AI-Generated Code Error Causes $1.78M Loss in DeFi Protocol Moonwell

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

The Moonwell DeFi protocol suffered a $1.78 million loss after an AI system, Claude Opus 4.6, co-authored faulty code for a price oracle. The misconfiguration led to cbETH being drastically undervalued, triggering mass liquidations and significant financial harm to users and the protocol.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system explicitly mentioned as co-authoring the smart contract code that contained a critical bug leading to a significant financial loss. The harm (financial loss) has already occurred, and the AI's involvement in the development process is a contributing factor to the vulnerability. Although the flaw could have been made by a human developer, the AI-assisted coding played a role in the incident. Therefore, this qualifies as an AI Incident due to the realized harm caused by the AI system's involvement in the development and deployment of the vulnerable contract.[AI generated]
AI principles
Robustness & digital securityAccountability

Industries
Financial and insurance services

Affected stakeholders
ConsumersBusiness

Harm types
Economic/Property

Severity
AI incident

Business function:
Research and development

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

$1.78M 'Vibe-Coded' Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny

2026-02-18
Cointelegraph
Why's our monitor labelling this an incident or hazard?
The event involves an AI system explicitly mentioned as co-authoring the smart contract code that contained a critical bug leading to a significant financial loss. The harm (financial loss) has already occurred, and the AI's involvement in the development process is a contributing factor to the vulnerability. Although the flaw could have been made by a human developer, the AI-assisted coding played a role in the incident. Therefore, this qualifies as an AI Incident due to the realized harm caused by the AI system's involvement in the development and deployment of the vulnerable contract.
Thumbnail Image

Ether briefly priced at $1 after glitch on DeFi app, triggering $1.8M in bad debt

2026-02-18
CoinDesk
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (an AI coding assistant) contributing to the development of the oracle software that malfunctioned, causing a critical pricing error. This error directly led to significant financial harm (bad debt and collateral loss) within the DeFi platform. The AI's role is indirect but pivotal in the chain of events leading to harm. The harm is material and realized, meeting the criteria for an AI Incident. The event is not merely a potential risk or a governance update, but a concrete incident with financial damage caused by AI-influenced software malfunction.
Thumbnail Image

Oracle Error Leaves DeFi Lender Moonwell With $1.8 Million Hole

2026-02-18
cryptonews.com
Why's our monitor labelling this an incident or hazard?
An AI system (the oracle pricing mechanism, with code possibly generated by AI tools) was involved in the malfunction that directly led to significant financial harm (bad debt and collateral loss) for users of the DeFi platform. The incident stems from the AI system's malfunction (misconfiguration and flawed code) causing incorrect price feeds, triggering liquidations and financial losses. This fits the definition of an AI Incident because the AI system's malfunction directly led to harm (financial loss) to a group of people (borrowers and the protocol).
Thumbnail Image

AI-Induced Slip Costs DeFi Millions - Latest cryptocurrency news

2026-02-18
BH NEWS
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI system (Claude Opus 4.6) generating faulty code that caused a pricing oracle error in the Moonwell protocol, leading to a large financial loss. This is a direct harm caused by the AI system's malfunction during its use in software development. The financial loss constitutes harm to property and communities, fulfilling the criteria for an AI Incident. Therefore, this event is classified as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Oracle Error Leaves DeFi Lender Moonwell With $1.8 Million in Bad Debt - Decrypt

2026-02-18
Decrypt
Why's our monitor labelling this an incident or hazard?
The oracle is an AI system component that provides real-time price data used for decision-making in the DeFi lending platform. The misconfiguration and malfunction of this AI system directly led to a major pricing error, triggering liquidations and financial losses totaling approximately $1.78 million. This constitutes harm to property and financial interests, fulfilling the criteria for an AI Incident. The event involves the AI system's malfunction causing direct harm, not just a potential risk, and thus is not merely a hazard or complementary information.
Thumbnail Image

Vibe Coding via Claude Opus Leads to Moonwell DeFi Project Breach | ForkLog

2026-02-18
ForkLog
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Claude Opus 4.6) used in the development of smart contract code (vibe coding). The flawed code produced by this AI-assisted development led to an oracle misconfiguration, which was exploited causing a $1.78 million loss and harm to users' collateral and debts. The harm is direct and material, fulfilling the criteria for an AI Incident. Although human oversight was involved, the AI's role in generating vulnerable code was pivotal. The incident also highlights risks associated with AI-assisted programming in critical financial infrastructure.
Thumbnail Image

Moonwell Exploited for $1.78 Million After cbETH Oracle Mispricing - FinanceFeeds

2026-02-18
FinanceFeeds
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Anthropic's Claude) used in the development of smart contract code that caused a critical oracle mispricing error. This error directly led to a financial loss of $1.78 million due to exploitation of the mispriced asset. The harm is materialized and directly linked to the AI-assisted code development process. Although human oversight and governance failures also contributed, the AI's role in generating the flawed code is pivotal. Hence, the event meets the criteria for an AI Incident as it involves realized harm caused directly or indirectly by the AI system's involvement.
Thumbnail Image

Anthropic's Claude Opus 4.6 blamed for Moonwell's $1.78M loss in smart contract exploit - Cryptopolitan

2026-02-18
Cryptopolitan
Why's our monitor labelling this an incident or hazard?
The incident involves an AI system (Anthropic's Claude Opus 4.6) used in the development of smart contract code that contained a critical vulnerability. The flawed AI-generated code directly caused a significant financial loss ($1.78 million) due to incorrect asset pricing and subsequent liquidations. This harm to property and financial assets is a direct consequence of the AI system's malfunction or misuse in code generation. Therefore, this event meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Moonwell suffered approximately $1.78 million in losses due to a misconfiguration of a price oracle. - Lookonchain - Looking for smartmoney onchain

2026-02-18
Lookonchain
Why's our monitor labelling this an incident or hazard?
The price oracle, which is an AI system component providing real-time price data, was misconfigured, leading to incorrect price information that directly caused financial harm to users and the protocol. The event involves the use and malfunction of an AI system component resulting in realized harm (losses of approximately $1.78 million). Therefore, this qualifies as an AI Incident due to direct harm caused by the AI system's malfunction.
Thumbnail Image

DeFi, meet Claude: Moonwell's 'vibe-coded' oracle in $1.8M blowup

2026-02-18
Protos
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Claude Opus 4.6) contributing to the development of a smart contract oracle that malfunctioned due to misconfiguration, causing direct financial harm to users and the protocol. The harm includes liquidation of user collateral and significant bad debt, which fits the definition of injury or harm to groups of people (financial harm) and harm to property (digital assets). The AI system's role in the development and the resulting malfunction leading to realized harm justifies classification as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

AI-Generated Code Blunder Sparks Multi-Million Dollar DeFi Breach

2026-02-18
COINTURK NEWS
Why's our monitor labelling this an incident or hazard?
The article explicitly states that the AI system (Claude Opus 4.6) co-authored the faulty code that caused the vulnerability exploited in the breach. This directly links the AI system's development role to the realized harm (financial loss) in the DeFi protocol. The harm is materialized and significant, involving millions of dollars lost due to the AI-generated error. Therefore, this qualifies as an AI Incident because the AI system's development and use directly led to harm (financial loss) in a critical financial infrastructure context.
Thumbnail Image

DeFi lending protocol Moonwell hit with $1.8 million bad debt after oracle misconfiguration

2026-02-18
The Block
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (AI-assisted code in smart contract development) whose malfunction (oracle misconfiguration) directly led to significant financial harm (bad debt and liquidations) in a decentralized finance protocol. The harm is realized and material, meeting the criteria for an AI Incident. Although the root cause is a configuration error, the AI-assisted nature of the code is relevant and pivotal in the incident. The incident is not merely a potential risk or a governance update but a concrete event with direct harm caused by AI system involvement.
Thumbnail Image

Moonwell Suffers $1.8M Loss After Oracle Glitch, With Claude Opus 4.6 Cited in Faulty Output - Crypto Economy

2026-02-18
Crypto Economy
Why's our monitor labelling this an incident or hazard?
An AI system (Claude Opus 4.6) was involved in the development of the faulty oracle configuration code that directly caused a mispricing error. This error led to significant financial harm (bad debt and user losses) in the DeFi protocol. The AI system's involvement in the development and the resulting malfunction that caused realized harm meets the definition of an AI Incident. The event is not merely a potential risk or a governance update but a concrete incident with direct financial harm linked to AI-assisted code.
Thumbnail Image

Moonwell: Recovery Plan Submitted to Governance Forum and Partial Compensation Initiated - Lookonchain - Looking for smartmoney onchain

2026-02-19
Lookonchain
Why's our monitor labelling this an incident or hazard?
An oracle configuration error in a DeFi protocol involves AI or algorithmic systems that provide data inputs to smart contracts. The error caused a significant financial loss (bad debt) to users, which constitutes harm to property. The event involves the malfunction of an AI-related system leading directly to harm, qualifying it as an AI Incident. The update about the recovery plan and compensation is part of the incident's response but does not change the classification.
Thumbnail Image

$1.8M Gone in Minutes: Moonwell's Oracle Glitch Shakes DeFi Lending

2026-02-19
DailyCoin
Why's our monitor labelling this an incident or hazard?
The event involves an AI system or AI-assisted components (automated liquidators, bots, and possibly AI-assisted code development) whose malfunction or misconfiguration led to a significant financial loss ($1.8 million) in a DeFi lending protocol. The harm is realized and directly linked to the AI system's outputs (incorrect pricing and automated liquidations). Although AI involvement in the code development is speculative, the automated bots reacting to the faulty oracle data are AI systems contributing to the harm. This meets the criteria for an AI Incident as the AI system's malfunction has directly led to harm (financial loss).