Mango Markets V3 Hack

TOTAL LOST $116.0M
Critical Oracle Manipulation & Price Manipulation solana

What happened

Mango Markets V3 on Solana lost about $116 million on October 11, 2022 after a trader created opposing MNGO perpetual positions in two accounts and drove the thinly traded MNGO price higher on markets used by Mango's oracle. The inflated valuation made the long position appear sufficiently collateralized to withdraw most available liquidity. Public estimates vary from $110 million to $116 million with valuation timing; this page retains the record's $116 million estimate.

Technical Root Cause

Mango's risk model allowed a temporary price from shallow external MNGO markets to determine both perpetual-position valuation and borrowing capacity. Cross-account matched positions made the attacker benefit from that manufactured price. Liquidity-aware collateral haircuts, position limits, price-deviation or TWAP circuit breakers, and withdrawal limits reduce this type of oracle-driven economic attack.

Case & protocol details

Classification Oracle Manipulation / Perpetual Collateral
Protocol Type Derivatives
Affected asset / contract MGNO
Smart Contract Language Rust
Official Website mango.markets/
Protocol Twitter/X @mangomarkets

Attack Timeline

The attacker funded two Mango accounts with about $5 million USDC each and matched a large MNGO perpetual trade between them, leaving one account long and the other short. They then bought MNGO across low-liquidity markets feeding Mango's oracle, sharply raising the reported price. Mango marked the long perpetual position up from about $0.0382 per MNGO to roughly $0.54, so it appeared to have enough collateral to make 19 withdrawals worth approximately $116 million.

When the temporary price support ended, the position's value collapsed and left the protocol with bad debt.

Funds Recovery

59.5%

Recovered

$69.0M

Net Loss

$46,980,000

Post-Incident Timeline

  • 2022-10-17

    69,000,000 $USD has been recovered from the stolen funds by the hacker. After the finish of the proposal of returning part of the funds, the hacker and the Mango team decided to mark 47,000,000 $USD as a bug bounty for the hacker and returning of the remaining 69,000,000 $USD. A Twitter user named Abraham Eisenberg took the responsibility for the funds removal and said that it was not illegal action because he performed actions as the project was designed.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.