Onchain Atlas

Mango Markets Exploit

A single trader manipulated the MNGO oracle price to inflate a perpetual-futures position, then borrowed against it to drain roughly $110-116M from the Solana lending protocol Mango Markets.

▶ Run interactive simulation animated mechanism with editable parameters

Statusexploited
Launched2022-10-11
ChainsSolana
Mechanismsoracle-price-manipulation, cross-margin-collateral, perpetual-futures, under-collateralized-borrowing, dao-negotiated-settlement
Official sitehttps://mango.markets/
Project X@mangomarkets (verified_by_official_website)
FoundersAvraham 'Avi' Eisenberg (attacker / exploiter) (@avi_eisen), Daffy Durairaj (co-founder, Mango Markets protocol), Maximilian 'Max' Schneider (co-founder, Mango Markets protocol)

How it works onchain

Diagram of how Mango Markets Exploit's mechanism worksOpen full-size diagram
Original diagram derived from this entry’s researched mechanism description.

Summary

Mango Markets was a decentralized cross-margin trading, lending, and perpetual-futures protocol on Solana, governed by holders of its MNGO token and, after an August 2021 token launch, the first major on-chain DAO in the Solana ecosystem. On October 11, 2022, a trader named Avraham "Avi" Eisenberg drained roughly $110-116 million from the protocol in a single sequence of transactions. Rather than exploiting a smart-contract bug in the conventional sense, Eisenberg attacked the protocol's economic assumptions: he manipulated the reported price of the thinly traded MNGO token to massively inflate the value of a leveraged position he controlled, then borrowed against that phantom collateral until Mango's treasury was empty. The event became one of the defining oracle-manipulation exploits in DeFi.

Design (Mechanism)

Mango let users deposit assets into a cross-margin account and use the entire balance as collateral for spot borrowing and for perpetual-futures positions on assets like BTC, ETH, SOL, and MNGO itself. Collateral values and position mark prices were set by external price oracles — Mango used Pyth and Switchboard feeds, which for MNGO drew on venues including FTX, AscendEX, and the on-chain MNGO/USDC market. Because the account was cross-collateralized, an increase in the value of any held asset or open position raised the total borrowing power of the account. The critical weakness was that MNGO was a low-liquidity governance token, so its oracle-reported price could be moved sharply with a relatively small amount of capital across the reference venues.

The attack used two funded accounts. Eisenberg deposited USDC and took a large long MNGO-PERP position on one account and the matching short on the other, effectively trading with himself to establish an enormous notional position. He then bought MNGO spot across the reference exchanges, spiking the oracle price of MNGO by roughly 2,300% (from around $0.03 to over $0.90) within minutes. That price spike caused an unrealized profit of hundreds of millions of dollars on his long perpetual position, which the cross-margin system counted as collateral. He then borrowed and withdrew essentially all of the protocol's deposited assets — USDC, SOL, BTC (Sollet), mSOL, USDT, and more — against the inflated collateral, leaving the protocol insolvent when MNGO's price reverted.

Outcome

The protocol was drained of roughly $110-116 million (estimates vary by asset pricing), rendering it insolvent and unable to make lenders whole. In the days after, Eisenberg publicly claimed responsibility, describing his actions on social media as a "highly profitable trading strategy" that used Mango "as designed." He submitted a governance proposal to the Mango DAO offering to return most of the funds in exchange for keeping a portion as a "bug bounty"; he voted for it with tokens acquired in the exploit. A counter-proposal from the community ultimately passed, under which Eisenberg returned about $67 million and kept roughly $47 million — at the time the largest crypto "bounty" on record.

Why it worked

  • Cross-margin collateral valuation depended entirely on oracle prices, and MNGO's oracle drew from low-liquidity venues that a single well-capitalized actor could move with a few million dollars.
  • The protocol allowed a position in its own governance token to serve as borrowing collateral, creating a reflexive loop where pumping MNGO directly increased borrowing power.
  • There were no circuit breakers, borrow caps, position limits, or oracle sanity checks that would have flagged a 2,300% intra-minute price move as anomalous.

Why it failed or underperformed

  • The attack was permissionless and atomic; by the time the price reverted, the assets were already withdrawn, and the protocol had no insurance fund large enough to cover the shortfall.
  • The DAO's negotiated settlement recovered only part of the loss and set an uncomfortable precedent of negotiating with the party who withdrew the funds rather than pursuing full recovery, while lenders still absorbed losses.
  • Deterrence through outside enforcement proved far weaker and slower than assumed, leaving DeFi protocols largely on their own for economic security.

Lessons

  • Oracle security is collateral security: any asset used as collateral must be priced from deep, manipulation-resistant sources, and illiquid governance tokens are especially dangerous as collateral for their own protocol.
  • Economic exploits are not "bugs" in code but violations of design assumptions; audits of Solidity/Rust do not catch a protocol that faithfully executes an attacker's manipulation.
  • Risk parameters matter as much as code: borrow caps, position limits, time-weighted or multi-source oracles, and confidence-interval checks can blunt this class of attack.
  • Do not assume outside enforcement will backstop economic security; protocols must treat economic security as fully their own responsibility.

Redesign (EDITORIAL — hypothesis, not fact)

The following is analysis, not established fact. A more resilient Mango would decouple borrowing power from reflexive assets: disallow a protocol's own low-cap governance token as cross-margin collateral, or apply a steep, dynamic haircut that shrinks as position size grows relative to token liquidity. Oracle inputs could require agreement across several independent venues, weighted by traded depth, with confidence-interval gating that freezes borrowing when a feed's reported price diverges from a time-weighted average beyond a threshold — turning a 2,300% spike into a halt rather than free collateral. Protocol-wide and per-asset borrow caps, plus per-account leverage ceilings on illiquid assets, would cap the maximum extractable loss. Finally, a meaningfully funded, over-collateralized insurance backstop and an automatic delayed-withdrawal circuit breaker for outsized withdrawals would give the system time to react before insolvency becomes irreversible. None of these would have required detecting a code bug — only pricing the true, liquidity-adjusted risk of the collateral.

Sources

  1. SEC Charges Avraham Eisenberg with Manipulating Mango Markets' Governance Token to Steal $116 Million — primary (governance)
  2. U.S. v. Avraham Eisenberg — SDNY Opinion and Order vacating convictions (May 2025) — primary (analysis)
  3. How Market Manipulation Led to a $100M Exploit on Solana DeFi Exchange Mango (news)
  4. The Mango Markets Exploit: An Order Book Analysis (analysis)
  5. Judge Overturns Convictions in Mango Markets Exploiter's Crypto Fraud Case (news)
  6. Mango Markets exploiter seeks to keep disputed funds paid as 'bug bounty' (governance)
  7. Mango Markets to wind down in wake of SEC settlement, DAO battle (news)

Related experiments

Last verified: 2026-07-27 · Spot an error? Suggest a correction