Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Ethereum Open Interest Rises While Price Pulls Back: Short Squeeze Setup?

May 13, 2026

First Hyperliquid ETF Launch: Day One Volume Hits $1.8M – Key Details

May 13, 2026

Kelp DAO Begins Recovering rsETH After the April Exploit

May 13, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Bitcoin

Moonwell hit by governance attack — $1.08M at risk for $1,800 spend

By WebDeskMarch 26, 20263 Mins Read
Moonwell hit by governance attack — .08M at risk for ,800 spend
Share
Facebook Twitter LinkedIn Pinterest Email

An attacker spent about $1,800 on MFAM to push a malicious Moonwell proposal that could seize control of seven markets and $1.08m in assets, testing its veto and governance defenses.

Summary

  • An unknown attacker spent just $1,800 to acquire 40 million MFAM tokens and push a malicious governance proposal through quorum in roughly 11 minutes on Moonwell’s Moonriver deployment.
  • The proposal, if executed, would transfer admin control of seven lending markets, the comptroller, and the oracle to an attacker-controlled contract, exposing approximately $1.08 million in user funds.
  • Moonwell retains an emergency veto mechanism — the “Break Glass Guardian” multisig — and a majority of subsequent votes have opposed the proposal ahead of the March 27 deadline.

An unknown attacker on March 26 spent approximately $1,800 to acquire around 40 million MFAM tokens and ram through a malicious governance proposal on Moonwell’s Moonriver deployment — completing the entire sequence in roughly 11 minutes and placing approximately $1.08 million in user funds at risk.

As reported by The Block, the attacker’s proposal, listed as MIP-R39, seeks to transfer administrative rights over seven lending markets, the comptroller contract, and the price oracle to a contract under the attacker’s control. Gaining that access would effectively allow the attacker to drain the protocol’s pools at will. Moonwell is a DeFi lending protocol operating on Moonbeam and Moonriver, two parachains within the Polkadot ecosystem, where users deposit assets to earn yield or borrow against collateral.

The exploit targets a structural weakness endemic to token-based governance: when a protocol’s governance token trades at depressed prices and voter participation is thin, a bad actor can acquire enough voting weight to pass proposals with relatively little capital. That dynamic is precisely what made the attack possible — $1,800 worth of MFAM was enough to hit quorum and lock in a favorable vote before meaningful opposition could mobilize.

Two fail-safes remain in play

Voting on the proposal remains open until March 27. While it reached quorum quickly, the majority of cast votes are now opposed. The final result still hinges on any remaining undeclared voting power. Separately, Moonwell maintains an emergency multisig mechanism known as the “Break Glass Guardian,” which can override the governance process and revoke the attacker’s access before execution regardless of the vote outcome.

The incident is the second major security failure to hit Moonwell in a matter of weeks. In February, the protocol suffered a previous exploit when a faulty oracle — reportedly co-authored using the AI model Claude Opus 4.6 — mispriced Coinbase Wrapped ETH (cbETH) at near $1 instead of its actual market value of roughly $2,200, generating approximately $1.78 million in bad debt.

A recurring vulnerability across DeFi

Governance attacks are not new to decentralized finance, but they continue to expose the tension between open participation and protocol security. The 2022 Beanstalk flash loan attack remains the most dramatic example of the vector, with an attacker draining over $180 million by using a flash loan to temporarily accumulate sufficient voting power to pass a fraudulent proposal in a single transaction. Compound Finance and the now-defunct Swerve Finance have also faced similar contested governance episodes driven by concentrated token accumulation.

What distinguishes the Moonwell case is the raw cost efficiency. There were no flash loans required — just a modest open-market purchase on a low-liquidity token, and a governance system that lacked the circuit breakers to slow down a hostile proposal.

The Moonwell community and team are now racing against the March 27 vote deadline. The outcome will test whether the Break Glass Guardian mechanism and organic voter opposition can neutralize the threat before the proposal reaches execution.

Credit: Source link

Previous ArticleSimon Gerovich Confirmed As A Bitcoin 2026 Speaker
Next Article Coinbase and Better.com Unveil Crypto-Backed Mortgages

Related Posts

Ethereum Open Interest Rises While Price Pulls Back: Short Squeeze Setup?

May 13, 2026

Ether Withdrawals to Resume Following KelpDAO and Aave’s Coordinated Token Burn

May 13, 2026

Jane Street cuts Bitcoin ETF holdings while boosting Ether exposure

May 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum Open Interest Rises While Price Pulls Back: Short Squeeze Setup?

May 13, 2026

First Hyperliquid ETF Launch: Day One Volume Hits $1.8M – Key Details

May 13, 2026

Kelp DAO Begins Recovering rsETH After the April Exploit

May 13, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Ethereum Price Slides Back To $2,250, Traders Watch Crucial Support

21shares Debuts US HYPE ETF With $1.8M Day-One Volume on Nasdaq – Bitcoin News

Babylon: Unlocking Bitcoin Staking for the PoS World

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$79,755.00-0.92%
  • ethereumEthereum(ETH)$2,267.71-0.02%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$672.862.93%
  • rippleXRP(XRP)$1.430.22%
  • usd-coinUSDC(USDC)$1.000.07%
  • solanaSolana(SOL)$91.81-2.78%
  • tronTRON(TRX)$0.3501950.67%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.71%
  • dogecoinDogecoin(DOGE)$0.1118402.84%
  • whitebitWhiteBIT Coin(WBT)$58.62-0.59%
  • USDSUSDS(USDS)$1.00-0.03%
  • cardanoCardano(ADA)$0.265963-1.29%
  • HyperliquidHyperliquid(HYPE)$39.06-3.08%
  • leo-tokenLEO Token(LEO)$10.01-1.64%
  • zcashZcash(ZEC)$538.64-2.61%
  • bitcoin-cashBitcoin Cash(BCH)$433.13-1.38%
  • moneroMonero(XMR)$404.321.08%
  • chainlinkChainlink(LINK)$10.210.19%
  • CantonCanton(CC)$0.154679-0.32%
  • the-open-networkToncoin(TON)$2.13-9.19%
  • stellarStellar(XLM)$0.160276-1.14%
  • suiSui(SUI)$1.21-1.52%
  • USD1USD1(USD1)$1.000.05%
  • litecoinLitecoin(LTC)$57.300.16%
  • daiDai(DAI)$1.000.03%
  • avalanche-2Avalanche(AVAX)$9.800.70%
  • MemeCoreMemeCore(M)$3.250.43%
  • hedera-hashgraphHedera(HBAR)$0.092394-0.85%
  • Ethena USDeEthena USDe(USDE)$1.000.05%
  • shiba-inuShiba Inu(SHIB)$0.000006-0.80%
  • RainRain(RAIN)$0.0075230.19%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.02%
  • Global DollarGlobal Dollar(USDG)$1.00-0.01%
  • crypto-com-chainCronos(CRO)$0.076720-2.46%
  • Circle USYCCircle USYC(USYC)$1.120.00%
  • BittensorBittensor(TAO)$297.53-3.29%
  • tether-goldTether Gold(XAUT)$4,674.700.14%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • uniswapUniswap(UNI)$3.67-1.67%
  • polkadotPolkadot(DOT)$1.352.54%
  • pax-goldPAX Gold(PAXG)$4,675.520.19%
  • mantleMantle(MNT)$0.66-1.65%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0670410.14%
  • nearNEAR Protocol(NEAR)$1.582.16%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.33%
  • OndoOndo(ONDO)$0.388520-1.72%
  • Pi NetworkPi Network(PI)$0.170724-0.28%
  • Falcon USDFalcon USD(USDF)$1.000.04%
  • HTX DAOHTX DAO(HTX)$0.000002-0.26%