Moonwell hacked for $1.78M due to AI-generated code
An error in the oracle pricing formula mispriced cbETH and allowed an attacker to drain funds from the protocol.
18.02.2026 - 09:05
408
2 min
0
Key points:
- Moonwell lost approximately $1.78 million due to a smart contract bug.
- cbETH was priced at $1.12 instead of around $2,200.
- According to the auditor, the vulnerable code was generated by Claude Opus 4.6.
Moonwell, a DeFi lending protocol, suffered an exploit caused by a flaw in its price calculation logic. Total losses amounted to roughly $1.78 million.
Security auditor pashov reported that the issue stemmed from the oracle formula: the smart contract treated the price of cbETH as $1.12 instead of its actual market value of around $2,200. This pricing discrepancy enabled the attacker to manipulate collateral calculations and withdraw assets from the protocol.
Code involvement of Claude
In the project’s repository, code changes were marked as co-authored by Claude. According to the auditor, the critical vulnerability was located in a code fragment generated by the Claude Opus 4.6 model.
The incident is already being described as one of the first known exploits involving a smart contract written with the assistance of generative AI in Solidity.
According to TRM Labs, AI-enabled fraud schemes increased by approximately 500% year over year in 2025. Generative models have made it easier for malicious actors to scale scam campaigns and automate communication with victims.
In 2025, nearly 150 attacks resulted in $2.87 billion in stolen funds. More than half of that amount — $1.46 billion — was linked to a single incident involving the hack of Bybit.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter