1 article on this topic.
An attacker pumped an illiquid collateral token and borrowed against the inflated price — no smart contract bug required. It's Moonwell's fourth loss event in under a year.