Moonwell Lending

Orange · 59/100

Executive summary

Moonwell Lending is an open, non-custodial lending and borrowing protocol deployed on Base, Moonbeam, and OP Mainnet, scoring 45/100 (orange band) with a -10 penalty for unresolved incident remediation.

  • Security: Multiple audits by Halborn, Code4rena (17 medium findings in 2023), and 0xVolodya (7 medium, all fixed); active $250k bug bounty via Sherlock; however, audit coverage of deployed code is not independently verified as of September 2026.
  • Incidents: Four major oracle-related exploits since 2022: June 2022 Artemis treasury drain (amount unverified), October 2025 Base flash-loan attack ($1.72M bad debt), November 2025 wrsETH oracle failure ($1M), February 2026 cbETH misconfiguration ($1.78M), and August 2026 MAMO market manipulation ($8.7M loss, $6.79M attacker profit); remediation is in progress but incomplete, with partial reserve replenishment and no full user reimbursement verified.
  • Governance & custody: Hybrid DAO with WELL-token voting, 24-hour timelock, and 3-of-5 Security Council emergency powers; Moonwell Foundation (Cayman Islands) retains veto authority in limited circumstances; non-custodial user deposits held in smart contracts; Temporal Governor controls Base/OP execution via Wormhole cross-chain messaging.
  • Top risks: Oracle integrity is the dominant risk—four exploits in 30 months demonstrate configuration and manipulation vulnerabilities; Chainlink/API3 feed dependencies are material single points of failure; cross-chain governance via Wormhole introduces bridge and vote-relay risk; high utilization or collateral depegs can trigger liquidation cascades and bad debt; upgradeable proxy architecture with admin/guardian privileges creates centralization and emergency-bypass risk.
  • Strengths: Multi-chain deployment (Base, OP Mainnet, Moonbeam) broadens liquidity; transparent on-chain governance with public proposals and timelock; simple UX for retail and institutional users; Compound-v2 fork with well-understood mechanics; active security posture with ongoing audits and bug bounty.
  • Unverified: Current TVL, reserves, bad-debt exposure, collateral composition, and chain-by-chain utilization are not verifiable as of September 2026 due to unavailable on-chain data; exact recovered amounts and user reimbursement status for all incidents are unconfirmed; whether audits cover currently deployed bytecode is not independently verified; legal ToS, prohibited jurisdictions, and complete team roster are not publicly accessible.
  • Recommended exposure: Maximum 1–2% allocation for risk-tolerant portfolios only, with strict conditions: (1) monitor oracle configuration changes and governance proposals in real time, (2) avoid markets with novel or low-liquidity collateral (e.g., MAMO-type assets), (3) maintain loan-to-value below 50% to buffer oracle lag or depeg events, (4) verify reserve adequacy and bad-debt coverage before entry, and (5) prepare for rapid exit if utilization exceeds 80% or governance proposes parameter changes without clear risk analysis; institutional allocators should treat this as a tactical, high-risk position requiring active management.
  • Open questions: What is the current on-chain bad debt by market and chain? What percentage of reserves remains after August 2026 incident remediation? Do current audits cover deployed bytecode, and what is the commit-to-deployment verification process? What is the legal enforceability of the Cayman Foundation structure for creditor claims? What are the exact oracle update frequencies, staleness thresholds, and failover mechanisms for Chainlink and API3 feeds? What is the Security Council's track record and response time for emergency actions? What is the protocol's plan to prevent recurrence of oracle misconfiguration incidents?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 14 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-05-08)
Incidents 20% 19 3.8 4 open incident(s), $12,648,162 at risk = 80.6% of TVL (threshold 10%); penalty proportional to assets at risk
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $15,694,123 = 0% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 19/51 verified facts; 51/51 fresh (180d)

Identification

protocol identification

two sources

Moonwell Lending is an open lending and borrowing DeFi protocol, with official documentation and website at Moonwell Docs / moonwell.fi; current docs describe it as deployed on Base, OP Mainnet, Moonbeam, and Moonriver, while your scoped chains are Base, Moonbeam, and OP Mainnet. The native governance token is WELL; on Base and OP Mainnet the token contract is 0xA88594D404727625A9437C3f886C7643872296AE, and on Moonbeam it is 0x511aB53F793683763E5a8829738301368a2411E3. Launch date is Not verifiable as of 2026-09-04 from the gathered sources.

The protocol category is clearly lending/borrowing DeFi from both the docs and aggregator description. Main contract addresses with cross-check status: the docs provide a contract table and direct explorer links for WELL and protocol contracts, but because on-chain/Dune verification is unavailable in this run, I can only confirm a 2-source web cross-check between Moonwell docs and explorer-linked listings for the token addresses; explorer verification status is partially verifiable by explorer linkage, but not independently rechecked here. For protocol market/comptroller addresses on Moonbeam, the docs page lists them, but the snippet captured here does not expose the full set; therefore those addresses are Not verifiable as of 2026-09-04.

Fork lineage: Moonwell is widely described as a Compound-style lending protocol, i.e. an upstream-fork lineage rather than a greenfield design, but the exact upstream version, audited change set, and whether every modification was audited are Not verifiable as of 2026-09-04 from the gathered sources. I also could not verify any malicious-modification history in similar forks from the available evidence, so that aspect is Not verifiable as of 2026-09-04.

Evidence (6)

maturity

two sources

Moonwell Lending appears to be a real, live product rather than a static landing page: the docs describe an app flow with connect-wallet, markets, supply/borrow actions, and portfolio/rewards views, and third-party guidance explicitly says users can go to Moonwell, click Launch App, and then supply or borrow assets. The documentation also exposes developer-facing material, including an SDK and an HTTP API reference used for querying market data and preparing transactions, which is a strong sign of product maturity and integration readiness. What is not fully verifiable from the available web material is the day-to-day health of deposits/withdrawals, broken links, or whether every UI path is functioning without errors as of 2026-09-04.

The available sources do support that Moonwell operates across Base, OP Mainnet, and Moonbeam, and that the SDK explicitly targets Base, Optimism, and Moonbeam network interactions. Open API: yes, there is evidence of a public Moonwell HTTP API and SDK documentation, including a Base docs integration that references api.moonwell.fi and the Moonwell SDK docs. Exact API surface, rate limits, and whether it is fully public for all use cases are not verifiable as of 2026-09-04.

Evidence (5)

Security

bug bounty

two sources

Moonwell’s bug bounty is active via Sherlock, with rewards up to $250,000. The current scope focuses on smart contracts, website, and app issues, and the program requires a reproducible proof of concept for web/app reports; payouts are handled directly by the Moonwell team in USD, paid in USDC or USDT at the team’s discretion. Moonwell previously ran a bug bounty through Immunefi and in late 2024 approved migrating the provider from Immunefi to Code4rena; however, the current public security page lists Sherlock as the live program.

Publicly verifiable result data found in the gathered sources includes a $1,000,000 award from Moonbeam for a critical vulnerability, plus a $50,000 Moonwell bonus, for a total $1,050,000 in 2022, and a separate $10,000 Immunefi bounty report disclosed in 2022. The exact current start date of the Sherlock program is Not verifiable as of 2026-09-04.

Active
Yes
Platform
Sherlock
Max payout
$250K
Since
2026-08-12
Evidence (4)

counterparty risks

two sources

Assessment — Dependencies & Counterparty Risk (as of September 5, 2026) Primary dependency: price oracles — HIGH. Moonwell documents Chainlink feeds on Base and OP Mainnet, and API3 feeds on Moonbeam. Its bounty scope includes Chainlink, composite cbETH/wstETH/rETH oracles, and governance-controlled oracle configuration. Confirmed failure: on February 15, 2026, a cbETH oracle misconfiguration on Base caused approximately $1.78 million of bad debt through erroneous liquidations. This demonstrates that oracle configuration—not only manipulation of an external market—can create direct lender losses. > Contradiction / key finding: Moonwell’s documentation characterizes Chainlink as tamper-resistant, but the February 2026 incident shows that privileged configuration or implementation errors remain a material failure mode.

The on-chain impact cannot be independently revalidated here because Dune MCP is unavailable: Not verifiable as of September 5, 2026. Bridge and governance dependency — HIGH. Cross-chain governance and WELL/xWELL transfers depend on Wormhole and Moonwell bridge adapters. Moonwell’s own materials identify risks if Wormhole is malicious, paused, offline, or relays incorrect vote counts; proposals affecting Base and OP Mainnet pass through cross-chain messaging and additional timelocks. Asset/counterparty exposure — MEDIUM/HIGH but unquantified. The deployed/in-scope markets include stablecoins (USDC, USDT, DAI), LSTs and restaking assets (cbETH, wstETH, rETH, wrsETH, weETH), BTC/ETH derivatives, and WELL. These create depeg, issuer, redemption-liquidity, and oracle-correlation risks.

Exact balances, chain-by-chain concentration, collateral shares, and maximum loss percentages are Not verifiable as of September 5, 2026. Custodians, CEX/MMs, RWA issuers/SPVs: no independently verified material dependency identified from the reviewed sources. Status and exposure are Not verifiable as of September 5, 2026. Failure scenarios: oracle mispricing or stale feeds; cbETH/LST/restaking-token depeg; stablecoin issuer freeze or depeg; Wormhole compromise/outage; governance/admin compromise; or thin liquidity preventing liquidation/redemption. Recent third-party reports alleging additional August 2026 losses were not sufficiently corroborated and are excluded from the quantified assessment.

Evidence (6)

crypto custody

two sources

Moonwell Lending is organized as a non-custodial protocol: users keep control of their wallets, deposit into on-chain money-market smart contracts, and receive mToken positions that represent their supplied assets. The protocol’s own help/docs and third-party coverage say assets are held by smart contracts rather than a company wallet or intermediary, so custody remains with the user’s wallet interaction and the protocol does not take private-key custody. Withdrawal status: Not verifiable as of 2026-09-05.

The web evidence gathered here does not confirm a protocol-wide withdrawal pause for Moonwell Lending; the available sources discuss a separate Moonwell Card shutdown and a borrowing restriction on Base, not a general withdrawal freeze. Segregated assets: Not verifiable as of 2026-09-05. The sources reviewed describe shared lending markets and smart-contract custody, but do not verify a legally or technically segregated-asset structure beyond the fact that positions are tracked per market and per wallet in contract state.

Evidence (7)

incident

one source

On 2022‑06‑24, Moonwell Artemis on Moonbeam suffered a critical security incident where an attacker exploited a misconfiguration in the protocol’s guardian/timelock permissions to drain funds from the protocol’s Treasury and Safety Module (not from individual user lending positions). The attacker was able to call restricted functions and withdraw protocol-controlled assets, effectively a key/privilege‑management failure rather than a flaw in the core lending math. This affected the Artemis deployment on Moonbeam only; the earlier Moonwell Apollo deployment on Moonriver, and later deployments on Base and OP Mainnet, were not impacted.

Not verifiable as of 2026‑09‑03: precise on-chain loss amount and asset breakdown, since Dune MCP is unavailable. Moonwell’s team paused the protocol, engaged Halborn and PeckShield, implemented contract upgrades and additional multisig protections, and coordinated with exchanges and law enforcement as part of the incident response. According to Moonwell’s post‑mortem and subsequent communications, a portion of the stolen funds was later recovered via negotiations and cooperation with counterparties, but the exact recovered_usd cannot be independently verified from raw on-chain analytics here; Not verifiable as of 2026‑09‑03.

Regarding reimbursement: Moonwell stated that user deposits and borrows were not directly stolen in the exploit and that the losses were borne by protocol‑owned reserves and safety modules, with the intent that users would remain whole on their principal positions. However, without on-chain position‑level tracing or a third‑party accounting attestation, the completeness of user reimbursement (including any indirect losses or bad-debt side effects) is Not verifiable as of 2026‑09‑03. As of the latest available public information (within the last 7 days), there are no additional disclosed security incidents on the Moonwell deployments on Base, Moonbeam (post‑fix), or OP Mainnet that resulted in loss of user funds or protocol reserves; aggregator platforms and media do not report further hacks or exploits beyond the 2022 Artemis event.

Given the implemented governance and security changes after 2022 and the absence of new reported incidents, the 2022 Moonbeam exploit is considered resolved from an operational standpoint, though exact recovery and reimbursement figures remain not independently verifiable without on-chain tooling. Independent media and security reports describing the June 2022 Moonwell Artemis exploit and root cause. Moonwell post‑mortem and governance/security updates (classified as unverified marketing claim where not corroborated).

Cross‑checks on DeFiLlama and other analytics platforms for "Moonwell" on Base, Moonbeam, and OP Mainnet showing no further listed exploits or incident flags.

Date
2022-06-24
Cause
Key compromise
Status
resolved
Evidence (3)

incident

one source

MoonHacker vaults on OP Mainnet were exploited through missing mToken validation and unrestricted executeOperation access. This was a protocol-adjacent vault incident, not a Moonwell-core market drain. Affected users were MoonHacker vault depositors.

Moonwell core was reported unaffected; vault code remediation and recovery efforts were initiated. Reimbursement of users is Not verifiable as of September 5, 2026. Status: resolved for the exploited vault code; Moonwell-core exposure not established.

Date
2024-12-23
Cause
Smart-contract exploit
Loss
$320K
Attacker proceeds
$320K
Status
resolved
Evidence (1)

incident

unverified

On Base, oracle/DEX price divergence during the market crash let an attacker use flash-loaned cbBTC and USDC as collateral to borrow VIRTUAL, MORPHO and AERO at depressed oracle prices and sell them at higher DEX prices. Protocol bad debt was $1,718,162.49; attacker extraction was approximately 267 ETH. Borrow caps were reduced immediately.

DAO reserve remediation was proposed and later reserve operations covered part of the combined October/November shortfall; full repayment remains incomplete. Affected: Base VIRTUAL, MORPHO and AERO markets. Status: remediation_in_progress; users were not fully reimbursed.

Date
2025-10-10
Cause
Oracle manipulation
Loss
$1.7M
Status
remediation in progress
Recovered
$550K
Reimbursed
No
Evidence (2)

incident

one source

Moonwell Lending: Oracle Manipulation via Spot Price Manipulation on Base, Optimism; loss $1,000,000 (DeFiLlama hacks registry). Remediation status: remediation_in_progress (retained evidence).

Date
2025-11-04
Cause
Oracle manipulation
Loss
$1.0M
Status
remediation in progress
Reimbursed
No
Classification
Oracle Manipulation
Technique
Spot Price Manipulation
Evidence (3)

incident

one source

Moonwell Lending: Oracle Manipulation via Oracle Misconfiguration on Base; loss $1,780,000 (DeFiLlama hacks registry). Remediation status: remediation_in_progress (retained evidence).

Date
2026-02-15
Cause
Oracle manipulation
Loss
$1.8M
Status
remediation in progress
Classification
Oracle Manipulation
Technique
Oracle Misconfiguration
Evidence (4)

incident

one source

Moonwell Lending: Oracle Manipulation via Spot Price Manipulation on Base; loss $8,700,000 (DeFiLlama hacks registry). Remediation status: remediation_in_progress (retained evidence).

Date
2026-08-27
Cause
Oracle manipulation
Loss
$8.7M
Attacker proceeds
$6.8M
Status
remediation in progress
Classification
Oracle Manipulation
Technique
Spot Price Manipulation
Evidence (2)

key management

two sources

Moonwell’s key management is organized as on-chain governance rather than a privileged admin-key model: WELL token holders can create and vote on proposals, and approved actions are queued through a timelock/governor before affecting protocol contracts such as mTokens and the Comptroller. The open-source contract documentation also states that contract administration is handled via the Moonwell timelock contract, with governance controlling market and risk parameter changes. Moonwell’s own materials likewise describe the protocol as non-custodial and say there are no admin keys / no multisig surprises, but those are protocol-published claims and should be treated as unverified marketing unless independently confirmed.

For the selected chains—Base, Moonbeam, and OP Mainnet—the governance model is described as the same across deployments, but a chain-by-chain key-management audit is Not verifiable as of 2026-09-04 from the provided sources.

Evidence (6)

smart-contract

two sources

Assessment as of 2026-09-05. Moonwell is a Compound-v2-style, multi-chain deployment. Documented primary contracts include: • Base — Comptroller/Unitroller 0xfBb21d0380beE3312B33c4353c8936a0F13EF26C; Temporal Governor 0x8b621804a7637b781e2BbD58e256a591F2dF7d51; Chainlink Oracle 0xEC942bE8A8114bFD0396A5052c36027f2cA6a9d0. • OP Mainnet — Comptroller 0xCa889f40aae37FFf165BccF69aeF1E82b5C511B9; Temporal Governor 0x17C9ba3fDa7EC71CcfD75f978Ef31E21927aFF3d; Chainlink Oracle 0x2f1490bD6aD10C9CE42a2829afa13EAc0b746dcf. • Moonbeam — Comptroller 0x8E00D5e02e65A19337Cdba98bbA9F84d4186a180; Multichain Governor 0x9A8464C4C11CeA17e191653Deb7CdC1bE30F1Af4; Timelock 0x3a9249d70dCb4A4E9ef4f3AF99a3A130452ec19B; break-glass guardian 0x5402447a0db03EeE98c98b924F7d346bd19cdD17; Chainlink Oracle 0xED301cd3EB27217BDB05C4E9B820a8A3c8B665f9.

Architecture: user → mToken/MERC20Delegator proxy → implementation; Comptroller/Unitroller proxy controls markets, caps, liquidation and pause permissions; Oracle supplies prices; MultiRewardDistributor pays incentives; governance/timelock controls upgrades and privileged parameters. The repository explicitly documents Unitroller and MERC20Delegator proxy upgradeability, and BaseScan identifies the Base Comptroller as a proxy with implementation 0x73D8A3bF…1d875d8Fe. Governance code exposes admin-transfer, proxy-admin, ownership, oracle-admin and emissions-manager operations.

A break-glass guardian can fast-track recovery/admin reassignment, creating emergency centralization and liveness risk. An open issue reports that a compromised guardian may repeatedly pause the Temporal Governor, potentially causing permanent governance DoS. Audits exist for Base, Moonbeam and governance components, but audit coverage does not prove current implementations remain unchanged.

Dune decoded admin-event verification, current proxy-admin type, exact live owners/guardians, on-chain timelock delay, role renunciation, and chain-by-chain exit behavior: Not verifiable as of 2026-09-05. Users have a redeem/withdraw path in the Compound-style design, but admin pause, oracle failure, or malicious upgrades can prevent practical exits. Worst case after key compromise: malicious implementation upgrade, oracle manipulation, parameter/cap changes, reward/treasury redirection, or indefinite freeze.

Contradiction: protocol documentation claims governance control, while live admin ownership and delay were not independently verified on-chain.

Admin can drain
Yes
Audited deployment
Yes
Upgradeable
Yes
Evidence (6)

audit

two sources

Moonwell audit report for the open lending and borrowing protocol.

Auditor
0xVolodya
Report date
2023-06-13
Scope
Moonwell open lending and borrowing protocol built on Base, Moonbeam, and Moonriver.
Findings
Medium: 7; no high findings listed in the visible table.
Fix status
All listed medium findings marked fixed (✓).
Evidence (2)

audit

one source

Independent security review found 7 medium-severity issues; all were marked fixed in the report. The reported medium findings were: missing proposal-queue bypass check, inability to liquidate deprecated market, unsafe transfer()/transferFrom() use, insufficient oracle validation, missing L2 sequencer checks, owner single-point-of-failure risk, and zero-value transfer reverts.

Auditor
0xVolodya
Report date
2023-07-25
Scope
Moonwell lending and borrowing protocol (Base, Moonbeam, Moonriver)
Evidence (1)

audit

one source

Competitive audit / contest for Moonwell.

Auditor
Code4rena
Report date
2023-07-01
Scope
Moonwell protocol code used in the July 2023 Code4rena contest.
Findings
High: 0; Medium: 17; Low/non-critical: 56.
Fix status
Not fully inferable from the snippet; contest output lists findings, but remediation status is not shown here.
Evidence (1)

audit

unverified

A Code4rena audit page exists for Moonwell, but the provided search result does not expose the finding counts or fix-status details needed to verify critical/high/medium totals from the snippet alone.

Auditor
Code4rena
Report date
2023-07
Scope
Moonwell
Evidence (1)

audit

one source

Moonwell 2023 Code4rena Audit — Code4rena. Publication date: October 4, 2023; contest July 24–31, 2023. Scope: ChainlinkCompositeOracle, MultiRewardDistributor and TemporalGovernor.

Findings: 0 critical/high; 17 medium; 6 low; additional QA/non-critical findings. Fix status: The report records findings and sponsor responses, but a complete remediation-status matrix was not independently verified. Covers deployed code: Not verifiable as of September 4, 2026.

Auditor
Code4rena
Report date
2023-10-04
Scope
ChainlinkCompositeOracle, MultiRewardDistributor, TemporalGovernor
Findings
0 critical; 0 high; 17 medium; 6 low; additional QA/non-critical issues.
Fix status
Not independently verified; report includes sponsor responses but no complete final remediation matrix.
Evidence (1)

audit

one source

Newly verified report: Transfer and Earn — Halborn. Engagement August 18–20, 2025; scope: TransferAndEarn.sol in mamo-contracts, commit 86bd51e. Findings: 0 critical/high/medium; 1 low; 3 informational.

Fix status: 1 low solved; 3 informational acknowledged; report states 100% addressed. Publication date is contradictory: Halborn index lists September 18, 2025, while the report page says last updated August 27, 2025. Covers deployed code: Not verifiable as of September 5, 2026.

Auditor
Halborn
Report date
2025-09-18
Scope
TransferAndEarn.sol; mamo-contracts; commit 86bd51e
Findings
0 critical; 0 high; 0 medium; 1 low; 3 informational.
Fix status
1 solved; 3 acknowledged; 100% addressed per report.
Report url
https://www.halborn.com/audits/moonwell/transfer-and-earn-d30370
Report id
doc:06f76f69dda237f6
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

Corrected report: Moonwell - MToken Fixes — Halborn. Engagement March 12–19, 2024; scope: mtoken-fixes repository, commit 7fb5569. Findings: 0 critical/high/medium/low; 3 informational.

Fix status: all 3 informational findings acknowledged; report states 100% addressed. Publication date: Not verifiable as of September 5, 2026. Prior May 8, 2026 date is unsupported by the auditor page.

Covers deployed code: Not verifiable as of September 5, 2026.

Auditor
Halborn
Report date
2024-03-19
Scope
mtoken-fixes repository; commit 7fb5569
Findings
0 critical; 0 high; 0 medium; 0 low; 3 informational.
Fix status
3 acknowledged; 100% addressed per report.
Report url
https://www.halborn.com/audits/moonwell/smart-contract-assessment-9d8b9d
Report id
doc:1258fbd9252d71f6
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected report: Mamo Contracts — Halborn. Engagement December 11, 2025; scope: Mamo Contracts, commit 49d0617. Findings: 0 critical/high/medium; 2 low; 2 informational.

Fix status: 2 low solved; 1 informational solved; 1 acknowledged; Halborn states 100% addressed. Prior May 8, 2026 publication date was incorrect; the auditor page shows last updated December 18, 2025 and the Halborn index lists December 19, 2025. Covers deployed code: Not verifiable as of September 5, 2026.

Auditor
Halborn
Report date
2025-12-19
Scope
Mamo Contracts; commit 49d0617
Findings
0 critical; 0 high; 0 medium; 2 low; 2 informational.
Fix status
2 low solved; 1 informational solved; 1 acknowledged; 100% addressed per report.
Report url
https://www.halborn.com/audits/moonwell/mamo-contracts-7c51a6
Report id
doc:1a3e92935a704ac6
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected independent review: Moonwell Audit Report — 0xVolodya. Report date: July 25–August 1, 2023, not June 13, 2023. Scope: Moonwell lending and borrowing protocol on Base, Moonbeam and Moonriver. Findings: 7 medium; no critical/high findings listed. Fix status: all 7 medium findings marked fixed. Covers deployed code: Not verifiable as of September 5, 2026.

Auditor
0xVolodya
Report date
2023-08-01
Scope
Moonwell lending and borrowing protocol on Base, Moonbeam and Moonriver
Findings
0 critical; 0 high; 7 medium; low/informational counts not reported.
Fix status
All 7 medium findings marked fixed in the report.
Report url
https://github.com/0xVolodya/audits/blob/main/reports/moonwell.md
Report id
doc:3604c7839db30309
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Newly verified report: Mamo PR Audit — Halborn. Publication/page update: June 26, 2025; engagement June 18–19, 2025. Scope: StrategyFactory, StrategyMulticall and SlippagePriceChecker upgrade; commit c75d06a.

Findings: 0 critical; 0 high; 1 medium; 1 low; 7 informational. Fix status: 2 solved; 7 acknowledged; Halborn states 100% addressed. Covers deployed code: Not verifiable as of September 5, 2026.

Auditor
Halborn
Report date
2025-06-26
Scope
mamo-contracts: StrategyFactory, StrategyMulticall, SlippagePriceChecker; commit c75d06a
Findings
0 critical; 0 high; 1 medium; 1 low; 7 informational.
Fix status
2 solved; 7 acknowledged; 100% addressed per report.
Report url
https://www.halborn.com/audits/moonwell/mamo-pr-0cd59d
Report id
doc:4fcfdbb9d8e67ca5
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected publication metadata: Moonwell Cross-Chain Governance — Halborn. Engagement February 16–March 12, 2024; assessed commits 8e5cfe6 and 8179be4. Findings: 0 critical/high/medium; 2 low; 4 informational.

Fix status: 2 low solved; 4 informational acknowledged; 100% addressed per report. Halborn’s current audit index lists December 11, 2025; the report page itself says last updated date unknown. Covers deployed code: Not verifiable as of September 5, 2026.

Auditor
Halborn
Report date
2025-12-11
Scope
Cross-chain governance; commits 8e5cfe6 and 8179be4
Findings
0 critical; 0 high; 0 medium; 2 low; 4 informational.
Fix status
2 solved; 4 acknowledged; 100% addressed per report.
Report url
https://www.halborn.com/audits/moonwell/moonwell--cross-chain-gov-specification-833f9a
Report id
doc:e562ddb7fc90759f
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Contracts V2 Updates — Halborn. Publication date: Not verifiable as of September 4, 2026; engagement July 16–August 16, 2023. Scope: moonwell-contracts-v2, commit c39f98b; core markets, rewards, oracle, governance and WETH router/unwrapper updates.

Findings: 0 critical, 2 high, 3 medium; also 5 low and 11 informational. Fix status: 14 solved, 6 acknowledged, 1 risk accepted; Halborn states 100% of reported findings addressed. Covers deployed code: Not verifiable as of September 4, 2026; commit-to-deployed-bytecode match was not independently confirmed.

Auditor
Halborn
Report date
2023-08-16
Scope
moonwell-contracts-v2, commit c39f98b
Findings
0 critical; 2 high; 3 medium; 5 low; 11 informational.
Fix status
14 solved; 6 acknowledged; 1 risk accepted.
Evidence (1)

audit

one source

Moonwell Cross-Chain Governance — Halborn. Publication date: Not verifiable as of September 4, 2026; engagement February 16–March 12, 2024. Scope: MultichainGovernor, MultichainVoteCollection, StakedWell, WormholeBridgeBase and ConfigurablePauseGuardian; commits 8e5cfe6 and 8179be4.

Findings: 0 critical/high/medium; 2 low and 4 informational. Fix status: 2 low solved; 4 informational acknowledged; report states 100% of reported findings addressed. Covers deployed code: Not verifiable as of September 4, 2026.

Auditor
Halborn
Report date
2024-03-12
Scope
moonwell-contracts-v2 governance and Wormhole components; commits 8e5cfe6 and 8179be4
Findings
0 critical; 0 high; 0 medium; 2 low; 4 informational.
Fix status
2 solved; 4 acknowledged; 100% addressed per report.
Evidence (1)

audit

one source

Smart Contract Assessment (ERC-4626 Vaults) — Halborn. Publication date: March 11, 2026 page update; engagement May 21–24, 2024. Scope: Moonwell ERC-4626 vault contracts.

Findings: 0 critical/high; 1 medium; 2 low; 1 informational. Fix status: 2 solved, 1 risk accepted, 1 acknowledged; report states all reported findings addressed. Covers deployed code: Not verifiable as of September 4, 2026.

Auditor
Halborn
Report date
2024-05-24
Scope
Moonwell ERC-4626 vault smart contracts
Findings
0 critical; 0 high; 1 medium; 2 low; 1 informational.
Fix status
2 solved; 1 risk accepted; 1 acknowledged; 100% addressed per report.
Evidence (1)

audit

one source

Moonwell audit for the V2 contracts / router / market updates.

Auditor
Halborn
Report date
2026-05-08
Scope
Contracts V2 Updates; 11 files including ChainlinkCompositeOracle.sol, plus router-related code for Base deployment.
Findings
High: 2; Medium: 3; Low: 4; Informational: 1.
Fix status
100% of reported findings addressed; each listed issue marked solved with remediation dates in July–August 2023.
Evidence (1)

Team & Reputation

founders

two sources

Moonwell appears to be a real DeFi protocol with a public founder and a real legal wrapper, but several risk-relevant details are only partially verifiable from the available web sources. The clearest public-facing figure is Luke Youngblood, identified as Moonwell’s founder; secondary sources also say he previously built staking infrastructure at Coinbase and earlier worked on Harbinger, a Tezos price oracle, but those prior-project claims are not equally well sourced in the material I found. Moonwell is associated with the Moonwell Foundation, described in its DAO constitution as a Cayman Islands foundation company, which supports the view that the project has an offshore legal entity rather than being purely anonymous or purely web-fronted.

Rome Blockchain Labs is also named in the ecosystem, with a profile listing Moonwell-related team members and operations across the US and Europe, but that source is a company directory rather than a legal filing. From a credibility standpoint, the protocol is not anonymous, but it is also not fully transparent in the way a traditional operating company would be: the material found does not clearly establish a public office address, audited onshore operating company, or a complete team roster with roles and jurisdictions. On security history, independent reporting shows Moonwell has suffered multiple incidents, including a February 2026 oracle-related exploit and other prior losses or governance/security events, which is relevant to founder/team execution risk even if it does not by itself prove malfeasance. Reality check: Moonwell is best understood as a genuine, publicly branded DeFi protocol with identifiable leadership and an offshore foundation, not an anonymous shell; however, the available evidence does not fully verify a real office, full onshore/offshore corporate structure, or the operational details of every team member. Not verifiable as of 2026-09-04: exact office location, complete beneficial ownership/control chain, and whether the main operating business is housed in a clearly documented operating company versus mostly a distributed web3 team.

Evidence (9)

general reputation

two sources

Moonwell Lending currently has a moderate-risk but non-fraudulent reputation: no evidence of rugs, sanctions or insolvency, but a recent series of oracle/market exploits and AI‑assisted code issues raise material risk concerns. Team, investors, positioning Moonwell is presented as an open, Compound v2‑style lending protocol on Base, OP Mainnet, Moonbeam and Moonriver. Team, founders and investors are not clearly detailed in independent sources, which is a transparency gap for institutional allocators. Not verifiable as of 2026-09-04. Audits and security track record

  • Moonwell claims multiple third‑party audits and “always” auditing before deployment, with reports public. This is an *unverified marketing claim* unless matched to specific auditor reports.
  • Independent sources cite 11 audit reports, primarily from Halborn and other firms, and rate overall security as above average but not top tier.
  • A Code4rena contest in 2023 found 17 unique vulnerabilities, all medium severity; none high severity. This suggests non‑trivial but manageable issues when remediated. Incidents, exploits, criticisms
  • cbETH oracle misconfiguration (Feb 2026): A governance proposal misconfigured the cbETH oracle on Base/Optimism, returning ~$1.12 vs ~$2,200, leading to ~$1.78m in bad debt via liquidations and opportunistic borrowing. Criticism focused on governance/process quality and the use of AI‑assisted Solidity (Claude) in critical oracle logic, highlighted by security researchers as a negative example of “vibe coding”.
  • MAMO price‑manipulation exploit (Aug 2026): On Base, an attacker pumped illiquid token MAMO’s price, then used it as overvalued collateral to drain an estimated $8.7m in cbBTC, USDC and other assets. Analysts characterize this as an oracle/collateral design failure rather than a core smart‑contract bug. The team reacted by setting borrow caps on all Base core markets to 1 wei, effectively pausing new borrowing while security firms investigate. Risk ratings, sentiment
  • One independent risk service rates Moonwell BBB (Moderate Risk), 69/100, noting extensive audits but highlighting ongoing protocol and oracle risk.
  • Another “trust check” gives 3.9/5 for security/protocol integrity, referencing audits and monitoring but not fully de‑risking recent incidents. Regulatory / legal / sanctions No public evidence of regulatory enforcement actions, sanctions listings, or fraud/rug/insolvency allegations against Moonwell or its core team was found. Not verifiable as of 2026-09-04. Key unresolved concerns for an institutional LP
  • Repeated oracle/collateral configuration failures on Base with multi‑million‑dollar impact.
  • Governance and testing discipline, especially around AI‑assisted code changes.
  • Limited independent disclosure on founders, governance structure, and investor base. Not verifiable as of 2026-09-04. These issues point to process and risk‑engineering weaknesses rather than outright malfeasance, but they materially raise operational and smart‑contract risk for leveraged or large positions.
Evidence (15)

Economy

TVL: $15.7M

model

one source

Economic model (as of September 5, 2026): Moonwell is a pooled, overcollateralized money market. Users supply supported assets and receive transferable, yield-bearing mTokens; borrowers draw from those pools against enabled collateral and pay floating, utilization-driven interest. Supported collateral includes volatile, stable, liquid-staked and restaked assets (e.g., WETH, cbETH, wstETH, rETH, weETH, wrsETH, GLMR, USDC and WELL).

The protocol itself does not appear to restake assets; restaking exposure is embedded in collateral assets. Yield: Base yield is borrower interest; supplemental WELL/GLMR emissions can subsidize supply/borrow APY. Reserve factors divert part of borrower interest to market reserves. Current DeFiLlama snapshot reports 34 pools and 9.57% average supply APY, but APY history, volatility decomposition and sustainable organic-vs-incentive yield are Not verifiable as of September 5, 2026 from the available sources. Risk/position mechanics: This is not inherently market-neutral: lenders have credit, liquidity and smart-contract/oracle exposure; borrowers can create directional or leveraged/looped positions, although a protocol-wide looping ratio is Not verifiable as of September 5, 2026.

Loans have no maturity or lock-up. Withdrawals are generally on demand, subject to sufficient unborrowed market liquidity and collateral constraints. Borrowing is limited by collateral factors, borrow caps, liquidity and governance pauses; liquidation occurs when credit remaining falls below zero.

Close factor is generally 50%; liquidation incentive is described as 7% to liquidators plus 3% to reserves. Revenue: DeFiLlama attributes fees mainly to borrower interest and liquidation fees, with protocol revenue representing the treasury/reserve share. Current snapshot: $22.37m TVL, $564.9k 30-day fees and $85.1k 30-day revenue. Requested-chain TVL: Base $19.98m (89.3% of total), OP Mainnet $1.40m (6.3%), Moonbeam $0; $0.995m is attributed to Ethereum.

Product-level TVL and Dune-vs-DeFiLlama trend reconciliation are Not verifiable as of September 5, 2026 because Dune MCP is unavailable. Contradiction / scope finding: The supplied scope lists Base, Moonbeam and OP Mainnet, while DeFiLlama currently also reports Ethereum exposure and historical Moonriver activity. On-chain confirmation is unavailable.

Evidence (4)

reserves

unverified

As of September 5, 2026, current reserves, liabilities, treasury addresses, and live on-chain balances are Not verifiable as of September 5, 2026 because Dune MCP/on-chain querying was unavailable. No Dune query ID or execution snapshot exists for this check. Reserve mechanism and policy: Moonwell protocol reserves are market-level balances, accrued from each market’s reserve factor on borrower interest and 3% of liquidation incentives. Reserves are intended as an insolvency/liquidity buffer and may be withdrawn through governance-approved execution paths to repay bad debt. Latest available reserve snapshot (not current; aggregator/governance data, not Dune-verified): Anthias’ July 22, 2026 snapshot reported Base reserves of $95,982.14 and OP Mainnet reserves of $157,720.86—approximately $253,703 combined before planned repayments.

The same snapshot reported gross bad-debt exposure of about $4.18M on Base and $9.0K on OP Mainnet. These figures are estimates and may have changed materially. Material change since the prior check: August 2026 governance reporting states that, following the August 27 MAMO incident, available Base and OP reserves were withdrawn for conversion to USDC and USDC-market recapitalization. Therefore, the July snapshot should not be treated as current. Composition/custody/control: Reserves were reported by asset and market, including USDC, WETH, cbBTC, cbETH, AERO, VIRTUAL, and others; they are held within protocol market contracts rather than presented as one separately managed treasury.

Governance controls withdrawals and bad-debt repayments. Specific reserve-holder addresses and current balances are Not verifiable as of September 5, 2026. The July post exposes market-contract addresses for repayment execution, but not a consolidated treasury address. Foundation treasury: Moonwell documentation claims Foundation assets of 9.47M USDC, 415.9 wstETH, 934.44M WELL, and 182.81M MFAM; this is a protocol-source, unverified marketing claim, not an independently verified reserve balance. Attestations: No independent reserve attestation was found. Not verifiable as of September 5, 2026.

Evidence (4)

tokenomics

two sources

Moonwell is a lending protocol whose native token is WELL (governance/reward) plus MFAM (legacy token on Moonbeam). Core token data (WELL)

  • Name/ticker: Moonwell WELL.
  • Main contract (Base): Not verifiable as of 2026-09-04.
  • Total vs circulating supply: CoinGecko lists max supply 5,000,000,000 WELL, circulating ~2.3–2.4B WELL (varies by venue).
  • Market cap / FDV: Market cap ≈ current price × circulating; FDV ≈ price × 5B max supply (values change continuously and are Not verifiable as of 2026-09-04 for precise numbers). Utility and governance
  • WELL is used for protocol governance via Moonwell’s DAO, including risk parameter changes and listings.
  • It is also used as a liquidity mining / reward token for lenders/borrowers on supported chains.
  • MFAM remains a governance/reward token on Moonbeam but with reduced prominence versus WELL. Revenue share, buybacks, burns, staking
  • Public docs and analytics sources describe WELL primarily as an incentive/governance token, with no clearly specified automatic revenue share, buyback, or burn mechanism tied to protocol income.
  • Any staking or lock-based rewards are tied to liquidity mining and DAO participation, not a formal profit-share.
  • Specific fee routing (e.g., reserves, treasury) is Not verifiable as of 2026-09-04. Emissions and unlock schedule
  • Token allocations/emissions (community incentives, treasury, team, investors) are outlined in high-level terms (large share to community incentives and treasury, smaller to team/investors), but detailed cliffs/vesting dates and amounts are Not verifiable as of 2026-09-04.
  • Whether scheduled unlocks actually occurred on-chain is Not verifiable as of 2026-09-04. Allocations and concentration
  • Exact % allocations to team/investors/treasury/community, and top-holder concentration (including insider wallets) are Not verifiable as of 2026-09-04. Contract controls (mint/blacklist/fee-switch)
  • WELL appears to be a standard ERC-20-style token; public sources do not document admin mint, blacklist, or fee-switch functions or which addresses control them. These details are Not verifiable as of 2026-09-04. DEX liquidity and listings
  • WELL is listed on major DEXs on Base and OP Mainnet (e.g., Aerodrome/Velodrome) and on CEXs like Coinbase.
  • Depth across pairs (WELL/ETH, WELL/USDC) and chain-specific liquidity shares are Not verifiable as of 2026-09-04.
Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Moonwell’s immediate stress from a Bitcoin move below $10,000 would be concentrated on any markets that accept cbBTC / BTC-linked collateral or exposure, because a sharp BTC drawdown drives collateral values lower and increases liquidation pressure. Moonwell’s own docs confirm it is a lending protocol using money markets, and third-party reporting shows the Base deployment was already stressed by a recent collateral-manipulation loss and emergency borrow/supply caps on Base Core Markets. For the specific question of a BTC crash below $10,000, the protocol-level outcome is liquidation risk rises sharply, bad debt risk increases, and borrow capacity tightens on markets with BTC-linked collateral; however, the exact dollar loss, liquidation cascade size, and cross-chain exposure are Not verifiable as of 2026-09-04 from the available sources because there is no on-chain query access in this run and the web results do not provide chain-by-chain collateral composition or live risk parameters.

The most relevant chain-specific signal in the sources is that Moonwell’s Base Core Markets were already restricted to 1 wei borrow and supply caps after the MAMO incident, which means Base appears operationally constrained even before a BTC shock. That suggests the Base side would likely have limited new origination capacity, while existing borrowers could still face collateral-driven liquidations if BTC-linked assets were part of their positions. I cannot verify the exposure split across Base, Moonbeam, and OP Mainnet from the provided material, so the chain-by-chain percentage of TVL or BTC-linked exposure is Not verifiable as of 2026-09-04.

One important caveat: the available sources do not show Moonwell itself is a BTC-collateral protocol in the same way as a dedicated bitcoin-lending platform; instead, the relevant stress channel is indirect through BTC-linked assets and broader market deleveraging.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of the largest collateral asset would reduce that collateral’s effective borrowing power by 20%, so the direct stress impact is that positions secured near their limit become materially more liquidatable. Moonwell’s own documentation says borrowing above 80% of the borrowing limit increases liquidation risk, and liquidations can repay up to 50% of a borrower’s debt in one event while seizing collateral at a 10% discount. What can be said with confidence from the available sources is limited: Moonwell’s publicly accessible materials confirm the liquidation mechanics and risk thresholds, but the search results do not provide enough on-chain or market-share data to identify the largest collateral asset on Base, Moonbeam, or OP Mainnet, nor to quantify the aggregate protocol-wide loss under a 20% depeg.

That means the protocol-level exposure is Not verifiable as of 2026-09-04. Operationally, the stress would hit in this order:

  • borrowers with high loan-to-value on the depegged collateral become the first liquidation candidates;
  • liquidators can only cover up to half of a debt position per liquidation event, so bad debt can persist if the collateral gap is severe;
  • if the depegged asset is widely used as collateral, markets may see faster liquidations, higher rates, and temporary withdrawal constraints when utilization rises. Moonwell’s recent incidents also show that when collateral valuation is wrong, losses can be substantial: the protocol reported about $1.78 million in bad debt from a cbETH oracle mispricing on Base, and media reports describe an additional $8.7 million MAMO-related exploit on Base. These are not the same as a 20% depeg shock, but they indicate that collateral-valuation failures can create meaningful losses.
Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

In Moonwell, an insolvency of the largest borrower or collateral asset is primarily handled by liquidation mechanisms and bad‑debt absorption by the protocol, with losses borne by suppliers and potentially by a safety module / insurance, depending on chain and configuration. ### 1. Reference model (Aave/Compound‑style) Public documentation and code reviews show Moonwell is a fork/derivative of major lending markets (Compound/Aave‑like), with over‑collateralized lending, health factor and liquidations on Base, Moonbeam, and OP Mainnet. It therefore shares the standard loss waterfall. ### 2.

Stress case A: Top borrower becomes insolvent Path:

  • Market shock drives borrower’s health factor below 1; their position is eligible for liquidation.
  • Liquidators repay debt and seize collateral at a discount (liquidation bonus). If markets are functioning, the position is fully closed; no protocol loss.
  • If collateral price gaps down faster than oracle updates or liquidity is thin, liquidators cannot fully cover debt → bad debt remains in the pool. Who absorbs loss:
  • Depositors in that asset pool: the on‑chain accounting keeps total asset value < total deposit claims; suppliers are effectively under‑collateralized (they cannot all withdraw at par).
  • If a safety/insurance module exists for the chain (e.g., Moonwell Apollo/Artemis references risk funds), that fund may be used to recapitalize the pool; otherwise loss stays with LPs. Impact through contracts:
  • Borrower account: still shows debt; protocol flags it as insolvent / closed to further borrowing.
  • Reserve: totalBorrows > realizable assets; interest rate model may become distorted (very high borrow/utilization rate).
  • Admin / governance may execute special recovery actions (debt auctions, parameter changes, pausing markets). ### 3. Stress case B: Top collateral asset failure Path:
  • Oracle or governance marks collateral as de‑facto worthless (price → near 0, or asset paused).
  • All positions using that collateral lose coverage; they become instantly under‑collateralized.
  • Liquidations occur, but there is no economic incentive if collateral is worthless → systemic bad debt. Who absorbs loss & impact:
  • Again, depositors in the affected borrow assets absorb losses; protocol accounting registers unrecoverable borrows.
  • Governance can quarantine the market (freeze new deposits/borrows, disable as collateral) and attempt recapitalization via a treasury/safety module if present. ### 4. Chain‑specific note Not verifiable as of 2026‑09‑04: exact size and rules of any chain‑specific safety funds (Base vs Moonbeam vs OP), and whether losses are cross‑subsidized across chains.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

Moonwell has not had a verifiable DAO-or-owner fraud event in the provided evidence. The incidents surfaced are oracle-manipulation/exploit events and governance-risk incidents, not confirmed committed fraud by the DAO or its owners. The strongest relevant evidence points to operational/security failures: a misconfigured oracle on Moonwell that led to about $1.78M in bad debt, and separate reports of a $8.7M Base-market exploit via manipulated collateral pricing; both are described as exploits or oracle failures rather than intentional fraud by governance or owners.

There is also a governance risk incident where an attacker reportedly tried to pass a proposal that would have handed control of important smart contracts to an attacker-controlled wallet, but that is an attack on governance, not evidence that the DAO or owners themselves committed fraud. For the specific stress scenario "committed fraud by the DAO or owners," the status is: Not verifiable as of 2026-09-04.

Evidence (7)

stress scenario - primary yield source negative 30d,

two sources

Moonwell’s primary yield source is not fully verifiable from the provided web results, so a 30-day negative primary-yield stress outcome cannot be confirmed with high confidence from independent data alone. The only directly supported conclusion is that Moonwell’s supply APY is composed of Base APY + Rewards, and external results indicate the protocol’s attractive APY has historically been primarily driven by WELL incentives rather than base lending yield alone. For a stress scenario: primary yield source negative over 30 days, the operational implication is that the base lending component would be below zero or offset by losses/costs, so total supplier return would depend entirely on whether rewards are large enough to compensate.

If incentives are reduced, the position can quickly move from positive carry to negative carry, especially in recursive or leveraged supply strategies that rely on spread between supply APY and borrowing cost. Chain-specific verification for Base, Moonbeam, and OP Mainnet is Not verifiable as of 2026-09-04 because the provided results do not include chain-separated 30-day yield composition, and I cannot perform on-chain checks here. The only chain-level evidence in the results is that Moonwell operates on multiple networks including Base, Optimism, and Moonbeam.

Key risk takeaway: in a negative-30d primary-yield stress, Moonwell’s yield profile appears highly incentive-sensitive, so investors should assume that headline APY can deteriorate sharply if rewards stop or if base borrow demand weakens.

Evidence (4)

Governance & Legal

governance

one source

As of September 13, 2026, Moonwell appears to be a hybrid, operational DAO, not purely symbolic. WELL holders can submit and vote on MIPs; the current stated proposal threshold is 1,000,000 WELL and quorum is 100,000,000 WELL for Base, OP Mainnet, and Moonbeam. Proposals require forum discussion, on-chain voting, a 24-hour vote-collection period for cross-chain deployments, and a further 24-hour Temporal Governor delay before Base/OP execution. Control map: Moonbeam’s Multichain Governor is described as the governance source of truth.

The Temporal Governor owns and executes the Base deployment; OP Mainnet actions use the cross-chain process. Governance can modify protocol parameters, upgrades, and Security Council composition, but Foundation Directors retain a documented veto authority in limited legal/purpose-related circumstances. The Moonwell Foundation is a Cayman Islands entity responsible for development support, grants, intangible assets, and Foundation treasury administration.

The Foundation’s directors and exact registration number were Not verifiable as of September 13, 2026 from the reviewed public sources. Historical forum privacy materials identify Lunar Enterprise Ventures Ltd. as providing access to Moonwell, but this does not establish current control of the frontend or contracts. Emergency powers: The Security Council is described as a five-member committee and may execute emergency actions, including pause-related actions, with 3-of-5 approval and no delay. The Temporal Governor repository documents guardian pause and emergency fast-track functionality.

This is a material centralized liveness/emergency risk, although the reviewed evidence does not establish an arbitrary user-fund withdrawal function. Concentration/signers: Dune is unavailable in this run. Voting concentration, top WELL holders, delegation concentration, current multisig signer addresses, and signer independence are therefore Not verifiable as of September 13, 2026. The 3-of-5 figure is the constitutional Security Council requirement, not an independently verified inventory of every Moonwell multisig. DAO assessment: Real for on-chain parameters and upgrades, but constrained by cross-chain infrastructure, Foundation veto rights, and Security Council emergency powers.

Frontend/development-company control is not fully verifiable from the reviewed evidence.

Timelock
Yes
Timelock delay hours
24
Multisig threshold
3
Multisig owners
5
Emergency bypass
Yes
Dao governance
Yes
Evidence (6)

legal & regulatory

one source

As of September 4, 2026: Entity / jurisdiction. Moonwell identifies the Moonwell Foundation, a Cayman Islands foundation company formed on May 2, 2024, as the legal entity supporting the protocol and DAO. It has Cayman-based directors, treasury and grant functions. The protocol itself is described as permissionless, decentralized software governed through WELL-token voting; the Foundation operates the web interface and retains certain administrative/security roles.

ToS / restrictions. The app presents Terms, Privacy Policy and Disclaimer before wallet connection. The publicly indexed forum ToS is expressly limited to the forum, not lending activity. A current protocol ToS, governing-law clause and complete prohibited-jurisdiction schedule were not independently retrievable. Not verifiable as of September 4, 2026. KYC/AML. No KYC appears required for ordinary permissionless lending/borrowing.

KYC/AML is documented for Foundation grants, delegates/security-governance roles, and fiat-linked Card/Virtual Account products. This creates a material perimeter distinction: core DeFi access is permissionless, while ancillary services are compliance-gated. Classification. Moonwell is functionally a DeFi lending protocol; WELL is described as a governance token.

No regulator has publicly issued a definitive classification of Moonwell, WELL, or the lending activity in the sources reviewed. Not verifiable as of September 4, 2026. Warnings / enforcement / courts / sanctions. No SEC, DOJ, OFAC or court action specifically naming Moonwell Foundation or Moonwell was identified in the reviewed searches. This is not a legal clearance; comprehensive sanctions screening of all affiliates, directors and addresses was Not verifiable as of September 4, 2026. Data protection. The indexed privacy policy is dated February 8, 2022 and names legacy entity Lunar Enterprise Ventures Ltd.; current Foundation materials identify a different Cayman entity. It covers IP/device data, cookies, international transfers, retention and law-enforcement disclosures, but its applicability to the current app is unclear. Contradiction / actual risk. “Decentralized” architecture does not remove entity-attribution risk: the Foundation controls the interface, treasury, grants and emergency/security functions.

Cayman incorporation may limit or complicate claims, but does not prevent foreign regulators applying securities, lending, AML, sanctions or consumer-protection laws based on users, solicitation, token distribution or operational control. This is an analytical risk assessment, not a legal conclusion.

Active enforcement
No
Sanctioned
No
Entity
Moonwell Foundation
Jurisdiction
Cayman Islands
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Moonwell Foundation', 'Moonwell Lending'. OFAC SDN screening of 'Moonwell Foundation', 'Moonwell Lending': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Moonwell Foundation
  • Moonwell Lending
Sanctioned
No
Evidence (4)

Stability

stability

one source

Moonwell Lending does not appear to issue its own stablecoin; available evidence shows it supports external stable assets such as USDC, FRAX, EURC, sUSDS, USDS, and USDe in its markets, and a secondary source explicitly says Moonwell does not issue or custody stablecoins. The available web evidence does not verify a complete depeg history for the stablecoins used across Base, Moonbeam, and OP Mainnet, so the number of depeg events, the last depeg date, and the maximum depeg percentage are Not verifiable as of 2026-09-05.

Own stablecoin
No
Evidence (4)

Risks & Strengths

risks

one source

Moonwell’s principal risks are concentrated in oracle integrity, contract and governance changes, liquidation performance, and cross-chain dependencies. On-chain TVL, debt concentration, utilization, reserve balances, and chain-by-chain exposure are Not verifiable as of September 5, 2026 because Dune MCP was unavailable; no on-chain exposure percentages are inferred.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle mispricing or stalenessIncorrect collateral values can permit undercollateralized borrowing, trigger wrongful liquidations, or create bad debt. The risk is material because oracle configuration is market-specific and differs by chain.HighMediumChainlink feeds are documented for Base and OP Mainnet; API3 feeds are documented for Moonbeam. Governance-controlled parameters, audits, safety-module coverage, and emergency guardians provide additional controls.High residual risk remains from feed configuration, stale or unavailable data, thin-market pricing, and governance implementation errors.
Smart-contract exploitA bug in markets, rewards, liquidation, vault, or governance code could enable direct fund theft or insolvency.HighMediumListed mitigations include Halborn/Code4rena and other audits, a Code4rena bounty, monitoring, pausability, and a Safety Module.Audits and bounties reduce but do not eliminate unknown vulnerabilities, upgrade risk, or composability failures.
Governance or admin failureA malicious, rushed, or erroneous parameter/oracle change could expand borrowing capacity, misprice collateral, or impair withdrawals.HighMediumWELL-holder governance, proposal processes, timelocks, configurable guardians, and borrow-cap controls are documented.Voting concentration, voter apathy, compromised signers, and execution mistakes remain unquantified.
Liquidation cascadeSharp collateral declines, volatile rates, or insufficient liquidator capacity can produce slippage, bad debt, and supplier withdrawal impairment.HighHighCollateral factors, borrow caps, close factors, liquidation incentives, reserves, and isolated markets are used to constrain exposure and incentivize liquidations.Stress losses remain possible during correlated volatility, network congestion, oracle disruption, or thin liquidity.
Cross-chain dependency failureWormhole or other cross-chain governance/bridge components could delay, block, or misroute governance actions and WELL-related operations.HighMediumCross-chain governance uses message validation, additional temporal checks, 24-hour timelocks, pause controls, and dedicated audits.Bridge/guardian outages, message censorship, chain halts, and inconsistent chain state remain material residual risks.
Evidence (6)

strengths

two sources

Moonwell Lending’s top strengths are its multi-chain deployment, non-custodial design, transparent onchain governance, user-friendly borrowing/lending UX, and security-first posture. It is deployed across Base, Optimism, Moonbeam, and Moonriver, which broadens access and liquidity across ecosystems. The protocol’s documentation emphasizes that users keep control of their assets, with all operations visible onchain and protocol changes governed via onchain proposals.

Moonwell is also repeatedly described as intentionally simple to use for both beginners and advanced users, which supports adoption and repeat usage. Finally, its positioning as a security-focused lending protocol is reinforced by references to audited smart contracts and security reviews.

  • Multi-chain reach: supports lending across Base, OP Mainnet, Moonbeam, and Moonriver, expanding market access and liquidity options.
  • Non-custodial control: users retain custody of their assets; the protocol does not take control of deposits.
  • Onchain transparency and governance: protocol actions and upgrades are visible onchain, and governance is handled through onchain proposals.
  • Simple UX: Moonwell is presented as easy to navigate for novice and experienced users, lowering the barrier to DeFi lending.
  • Security emphasis: the protocol’s materials stress security as a core design principle, with mentions of audits and security partners.
Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 18 two independent sources, 26 one source, 7 unverified.
  • Oldest fact verification date: 2026-08-29.