Moonwell was drained after an attacker inflated the price of a thinly traded collateral token and borrowed real assets against the artificial valuation. The loss was estimated at roughly $8.7 million, and the incident did not require a smart-contract bug or code takeover.

The weakness was in the protocol’s pricing and risk controls. When a lending market relies on a spot price for an illiquid asset, the market price can be moved quickly enough to make bad collateral look sound. That turns ordinary trading activity into an attack surface.

The best defense is to avoid trusting a single live price for thin markets. Protocols should use time-weighted average prices, cap exposure to assets with shallow liquidity, and cross-check valuations against independent feeds before allowing borrowing.

Security teams should also treat newly listed collateral as high risk until liquidity depth, volatility, and audit history are mature. If a token can be moved sharply with modest capital, it should not support high loan-to-value borrowing.