since proposed a governance proposal that is intended to deal with the oracle misconfiguration and hardening risk checks. 

AI’s Role Under Scrutiny

Although most of the past exploits in the DeFi sector are due to hacked oracle price feeds or flash loans, analysts believe that this was unique because of its link to AI-generated code. GitHub commits that have been co-authored by Claude Opus 4.6, an advanced generative model, have been pointed out by smart contract security auditor Pashov on social media regarding the pull request that added the faulty oracle logic. This has elicited controversy in blockchain and AI circles regarding the role of AI in the development of vital financial infrastructure. 

The process of developers basing their writing of production-level code on the AI suggestions or hints is known by industry observers as vibe-coding. The management of a basic pricing calculation, in this instance, of not multiplying an intermediate exchange rate by the proper USD peg, was disastrous in a live money market situation. 

Critics emphasize that although AIs are useful in speeding up the time-consuming routine tasks, the code generation in automation is insufficiently versed in the complex knowledge of economic invariants and edge-case logic to be used in DeFi protocols. A simple unit conversion or arithmetic error in the derivation of prices can become a huge systemic risk once used on scale, especially in highly leveraged collateralized lending systems where the solvency of the system heavily depends on the correct price of the market. 

The advocates of AI in software development also admit to the productivity gains achieved when using systems such as Claude or other generative models, but note that formal verification systems and human auditors are still essential. These people claim that AI cannot, but should complement, the processes of a careful review of security, particularly in protocols with billions of on-chain liquidity. 

Broader Implications for DeFi and AI Development

The defeat of Moonwell has already sparked a debate in the wider DeFi community regarding the tools, audit standards, and governance protections. Although the overall loss of about $1.78 million might be considered comparatively small in terms of historic exploits in the larger protocols, the incident highlights how even small logic errors in price feeds can lead to even greater multi-million-dollar results in the live markets. 

According to security experts, oracles are still a common vulnerability point in DeFi. Lending platforms rely on accurate valuation of collateral data. Once this underpinning information is poisoned by external or internal price manipulation, the whole risk model of the protocol may fail. The incident introduces an additional twist by attributing an archetypal cause of error, poor validation of arithmetic and data flows to AI. 

Since the exploit, governance forums of Moonwell have been more active, as community members suggested mitigation measures of risk, including a maximum number of wallet borrowings, extra liquidation fee buffers, and on-chain testing before oracle reconfigurations are implemented. According to protocol insiders, recovery plans are under debate to possibly compensate the affected users, but the details are still in discussion.

Moonwell Lost $1.78M After Smart Contract Bug Linked To AI-Generated Code

What This Means for AI in Smart Contract Engineering

The Moonwell accident is one of the warning examples to developers and protocol designers who may want to introduce AI into vital parts of the system. Correctness guarantees of smart contracts are much higher than those of normal application code because the financial integrity of smart contracts is at stake. Although boilerplate templates and developer productivity can be aided by automated code generation, formal verification, human inspection, and rigorous testing against economic adversarial situations is of paramount importance. 

With more tools in the AI-assisted category being deployed in Web3 engineering processes, the industry is calling on new audit frameworks, which explicitly address AI provenance, decision logic, and numerical correctness. This involves automated testing software, symbolic execution, and fuzzing methods that may examine the logic of a contract on a very low level before it goes into production. 

The governance performance and community reactions of Moonwell in the next several weeks will probably determine the quality at which the wider DeFi industry will treat AI-generated code risk avoidance and potentially develop more stringent guidelines on the incorporation of generative models into production-critical financial programs.

The post Moonwell Lost $1.78M After Smart Contract Bug Linked To AI-Generated Code appeared first on Metaverse Post.

Piyasa Fırsatı
Ucan fix life in1day Logosu
Ucan fix life in1day Fiyatı(1)
$0.0007269
$0.0007269$0.0007269
-13.36%
USD
Ucan fix life in1day (1) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

MORPHO Technical Analysis Feb 24

MORPHO Technical Analysis Feb 24

The post MORPHO Technical Analysis Feb 24 appeared on BitcoinEthereumNews.com. MORPHO’s 24-hour trading volume is trading above recent averages at 28.47 million
Paylaş
BitcoinEthereumNews2026/02/24 12:08
China’s Ban on Nvidia Chips for State Firms Sends Stock Tumbling

China’s Ban on Nvidia Chips for State Firms Sends Stock Tumbling

The post China’s Ban on Nvidia Chips for State Firms Sends Stock Tumbling appeared on BitcoinEthereumNews.com. Cyberspace Administration of China (CAC) has instructed big companies to stop purchasing and cancel existing orders for Nvidia’s RTX Pro 6000D chip The ban is part of China’s ongoing effort to reduce dependency on US-made AI hardware, especially after restrictive US export rules After the news, Nvidia shares dropped in premarket trading by about 1.5% Cyberspace Administration of China (CAC) has instructed big companies like Alibaba and ByteDance to stop purchasing and cancel existing orders for Nvidia’s RTX Pro 6000D chip. The ban is part of China’s ongoing effort to reduce dependency on US-made AI hardware, especially after restrictive US export rules. The RTX Pro 6000D was tailored for China to comply with some export rules, but now the regulator says even that chip is off-limits. After the news, Nvidia shares dropped in premarket trading (around 1.5%), reflecting investors’ concerns about reduced demand in one of the biggest markets. This isn’t the first time China has done something like this. For instance, in August, the country urged firms not to use Nvidia’s H20 chip due to potential security issues and the need to comply with international export control regulations. Meanwhile, Alibaba and Baidu have begun using domestically produced AI chips more heavily, which shows that China is seriously investing in building its own chip-making capacity. Additionally, a few days ago, Chinese regulators opened an antitrust review into Nvidia’s Mellanox acquisition, suggesting the company may have broken some of the promises it made to get the 2020 deal passed. From AI to blockchain and the possible effects of China’s ban The banning of Nvidia chips represents a rather notable escalation in the technological rivalry between the United States and China. Beyond tariffs or export bans, China is now proactively telling its firms to avoid even “compliant” US chips and instead shift…
Paylaş
BitcoinEthereumNews2025/09/18 07:46
Nasdaq Company Adds 7,500 BTC in Bold Treasury Move

Nasdaq Company Adds 7,500 BTC in Bold Treasury Move

The live-streaming and e-commerce company has struck a deal to acquire 7,500 BTC, instantly becoming one of the largest public […] The post Nasdaq Company Adds 7,500 BTC in Bold Treasury Move appeared first on Coindoo.
Paylaş
Coindoo2025/09/18 02:15