<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Moonhacker_Moonwell_Vault_Unprotected_ExecuteOperation_Call</id>
	<title>Moonhacker Moonwell Vault Unprotected ExecuteOperation Call - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Moonhacker_Moonwell_Vault_Unprotected_ExecuteOperation_Call"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Moonhacker_Moonwell_Vault_Unprotected_ExecuteOperation_Call&amp;action=history"/>
	<updated>2026-07-26T08:14:43Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Moonhacker_Moonwell_Vault_Unprotected_ExecuteOperation_Call&amp;diff=6498&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/moonhackermoonwellvaultunprotectedexecuteoperationcall.php}} {{Unattributed Sources}}  Moonwell Logo/HomepageMoonwell is a decentralized lending platform that allows users to lend or borrow digital assets with flexible repayment schedules and no additional fees. It prioritizes security through audits by Halborn Security and a bug bounty program with rewards up...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Moonhacker_Moonwell_Vault_Unprotected_ExecuteOperation_Call&amp;diff=6498&amp;oldid=prev"/>
		<updated>2025-01-30T22:11:16Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/moonhackermoonwellvaultunprotectedexecuteoperationcall.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Moonwell.jpg&quot; title=&quot;File:Moonwell.jpg&quot;&gt;thumb|Moonwell Logo/Homepage&lt;/a&gt;Moonwell is a decentralized lending platform that allows users to lend or borrow digital assets with flexible repayment schedules and no additional fees. It prioritizes security through audits by Halborn Security and a bug bounty program with rewards up...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/moonhackermoonwellvaultunprotectedexecuteoperationcall.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Moonwell.jpg|thumb|Moonwell Logo/Homepage]]Moonwell is a decentralized lending platform that allows users to lend or borrow digital assets with flexible repayment schedules and no additional fees. It prioritizes security through audits by Halborn Security and a bug bounty program with rewards up to $250,000. The platform operates across multiple networks like Base, Moonbeam, and Optimism, offering markets for USDC, Ethereum, and Staked Ethereum with competitive APY. Moonwell emphasizes community governance and has a total market size of nearly $791 million. A recent exploit targeted the MoonHacker vault, interacting with Moonwell, where a vulnerability in the executeOperation function allowed an attacker to manipulate token approvals and steal $320,000 USDC. The creator of the MoonHacker vault does not appear to have responded to the situation.&amp;lt;ref name=&amp;quot;optimistic-17722&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;optimistic-17723&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;nicklfranklintweetmoonhacker-17724&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;nicklfranklinsitemoonhacker-17725&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cyversalertstwitter-17726&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;lukeyoungbloodtwitter-17727&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;Moonhacker Vault Contract-17728&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;Moonhacker Vault Contract Creation-17729&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;binance-17730&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;chaincatcher-17731&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;panewslab-17732&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-17733&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;DefiHackLabs Proof Of Concept-17734&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-17735&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-17736&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-17737&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot; -17738&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-17739&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-17740&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Moonwell DeFi ==&lt;br /&gt;
Moonwell is a decentralized lending platform that enables users to lend or borrow digital assets without monthly payments or additional fees, allowing for flexible repayment schedules. It prioritizes security by conducting thorough audits through Halborn Security and offering a bug bounty program with rewards up to $250,000. The platform operates across multiple networks, including Base, Moonbeam, and Optimism, with a variety of available markets such as USDC, Ethereum, and Staked Ethereum, offering competitive annual percentage yields (APY). Moonwell also emphasizes community governance, empowering members to make decisions and adapt to changing market conditions. The platform currently has a total market size of nearly $791 million, with a significant portion supplied by its users.&lt;br /&gt;
== About Moonhacker Vault Contract ==&lt;br /&gt;
The moonhacker vault was created on December 17th, 2025. It interacts with, but otherwise has no direct relation to the Moonwell DeFi protocol.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;The Moonhacker contract suffered a flash loan attack, resulting in a loss of approximately $320,000.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Moonhacker Moonwell Vault Unprotected ExecuteOperation Call&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|December 17th, 2024 4:07:47 PM MST&lt;br /&gt;
|Moonhacker Vault Contract Created&lt;br /&gt;
|The vulnerable Moonhacker vault contract is launched on the Optimism blockchain.&lt;br /&gt;
|-&lt;br /&gt;
|December 23rd, 2024 3:34:39 PM MST&lt;br /&gt;
|Optimism Blockchain Transaction&lt;br /&gt;
|The malicious transaction on the Optimism blockchain.&lt;br /&gt;
|-&lt;br /&gt;
|December 23rd, 2024 5:08:00 PM MST&lt;br /&gt;
|CertiK Initial Report Posted&lt;br /&gt;
|CertiK post an initial analysis of the exploit on Twitter/X.&lt;br /&gt;
|-&lt;br /&gt;
|December 24th, 2024 12:33:00 AM MST&lt;br /&gt;
|SJ_cryptosight Withdrawal Notice&lt;br /&gt;
|SJ_cryptosight publishes that they are withdrawing their funds until there's an official update.&lt;br /&gt;
|-&lt;br /&gt;
|December 24th, 2024 9:02:00 AM MST&lt;br /&gt;
|LukeYoungBlood Posts Update&lt;br /&gt;
|LukeYoungBlood (LukeYoungblood.eth) provides a detailed explanation regarding the MoonHacker vault exploit, clarifying that the attack did not affect the Moonwell protocol. The MoonHacker vault, which was integrated with Moonwell on the Optimism network, suffered from two key vulnerabilities: a lack of protection on the &amp;quot;executeOperation&amp;quot; function and insufficient validation of input addresses. The attacker exploited these flaws by using a flash loan to drain USDC from the vault by manipulating the function to approve their own wallet instead of the intended mUSDC contract. Although some security monitoring services mistakenly linked the exploit to Moonwell, Luke emphasized that the Moonwell protocol was not involved, as the exploit targeted only the vulnerable vault. The incident underscored the importance of code audits in preventing such attacks and highlighted the sophisticated nature of on-chain exploits.&lt;br /&gt;
|-&lt;br /&gt;
|December 24th, 2024 4:38:00 PM MST&lt;br /&gt;
|Nick L Franklin Posts Analysis&lt;br /&gt;
|Nick L Franklin posts an update with an analysis of the exploit. &amp;quot;There're several Moonhacker contracts that can be used for smart supply and borrow. In &amp;quot;executeOperation&amp;quot; function, input data is not checked, hacker was able to input his own contract&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|December 24th, 2024 7:15:00 PM MST&lt;br /&gt;
|CertiK Reports Unrelated&lt;br /&gt;
|CertiK posts a tweet reporting that the exploit has no relation to the MoonWell protocol itself.&lt;br /&gt;
|-&lt;br /&gt;
|December 25th, 2024 11:10:51 PM MST&lt;br /&gt;
|Shashank Posts Analysis&lt;br /&gt;
|Shashank posts an analysis of the smart contract exploit.&lt;br /&gt;
|-&lt;br /&gt;
|January 2nd, 2025 8:21:00 AM MST&lt;br /&gt;
|Debaub Analysis Published&lt;br /&gt;
|Debaub publishes an analysis of the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|January 24th, 2025 1:55:53 AM MST&lt;br /&gt;
|Verichains Exploit Analysis&lt;br /&gt;
|Verichains publishes an analysis of the exploit online.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
The attack targeted the MoonHacker vault contracts interacting with the Moonwell DeFi protocol on the Optimism network, exploiting improper input validation in the executeOperation function. This vulnerability allowed the attacker to pass a malicious contract as the mToken address, gaining unauthorized token approvals and manipulating the contract logic. The attacker deployed two contracts, exploited the vulnerability, and withdrew the stolen funds. To mitigate such risks in the future, the blog recommends implementing proper input validation, access control, and function modifiers. The incident highlights the importance of comprehensive audits and validation checks in smart contract security to protect user funds in the DeFi ecosystem.&lt;br /&gt;
&lt;br /&gt;
&amp;quot;First, the attacker took out a flash loan of USDC on Aave, because they needed more USDC to call repayBorrow and redeem (withdraw) many times to drain the vault.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Next, they called the vulnerable executeOperation function on the Moonhacker vault, but instead of specifying the mUSDC contract, they specified their own wallet as the approval address.&lt;br /&gt;
&lt;br /&gt;
This allowed them to steal all the mUSDC collateral tokens held by the vault.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Then they simply called repayBorrow and redeem (withdraw) multiple times to withdraw all of the underlying USDC that was previously held by the Moonhacker vault.&lt;br /&gt;
&lt;br /&gt;
Finally, they repaid the flash loan to Aave and took all the USDC profit they had stolen from Moonhacker.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $320,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Compound fork lending project – Moonwell was hacked because of improper input check.&lt;br /&gt;
&lt;br /&gt;
There’re several Moonhacker contracts that can be used for smart supply and borrow. In “executeOperation” function, input data is not checked, hacker was able to input his own contract as mToken contract as there’s no check.&lt;br /&gt;
&lt;br /&gt;
If he provide his contract as mToken, Moonhacker contract approves his tokens to that contract.&lt;br /&gt;
&lt;br /&gt;
Then, he could move all tokens to his contract. Total loss is about $320k.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;As a precautionary measure, I withdrew my funds in the @MoonwellDeFi Flagship USDC vault curated by Morpho until an official report is out. If you have funds in the pool on Optimium, withdraw them as soon as possible.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
Lukeyoungblood offered to help out the affected smart contract. &amp;quot;If the team or individual behind Moonhacker would like to reach out and get help from Moonwell contributors or teams like Seal 911 who can potentially try to help them recover the USDC stolen from their vault, please DM me on Telegram&amp;quot;. It is unclear that any effort was undertaken to track or recover the funds.&lt;br /&gt;
&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;optimistic-17722&amp;quot;&amp;gt;[https://optimistic.etherscan.io/tx/0xd12016b25d7aef681ade3dc3c9d1a1cc12f35b2c99953ff0e0ee23a59454c4fe OP Mainnet Transaction Hash (Txhash) Details | OP Mainnet Etherscan] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;optimistic-17723&amp;quot;&amp;gt;[https://optimistic.etherscan.io/tx/0xd12016b25d7aef681ade3dc3c9d1a1cc12f35b2c99953ff0e0ee23a59454c4fe#eventlog OP Mainnet Transaction Hash (Txhash) Details | OP Mainnet Etherscan] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;nicklfranklintweetmoonhacker-17724&amp;quot;&amp;gt;[https://twitter.com/0xNickLFranklin/status/1871702134301098483 0xNickLFranklin - &amp;quot;There're several Moonhacker contracts that can be used for smart supply and borrow. In &amp;quot;executeOperation&amp;quot; function, input data is not checked, hacker was able to input his own contract&amp;quot; - Twitter] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;nicklfranklinsitemoonhacker-17725&amp;quot;&amp;gt;[https://nickfranklin.site/2024/12/24/moonwell-hacked/ Moonwell hacked. – Defi hack analysis] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cyversalertstwitter-17726&amp;quot;&amp;gt;[https://twitter.com/CyversAlerts/status/1871440613578510736 @CyversAlerts Twitter] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;lukeyoungbloodtwitter-17727&amp;quot;&amp;gt;[https://twitter.com/LukeYoungblood/status/1871587295520002520 @LukeYoungblood Twitter] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;Moonhacker Vault Contract-17728&amp;quot;&amp;gt;[https://optimistic.etherscan.io/address/0xd9b45e2c389b6ad55dd3631abc1de6f2d2229847 MoonHacker | Address 0xd9b45e2c389b6ad55dd3631abc1de6f2d2229847 | OP Mainnet Etherscan] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;Moonhacker Vault Contract Creation-17729&amp;quot;&amp;gt;[https://optimistic.etherscan.io/tx/0xacc02fff0540e69ed8cfa98575ccf16369ba71b6480dd5b902d14b648be5e54b OP Mainnet Transaction Hash (Txhash) Details | OP Mainnet Etherscan] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;binance-17730&amp;quot;&amp;gt;[https://www.binance.com/en/square/post/12-24-2024-moonhacker-contract-suffers-flash-loan-attack-incurring-320-000-loss-17975611563473 https://www.binance.com/en/square/post/12-24-2024-moonhacker-contract-suffers-flash-loan-attack-incurring-320-000-loss-17975611563473] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;chaincatcher-17731&amp;quot;&amp;gt;[https://www.chaincatcher.com/en/article/2158886 Moonhacker contract suffered a flash loan attack, resulting in a loss of approximately $320,000 - ChainCatcher] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;panewslab-17732&amp;quot;&amp;gt;[https://www.panewslab.com/en/articledetails/4wovaiq9.html Moonhacker contract was attacked by flash loan, losing about $320,000 - PANews] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-17733&amp;quot;&amp;gt;[https://twitter.com/CertiKAlert/status/1871741504534053270 &amp;quot;The stolen funds on MoonHacker only trace to several 'SmartSupply()' call days ago while the Moonwell lending pools are not affected. The &amp;quot;MoonHacker&amp;quot; deployers have no known connection to Moonwell.&amp;quot;] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;DefiHackLabs Proof Of Concept-17734&amp;quot;&amp;gt;[https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2024-12/Moonhacker_exp.sol DeFiHackLabs/src/test/2024-12/Moonhacker_exp.sol at main · SunWeb3Sec/DeFiHackLabs · GitHub] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-17735&amp;quot;&amp;gt;[https://twitter.com/dedaub/status/1874838342485102852 Debaub - &amp;quot;The attacker abused an Unchecked FlashLoan Callback &amp;amp; an Unrestricted Approve Proxy.&amp;quot; - Twitter] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-17736&amp;quot;&amp;gt;[https://twitter.com/CertiKAlert/status/1871347300918030409 Original CertiK Post] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-17737&amp;quot;&amp;gt;[https://blog.verichains.io/p/moonhacker-vault-hack-analysis MoonHacker Vault Hack Analysis - Verichains] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot; -17738&amp;quot;&amp;gt;[https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6 MoonHacker Vault Hack Analysis - Shashank] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-17739&amp;quot;&amp;gt;[https://twitter.com/SJ_cryptosight/status/1871459282623074698 SJ_cryptosight - &amp;quot;As a precautionary measure, I withdrew my funds in the @MoonwellDeFi Flagship USDC vault curated by Morpho until an official report is out. If you have funds in the pool on Optimium, withdraw them as soon as possible.&amp;quot; - Twitter] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-17740&amp;quot;&amp;gt;[https://twitter.com/LukeYoungblood/status/1871587301585002841 Lukeyoungblood - &amp;quot;If the team or individual behind Moonhacker would like to reach out and get help from Moonwell contributors or teams like Seal 911 who can potentially try to help them recover the USDC stolen from their vault, please DM me on Tel...itter] (Accessed Jan 30, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>