No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

Moonwell hit by governance attack — $1.08M at risk for $1,800 spend

March 26, 2026
in Crypto
0
Moonwell hit by governance attack — $1.08M at risk for $1,800 spend



An attacker spent about $1,800 on MFAM to push a malicious Moonwell proposal that could seize control of seven markets and $1.08m in assets, testing its veto and governance defenses.

Summary

  • An unknown attacker spent just $1,800 to acquire 40 million MFAM tokens and push a malicious governance proposal through quorum in roughly 11 minutes on Moonwell’s Moonriver deployment.
  • The proposal, if executed, would transfer admin control of seven lending markets, the comptroller, and the oracle to an attacker-controlled contract, exposing approximately $1.08 million in user funds.
  • Moonwell retains an emergency veto mechanism — the “Break Glass Guardian” multisig — and a majority of subsequent votes have opposed the proposal ahead of the March 27 deadline.

An unknown attacker on March 26 spent approximately $1,800 to acquire around 40 million MFAM tokens and ram through a malicious governance proposal on Moonwell’s Moonriver deployment — completing the entire sequence in roughly 11 minutes and placing approximately $1.08 million in user funds at risk.

As reported by The Block, the attacker’s proposal, listed as MIP-R39, seeks to transfer administrative rights over seven lending markets, the comptroller contract, and the price oracle to a contract under the attacker’s control. Gaining that access would effectively allow the attacker to drain the protocol’s pools at will. Moonwell is a DeFi lending protocol operating on Moonbeam and Moonriver, two parachains within the Polkadot ecosystem, where users deposit assets to earn yield or borrow against collateral.

The exploit targets a structural weakness endemic to token-based governance: when a protocol’s governance token trades at depressed prices and voter participation is thin, a bad actor can acquire enough voting weight to pass proposals with relatively little capital. That dynamic is precisely what made the attack possible — $1,800 worth of MFAM was enough to hit quorum and lock in a favorable vote before meaningful opposition could mobilize.

Two fail-safes remain in play

Voting on the proposal remains open until March 27. While it reached quorum quickly, the majority of cast votes are now opposed. The final result still hinges on any remaining undeclared voting power. Separately, Moonwell maintains an emergency multisig mechanism known as the “Break Glass Guardian,” which can override the governance process and revoke the attacker’s access before execution regardless of the vote outcome.

The incident is the second major security failure to hit Moonwell in a matter of weeks. In February, the protocol suffered a previous exploit when a faulty oracle — reportedly co-authored using the AI model Claude Opus 4.6 — mispriced Coinbase Wrapped ETH (cbETH) at near $1 instead of its actual market value of roughly $2,200, generating approximately $1.78 million in bad debt.

A recurring vulnerability across DeFi

Governance attacks are not new to decentralized finance, but they continue to expose the tension between open participation and protocol security. The 2022 Beanstalk flash loan attack remains the most dramatic example of the vector, with an attacker draining over $180 million by using a flash loan to temporarily accumulate sufficient voting power to pass a fraudulent proposal in a single transaction. Compound Finance and the now-defunct Swerve Finance have also faced similar contested governance episodes driven by concentrated token accumulation.

What distinguishes the Moonwell case is the raw cost efficiency. There were no flash loans required — just a modest open-market purchase on a low-liquidity token, and a governance system that lacked the circuit breakers to slow down a hostile proposal.

The Moonwell community and team are now racing against the March 27 vote deadline. The outcome will test whether the Break Glass Guardian mechanism and organic voter opposition can neutralize the threat before the proposal reaches execution.

Editorial Team

Editorial Team

Related Posts

Trump signals openness to 20-year limit on Iran nuclear program
Crypto

Trump signals openness to 20-year limit on Iran nuclear program

May 15, 2026
Cardano Founder Says 'Leios Is Coming' As Proposal Heads To DReps
Crypto

Cardano Founder Says ‘Leios Is Coming’ As Proposal Heads To DReps

May 15, 2026
Can The Bullish 'HYPE' Sustain?
Crypto

Can The Bullish ‘HYPE’ Sustain?

May 15, 2026
Bitcoin absorbs $732B as tokenized RWAs hit $24B
Crypto

Will Bitcoin price break $100K as golden cross looms?

May 15, 2026
THORChain loses nearly $11 million in suspected exploit as RUNE tumbles 13%
Crypto

THORChain loses nearly $11 million in suspected exploit as RUNE tumbles 13%

May 15, 2026
Bitcoin
Crypto

Bitcoin Bear Would Be Record Shallow If $60,000 Was The Low

May 15, 2026
Load More
Next Post
My Cat's Favorite Remote-Controlled Toy Is 15% Off for Amazon's Spring Sale

My Cat's Favorite Remote-Controlled Toy Is 15% Off for Amazon's Spring Sale

Popular News

  • 6 Ways To Deal With Family Asking About Your Job Search

    6 Ways To Deal With Family Asking About Your Job Search

    0 shares
    Share 0 Tweet 0
  • Niente panico: Bitcoin è solo in fase di ristrutturazione

    0 shares
    Share 0 Tweet 0
  • BDC market to triple by 2030

    0 shares
    Share 0 Tweet 0
  • 8 influencers financieros latinos a seguir en 2023

    0 shares
    Share 0 Tweet 0
  • Bitcoin Supply Squeeze? Institutions Absorb 500% Of New BTC

    0 shares
    Share 0 Tweet 0

Latest News

When to help an aging parent with finances, and how to do it

When to help an aging parent with finances, and how to do it

May 15, 2026
0

As an adult, a point may arrive when you realize that your aging parents or other older relatives could use...

The EufyCam C35 Four-Cam Kit Is 43% Off Right Now

The EufyCam C35 Four-Cam Kit Is 43% Off Right Now

May 15, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Trump signals openness to 20-year limit on Iran nuclear program

Trump signals openness to 20-year limit on Iran nuclear program

May 15, 2026
0

## Market Snapshot US-Iran nuclear deal before 2027 is currently priced at 61.5% YES, up from 56% 24 hours ago....

Here are the new bulls on the block for 2026

Here are the new bulls on the block for 2026

May 15, 2026
0

The impact of AI capex, the geopolitical race for resources, rising defense spend and a housing shortage in America all...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.