Mango Markets
Solana's flagship cross-margin lending and perpetuals DEX, drained of ~$110M via oracle manipulation of its own MNGO token in 2022, then wound down in 2025 citing regulatory constraints.
▶ Run interactive simulation animated mechanism with editable parameters
How it works onchain
Summary
Mango Markets was Solana's early flagship for fully on-chain leveraged trading: a cross-margin protocol combining spot markets, perpetual futures, and permissionless borrow/lend in a single margin account. Founded in early 2021 by Daffy Durairaj and Maximilian Schneider (developed via the Blockworks Foundation), it raised roughly $70.5M in an August 2021 MNGO token sale that capitalized an insurance fund and seeded the Mango DAO. In October 2022, trader Avraham Eisenberg manipulated the thinly traded MNGO token's oracle price to borrow and withdraw about $110-116M — one of the defining oracle-manipulation exploits in DeFi. The protocol relaunched as Mango v4 but never recovered its position, and the community voted to wind the platform down in January 2025, citing regulatory constraints.
Design (Mechanism)
Mango's core primitive was the cross-margin account: every deposit was simultaneously collateral for spot leverage, perp positions, and borrows. Key components:
- Unified risk engine. Each account's health was computed across all assets and positions, with asset-specific collateral weights. Any listed token could be borrowed against any other, and unrealized perp PnL counted toward borrowing power — the property the exploit weaponized.
- Oracle-priced collateral. Collateral and perp marks were valued from external oracles (Pyth/Switchboard feeds) reflecting spot prices on venues where long-tail assets like MNGO traded thinly.
- On-chain order books. Spot trading routed through Serum's central-limit order book; perps used Mango's own on-chain book, with liquidity mining in MNGO rewarding market makers rather than deals with professional MM firms.
- Perpetual futures with funding. Standard funding-rate perps, including a MNGO-PERP market whose open interest could dwarf the token's real spot liquidity.
- Token-sale-capitalized insurance fund and DAO. The 2021 sale locked ~$70M in the protocol, part earmarked as an insurance backstop; MNGO governed the DAO, which controlled listings, risk parameters, and the treasury.
- Liquidations. Underwater accounts were liquidated by permissionless keepers, with the insurance fund absorbing bad debt — assuming losses stayed within its size.
Mango v4 (program 4MangoMjqJ2firMokCjjGgoK8d4MXcrgL7XJaL3w6fVg, launched after the exploit) rebuilt the same design with conservative collateral weights, deposit caps, and oracle staleness/confidence checks.
Outcome
- Post-token-sale (Aug 2021), Mango held ~$70M and became one of Solana's largest margin venues in the 2021-22 cycle.
- October 11, 2022: Eisenberg funded two accounts, took opposing ~488M MNGO-PERP positions between them, then aggressively bought thin MNGO spot markets, pushing the oracle price up over 1,000% in roughly 20-30 minutes. His account's massive unrealized perp profit became borrowing power, and he withdrew ~$110-116M in various tokens, draining the protocol.
- The DAO then negotiated via governance with the attacker: Eisenberg returned roughly $67M and kept the remainder under a controversial "bounty" proposal; the DAO used treasury and returned funds to make depositors whole.
- 2024-2025: Facing regulatory constraints tied to the 2021 token sale, the DAO agreed to destroy MNGO tokens and, in January 2025, voted unanimously to end borrowing/lending and wind down Mango v4 and Boost. Outcome: exploited, then formally abandoned.
Why it worked
- Genuine architectural ambition delivered. Fully on-chain cross-margin with order-book perps was impossible on L1 Ethereum; Mango proved Solana could host a CEX-like margin engine and became core 2021-22 Solana DeFi infrastructure.
- Credible neutrality of the launch. The refundable, price-discovery token sale ($500M committed, $70.5M kept, all locked in the protocol) capitalized an insurance fund and DAO rather than VCs, earning community trust.
- Composability. One account for spot, perps, and borrow/lend was a real UX and capital-efficiency advance that later venues (Drift, Hyperliquid) iterated on.
Where the design broke
- Self-referential collateral. Letting the protocol's own illiquid token — and unrealized PnL from a perp on that token — count as borrowing power meant the cost of moving the oracle was far below the credit it unlocked. The attack was economically trivial: ~$10M of capital extracted ~$110M.
- No circuit breakers. No deposit/borrow caps per asset, no oracle deviation limits, no withdrawal delays; the entire drain happened inside half an hour.
- Insurance fund mismatch. The backstop was an order of magnitude smaller than the credit the risk engine could extend against manipulable collateral.
- Governance under duress. Negotiating with the attacker through token voting — where the attacker himself voted tokens acquired in the exploit — damaged legitimacy.
- Loss of coordination and momentum. The eventual destruction of the governance token removed the DAO's coordination mechanism; combined with the loss of market position after the exploit, continued operation stopped being viable.
Lessons
- Collateral value must be bounded by exit liquidity. Borrowing power against any asset should be capped near what liquidators could actually realize selling it; market cap or oracle price alone is meaningless for thin tokens.
- Never let a protocol's own token, or unrealized PnL on it, be high-weight collateral. Reflexive collateral converts token-price manipulation directly into treasury drain.
- Oracle manipulation is a solvency problem, not just an oracle problem. Even an honest oracle reporting a manipulated thin market is lethal; defenses (TWAPs, confidence intervals, deposit caps, borrow limits, circuit breakers) belong in the risk engine.
- A governance token can become the DAO's single point of failure. The instrument that funded and coordinated the protocol was also the one dependency whose loss ended the DAO's ability to exist.
Redesign (EDITORIAL — hypothesis, not fact)
This section is editorial hypothesis, not historical fact. A redesigned Mango would keep the cross-margin account but make the risk engine liquidity-aware: per-asset deposit and borrow caps sized to a fraction of observable on-chain depth, collateral weights derived from realized volatility and slippage curves rather than governance intuition, and zero (or near-zero) weight for the native token and for unrealized PnL on any market whose open interest exceeds spot depth. Oracle inputs would be TWAP-smoothed with confidence bands, and health-based withdrawals exceeding a threshold would incur a short timelock — long enough for a manipulation to mean-revert or for keepers to halt markets. The insurance fund would mechanically bound total extendable credit: the engine should never be able to lose more than the backstop plus a haircut. The token sale's lockup instinct was right but the instrument was wrong: a revenue-sharing structure decoupled from a freely-tradable governance token (or no token at all, as Hyperliquid initially demonstrated) would have removed the dependency that later forced the wind-down. Finally, incident governance should be pre-committed: an on-chain "safe harbor bounty" contract with fixed terms would have avoided negotiating with an attacker who voted tokens from the exploit on his own settlement.
Sources
- Mango v4 monorepo (Blockworks Foundation) — primary (contract)
- Mango v3 smart contract (Blockworks Foundation) — primary (contract)
- Mango (@mangomarkets) incident thread on the oracle-manipulation exploit — primary (governance)
- Mango (@mangomarkets) shutdown announcement, January 2025 — primary (governance)
- SEC Charges Entities Operating Crypto Asset Trading Platform Mango Markets for Unregistered Offers and Sales of MNGO Governance Tokens — primary (news)
- Solana's Mango Markets DEX Raises $70M in MNGO Token Sale (CoinDesk, Aug 2021) (news)
- 2022 Solana Hacks Explained: Mango Markets (Ackee Blockchain) (analysis)
- The Mango Markets Exploit: An Order Book Analysis (Solidus Labs) (analysis)
- Mango Markets Attacker Guilty of Fraud Over $110 Million Exploit (Decrypt, Apr 2024) (news)
- Judge Overturns Convictions in Mango Markets Exploiter's Crypto Fraud Case (CoinDesk, May 2025) (news)
- Mango Markets to wind down in wake of SEC settlement, DAO battle (The Block, Jan 2025) (news)
- Mango DAO votes to shut down following SEC settlement (DL News) (news)
Related experiments
Last verified: 2026-07-27 · Spot an error? Suggest a correction