An error in the oracle pricing formula mispriced cbETH and allowed an attacker to drain funds from the protocol.

Moonwell hacked for $1.78M due to AI-generated code

18.02.2026 - 09:05

408

2 min

Key points:

  • Moonwell lost approximately $1.78 million due to a smart contract bug.
  • cbETH was priced at $1.12 instead of around $2,200.
  • According to the auditor, the vulnerable code was generated by Claude Opus 4.6.

Moonwell, a DeFi lending protocol, suffered an exploit caused by a flaw in its price calculation logic. Total losses amounted to roughly $1.78 million.

Security auditor pashov reported that the issue stemmed from the oracle formula: the smart contract treated the price of cbETH as $1.12 instead of its actual market value of around $2,200. This pricing discrepancy enabled the attacker to manipulate collateral calculations and withdraw assets from the protocol.

Source: X.com

Code involvement of Claude

In the project’s repository, code changes were marked as co-authored by Claude. According to the auditor, the critical vulnerability was located in a code fragment generated by the Claude Opus 4.6 model.

The incident is already being described as one of the first known exploits involving a smart contract written with the assistance of generative AI in Solidity.

According to TRM Labs, AI-enabled fraud schemes increased by approximately 500% year over year in 2025. Generative models have made it easier for malicious actors to scale scam campaigns and automate communication with victims.

In 2025, nearly 150 attacks resulted in $2.87 billion in stolen funds. More than half of that amount — $1.46 billion — was linked to a single incident involving the hack of Bybit.

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy