Mango Markets Exploit

Mango Markets

Critical
Resolved
October 11, 2022
Oracle Manipulation
$114,000,000.00

Description

An attacker manipulated the MNGO token price oracle by taking large positions on two exchanges, artificially inflating the price to take out significant loans against their position.

Technical Details

The attacker manipulated Mango's oracle price by taking large opposing positions on two exchanges, artificially moving MNGO's price. This allowed the attacker to take out massive loans against their position, draining Mango's treasury.

DEX
Oracle
Lending

Exploit Timeline

Initial Attack

Attacker began manipulating MNGO price across exchanges.

Funds Drained

Approximately $114M was drained from the protocol.

Negotiation

Attacker negotiated to return $67M, keeping $47M as a "bug bounty".