Breaking
February 18, 2026

Claude Opus 4.6 blamed after $1.78M exploit hits Moonwell Hannah Collymore | usagoldmines.com

DeFi lending protocol Moonwell lost $1.78 million after an oracle pricing error in what is being described as one of the first major exploits directly linked to AI-generated Solidity code. Apparently, the error was caused by some code that was partially written by Anthropic’s Claude Opus 4.6 model.

Moonwell, a decentralized lending market operating on Base and Optimism, stated that it found a critical oracle configuration issue affecting its Coinbase Wrapped Ether (cbETH) Core Market on Base.

This caused cbETH to be valued at approximately $1.12 per token instead of its actual market price near $2,200, which is a 2,000x undervaluation that triggered instant liquidations.

Claude co-authored code set cbETH price at $1.12 instead of $2,200

The vulnerability appeared on February 15, just after Moonwell activated governance proposal MIP-X43, which integrated Chainlink’s Oracle Extractable Value (OEV) wrapper contracts across Base and Optimism markets.

As such, instead of calculating the cbETH price in USD by multiplying the cbETH/ETH exchange rate by the ETH/USD price feed, the deployed code obtained only the cbETH/ETH exchange rate and treated that ratio as if it were already denominated in dollars.

With cbETH trading at lower prices because of Moonwell’s oracle, liquidators could repay around $1 worth of debt and get collateral worth thousands in return.

Moonwell’s risk manager was able to reduce the cbETH borrow cap to 0.01 within hours of the vulnerability, effectively freezing new borrowing activity and containing further damage.

However, liquidations had already been processed, so users were left with catastrophic losses.

The protocol also estimated total losses at $1.78 million, mostly affecting cbETH, WETH, and USDC positions. Some borrowers nearly lost all their collateral as well, while others exploited the incorrect pricing to borrow even more money than they should have been allowed to, thus creating more debt within the protocol.

Bithumb suffered similar value assignment error just days earlier

The Moonwell incident is very similar to an error made at the South Korean exchange Bithumb just days earlier, on February 6, where a wrong-unit assignment created tens of billions of dollars in ghost value.

Apparently, a Bithumb staff member entered “BTC” instead of “KRW” while distributing rewards for a Random Box promotion, thus rewarding users in Bitcoin instead of Korean won.

The project lost approximately 620,000 Bitcoin worth over $40 billion (nearly 3% of Bitcoin’s entire global supply).

Vibe coding debate intensifies

The Moonwell incident has re-sparked the debate over vibe coding. Advocates argue that AI makes coding more accessible, while critics warn that its code may contain vulnerabilities that human reviews would most likely miss.

Smart contract auditor Pashov emphasized that “behind the AI is a person who checks the finished work, and possibly an auditor. For this reason, blaming the neural network alone is incorrect, although the incident ‘raises concerns’ about vibe coding.”

Anthropic’s Claude Opus 4.6 blamed for Moonwell's $1.78M loss in smart contract exploit.
Source: @pashov via X/Twitter.

Another blockchain security firm, SlowMist, shared its concerns about “oracle formula vulnerability” and the breakdown of human oversight that allowed the flawed code to reach production.

A study published just weeks before the Moonwell incident identified 69 vulnerabilities across 15 applications created using popular AI coding tools, including Cursor, Claude Code, Codes etc.

Even more interesting is that Anthropic’s own research from December 2025 revealed that Claude Opus 4.5 could exploit smart contract vulnerabilities worth $4.6 million by itself (in simulated environment). The research also established that premier AI models can now “independently identify vulnerabilities, create working exploit chains, and extract value with minimal human oversight.”

Nonetheless, Moonwell clarified that “no other markets on Base or OP Mainnet were affected. The issue is isolated to the cbETH Core Market on Base.”

The protocol also noted that this was not its first oracle incident, recalling a misreporting incident in November 2025.

The smartest crypto minds already read our newsletter. Want in? Join them.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.