Moonwell Exploit: AI-Coded $1.78M Oracle Flaw

AI-authored oracle bug causes $1.78M DeFi loss at Moonwell

  • Moonwell, a DeFi protocol, lost roughly $1.78 million due to a misconfigured price oracle for cbETH.
  • A governance proposal set the wrong exchange rate, causing the oracle to report cbETH at about $1.12 instead of its actual value near $2,200.
  • Multiple commits in the vulnerable code were co-authored by Anthropic’s Claude Opus 4.6, spotlighting risks in AI-assisted development.
  • The incident highlights the critical need for rigorous validation, even for code that has undergone audits and testing.

A governance failure at the Moonwell DeFi lending protocol enabled exploiters to extract approximately $1.78 million in bad debt this week. Attackers exploited a severe mispricing of Coinbase Wrapped Staked ETH (cbETH) after a faulty oracle reported its value at $1.12 instead of $2,200.

- Advertisement -

The team said the error stemmed from a Sunday governance action that misconfigured the cbETH price feed. Consequently, liquidation bots and opportunistic borrowers quickly capitalized on the pricing discrepancy for profit.

Security auditor Pashov publicly flagged that the pull requests for the affected contracts showed multiple commits co-authored by AI. He later cautioned, however, against treating the flaw as uniquely AI-driven, stating it was a mistake even a senior developer could make.

The real issue, according to Pashov, was insufficient rigorous checks and end-to-end validation. He argued the mispricing could have been caught with a proper integration test that interacted with the blockchain. Meanwhile, the protocol noted it had commissioned an audit from Halborn and conducted unit tests, which failed to prevent the incident.

Fraser Edwards, CEO of cheqd, told Cointelegraph that AI-assisted development requires strict governance. He argued all AI-generated smart contract code should be treated as untrusted input within a disciplined engineering process.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Trump-Linked WLFI Token Jumps Amid Whale Squeeze, Heat

The WLFI token surged over 22% in 24 hours but remains down significantly from...

Bitcoin Divergence Signals Deflation Risk: Hayes

Bitcoin's divergence from the Nasdaq 100 may signal an imminent deflationary credit event driven...

Claude AI’s Vibe-Coded Bug Liquidates $1.8M in Moonwell DeFi

On Sunday, an Moonwell oracle error introduced in a pull request co-authored by Claude...

Three Intelligent Workflows to Automate Security & IT Tasks

Security and IT teams are shifting focus from standalone tools to intelligent workflows that...

California Sets July 2026 Crypto License Deadline

California has set a July 1, 2026 deadline for crypto firms to either obtain...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!