Moonwell Exploit Results in $1.78 Million Loss Due to Oracle Misconfiguration
- Moonwell, a DeFi lending protocol, was exploited for approximately $1.78 million.
- The exploit occurred after the pricing oracle for Coinbase Wrapped Staked ETH (cbETH) incorrectly reported a value of about $1.12 instead of the correct price of $2,200.
- A governance proposal misconfigured the cbETH oracle by using only the cbETH/ETH exchange rate, leading to significant mispricing.
- Liquidation bots and opportunistic borrowers took advantage of this mispricing, resulting in bad debt for the protocol.
- Security auditor Pashov linked the incident to AI involvement, noting that multiple commits were co-authored by Anthropic’s Claude Opus.
The Moonwell incident highlights vulnerabilities in oracle configurations and raises questions about AI-assisted coding practices in DeFi. Despite existing audits and tests, critical flaws went undetected due to inadequate validation processes.
This exploit underscores the importance of rigorous testing protocols as a safeguard against similar incidents, particularly given that roughly $1.78 million was lost due to a basic configuration error.(Source)