Mango Markets V3 Hack
Incident Overview
The Mango Markets exchange was exploited by market manipulation. The attacker profited from the total amount of 116,000,000 $USD.
Mango Markets is a DeFi Exchange on the Solana chain. The attacker used two addresses to pump the $MNGO price and used the tokens to take a loan of 116,000,000 $USD from various pools. From the first address, the attacker bought $MNGO tokens for 5,000,000 $USDC and created opened position.
From the second address, the same amount of the tokens have been bought and a long position opened for hedging purposes. Consequently, the attacker was able to pump the token price due to little liquidity in the pool. After the accident, the exploiter opened a proposal on MangoDAO for returning the user's deposit funds for immunity, turning Mango users against the DEX.
That's also interesting that the attacker's address was funded by an FTX address.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Mango Markets V3, these are the critical security checks that could have prevented this incident (October 2022).
- Verify all logic paths related to Price Oracle Attack / Other are guarded by proper access controls and input validation - see the Oracle Manipulation & Price Manipulation attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$69.0M
Net Loss
46980000
Security Audit History
- Audit Report 1 Report
Post-Incident Timeline
-
2022-10-17
69,000,000 $USD has been recovered from the stolen funds by the hacker. After the finish of the proposal of returning part of the funds, the hacker and the Mango team decided to mark 47,000,000 $USD as a bug bounty for the hacker and returning of the remaining 69,000,000 $USD. A Twitter user named Abraham Eisenberg took the responsibility for the funds removal and said that it was not illegal action because he performed actions as the project was designed.
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Mango Markets V3
The Mango Markets V3 hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.