Cointime

Download App
iOS & Android

CertiK Report: Revisiting the Mango Market Incident Anaylsis

Validated Project

TL;DR

On October 11, 2022 at 6:19 PM EST, Mango Market was attacked, causing a loss of $116M. The attacker was able to manipulate the price of MNGO token and borrowed more assets on the platform than was permitted.

Introduction

Mango Market is built on the Solana blockchain and utilizes Serum DEX for spot margin trading while perpetual futures are traded on Mango Market’s own order book. Mango Market is governed by $MNGO token holders via the Mango DAO.

On October 11, 2022 at 10:19 PM UTC, Mango Markets was hacked by a group of attackers, including Avraham Eisenberg who claimed to be part of the group on Twitter. A loss of $116M occurred after manipulating the value of a posted collateral to higher prices, and then taking out significant loans against the inflated collateral, which ended up draining Mango’s treasury. The attacker began by funding the first account (CQvKSNnY…) with 5M USDC and then offered 483mm units of MNGO perps on the order book. Then the attacker funded the second account (4ND8FVPjU…) which was used to buy the 483mm units of MNFO perps at a price of $0.0382 per unit. As a result, the attacker was able to move the price of MNGO which they increased to $0.91. With this price set for MNGO/USD, the second account was able to borrow other tokens on Mango Market. The attacker subsequently took all available liquidity on Mango, leaving account A with approximately $11,537,729.05 borrowed tokens and account B with 500M uncollectible debt. The price of $MNGO has dropped 47% as a result of the incident.

On October 15, 2022 Eisenberg posted on Twitter that this was a “highly profitable trading strategy” and that it was “legal open market actions, using the protocol as designed.” In his tweet, he claims that the development team failed to anticipate the consequences of the protocol’s parameters.

Funds Returned

The attacker submitted a proposal to send the token back. The wallet receiving funds drained from the protocol offered via a DAO community vote to return a portion of the proceeds less a substantial bounty, if the community promised not to pursue legal action.

On October 15, 2022 Mango’s developers tweeted that they were in the process of getting back $67 million in various cryptoassets and that the team started working on an algorithm to decide on a refund split. Overall, after a proposal in the Mango’s governance forum was approved, Eisenberg was allowed to keep $47 million as a “bug bounty” while $67 million was sent back to the treasury.

Eisenberg was initially linked to the wallet address that carried out the attack via an ENS domain name ponzishorter.eth. An anonymous Discord chat log also showed Eisenberg discussing the precise mechanism of the exploit in advance.

Attack Flow

  1. The attacker funded the first account (Account A) CQvKSNnYtPTZfQRQ5jkHq8q2swJyRsdQLcFcj3EmKFfX with 5M USDC in this transaction.
  1. The attacker then offered out 483M units of MNGO perps (short) on the order book
  1. The attacker funded the second account (Account B) 4ND8FVPjUGGjx9VuGFuJefDWpg3THb58c277hbVRnjNa
  1. Then the second account was used to buy 483M units of MNGO perps (long), at a price of $0.0382 per unit.
  2. The attacker started to move the spot price of MNGO, and increased it to $0.91
  1. With MNGO/USD price of $0.91 per unit, account B was able to borrow other tokens on Mango Market. The attacker also used the funds in account B (the original deposit + the funds for selling borrowed MNGO) to borrow other tokens on Mango Market.
  2. The above borrow behaviors leave account A with a total value of $11,306,771.61 uncollectible debt and account B with -$115,182,674.43 bad debt.

Addresses

Two accounts were used to conduct the attack.

Account “A” received 5M USDC collateral which offered out 483mm units of MNGO perps: CQvKSNnYtPTZfQRQ5jkHq8q2swJyRsdQLcFcj3EmKFfX

Account “B,” the trader, used another 5 million USDC to buy the same amount of MNGO, using 10 million USDC in total to effectively hedge his position: 4ND8FVPjUGGjx9VuGFuJefDWpg3THb58c277hbVRnjNa

Profit and Assets Tracing

Solana.FM🔮🔎 SolanaFM SolanaFM

Account A: 

Account B: 

Conclusion

Overall, the attackers executed a self-funded economic attack by manipulating the oracle price of MNGO. Since the attack, a debate has been sparked on Twitter as to whether those responsible could be subject to civil or even criminal liability. So far, there are few precedents for prosecuting this type of DeFi market manipulation. This case has some similarities to the Indexed Finance exploit that took place in December 2021. The founders of the protocol identified the attacker, and a lawsuit is still pending in Canadian courts. Following these events, Mango Markets has announced a new version dubbed 'v4' which will use the Serum Community Fork. Despite serious setback, the project appears hopeful in securing a place in the future of web3.

Comments

All Comments

Recommended for you

  • Xi Jinping: Make 2026 a Historic Year for China-U.S. Relations

    Beijing, May 14 — On the morning of May 14, Chinese President Xi Jinping held talks with U.S. President Donald Trump, who is on a state visit to China, at the Great Hall of the People in Beijing. Xi emphasized that the common interests between China and the United States outweigh their differences, that the success of each country is an opportunity for the other, and that stable China-U.S. relations are beneficial to the world. The two sides should be partners, not adversaries, achieving mutual success and common prosperity, and forging a new path for major countries to coexist correctly in the new era. "I look forward to exchanging views with President Trump on major issues concerning both countries and the world, jointly steering and navigating the great ship of China-U.S. relations, and making 2026 a historic and landmark year for China-U.S. relations to build on past achievements and usher in a new future," Xi said. (Xinhua News Agency)

  • US Spot Ethereum ETF Sees Net Outflow of $36.25 Million Yesterday

    On May 14, according to monitoring by Trader T, the US spot Ethereum ETF experienced a net outflow of $36.25 million yesterday.

  • US Spot Bitcoin ETF Sees Net Outflow of $630.38 Million Yesterday

    On May 14, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net outflow of $630.38 million yesterday.

  • Xi Jinping Welcomes Trump to China

    On May 14, Chinese President Xi Jinping held a ceremony at the East Plaza of the Great Hall of the People in Beijing to welcome U.S. President Donald Trump on his visit to China. President Trump had arrived at the welcome ceremony site by car. (CCTV News)

  • U.S. Senate Confirms Kevin Walsh as Federal Reserve Chair

    On May 14, the U.S. Senate confirmed Walsh as the Chair of the Federal Reserve with a vote of 54 to 45. The Senate had previously approved Walsh as a Federal Reserve Governor for a 14-year term on the 12th. Following the approval of his chairmanship on the 13th, Walsh will officially assume office after completing the necessary signing procedures at the White House, succeeding the current Chair Powell, whose term ends this Friday (May 15). However, Powell is expected to remain on as a Federal Reserve Governor. This vote marks one of the most significant partisan divides in history: only one Democrat—Senator John Fetterman of Pennsylvania—voted in favor alongside the Republican majority.

  • Nvidia Stock Hits Record High with Market Capitalization Reaching $5.5 Trillion

    On May 13, during early trading in the U.S. stock market, Nvidia's stock price rose by 2.85%, reaching $227.08 per share, setting a new record high, with a total market capitalization of $5.50 trillion.

  • BTC Falls Below $80,000

    Market data shows that BTC has fallen below $80,000, currently priced at $79,998.07, with a 24-hour decline of 1.06%. The market is experiencing significant volatility, so please ensure proper risk management.

  • President Trump to Arrive in Beijing

    On the evening of May 13, President Trump will arrive in Beijing aboard a special aircraft.

  • OG Agent Global Launch Conference (Shenzhen Station) Successfully Concludes: The Intelligent Computing Era Officially Begins

    On May 13, 2026, the AI intent-driven engine “Intelligent Trading Intent Awakening: OG Agent Global Launch Conference”, co-hosted by Ju.com and Nivex, successfully concluded simultaneously in Hangzhou, Chongqing, and Shenzhen. This grand event brought together global blockchain elites and ecosystem leaders to jointly witness a milestone moment in AI trading in the Web 4.0 era.

  • OG Agent Global Launch Conference Holds Roundtable Forum, Discussing “Web 4.0 Era: Foundations, Challenges, and Future Directions of AI Intent Trading”

    On May 13, 2026, the AI intent-driven engine “Intelligent Trading Intent Awakening: OG Agent Global Launch Conference”, co-hosted by Ju.com and Nivex, was simultaneously held in Hangzhou, Chongqing, and Shenzhen. This three-city linkage marks that the tremendous AI momentum embedded in OG Agent is highly favored by users.