Moonwell loses $1.78M after AI code misprices cbETH

Moonwell lost $1.78M after AI-generated code mispriced cbETH, enabling attackers to exploit the protocol. The incident raises concerns about AI use in DeFi security.

Moonwell, a decentralized finance (DeFi) lending protocol, suffered a $1.78 million exploit due to a vulnerability in its smart contract code. The code was generated by the AI model Claude Opus 4.6, which introduced an incorrect formula in the price oracle configuration. This error caused Coinbase-wrapped ETH (cbETH) to be valued at just $1.12, far below its actual market price of around $2,200. Attackers exploited this mispricing to manipulate collateral calculations, allowing them to borrow against underpriced assets and drain funds from the protocol. The exploit followed the activation of a new proposal and the integration of Chainlink OEV contracts. The incident has sparked debate about the security of AI-generated Solidity code and highlighted the crucial role of accurate price oracles in DeFi. Security auditors confirmed the vulnerable code was co-authored by Claude, marking a significant exploit involving generative AI in smart contract development.

Related Tokens

Related News