MangoFarmSOL Hack
Incident Overview
MangoFarmSOL exit scammed, stealing 1,297,344 USD worth of SOL (13,514 tokens) from users and deleting their website and Twitter account.
MangoFarmSOL, a yield farming protocol on the Solana blockchain, encouraged users to deposit Solana tokens into the protocol to earn airdrops. On January 6, 2024, the project conducted an exit scam, withdrawing a total of 13,514 SOL tokens (worth around 1.29 million USD) deposited by users. The stolen funds primarily consisted of SOL tokens, which were then laundered through various channels, first bridging to the Ethereum network via wormhole and allbridge and then deposited into platforms such as Railgun and eXch.
The acquired USDC was bridged from the Solana network to Ethereum via the wormhole bridge. The project subsequently deleted their website and Twitter account.
Scammer Address:
https://explorer.solana.com/address/FLq2GE2x4kv5UbK6Qw2h9FtBPcLeZnNhwSeGvDDokYbH
Additional Scammer Addresses:
https://explorer.solana.com/address/8ggviFegLUzsddm9ShyMy42TiDYyH9yDDS3gSGdejND7
https://explorer.solana.com/address/8FNFfU47C2W4kEZv3kJ7r4S4LrUNoB5tJ4NGm2TwdGW6
Funds Withdraw Transaction:
https://explorer.solana.com/tx/2HFZyg21afEgKy9NgM7p4TQFzA33ppNWwsSoLyh61wxRFB2ELkpsKPECwu4PrUtRNF3TvmJZbXmQ4thjw3gFcLK9
https://explorer.solana.com/tx/nod1VcqpUm9K5sexbJFyZSfQZpY9qJwgyQGRdtqHMEmjQ1RExtqcdsdqQBQeQ3YKqFbd9Z3YUzJ6s9t3FCFoLJK
eXch, Railgun Deposit Transaction:
https://etherscan.io/tx/0xe2903d42…8f3d17
https://etherscan.io/tx/0xe21d8496…8ac5dd
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to MangoFarmSOL, these are the critical security checks that could have prevented this incident (February 2024).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
- 01
-
02
Web Archive https://archive.ph/NRxov
Learn to Prevent the Next MangoFarmSOL
The MangoFarmSOL hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.