M

MangoProject · Collapse Archive

Algorithmic automated trading platform

Mango Markets project ceased operations due to a $110 million hack in 2022, SEC investigation and settlement, and DAO governance vote

01

Collapse Timeline

Live API Sync
Total amount stolen$114 millionBorrowing all liquidity from the protocol through price manipulation via MNGO
Amount to be refunded$67 millionThe funds were returned through negotiations with the DAO, with the attackers retaining $47 million.
Net lossOver $47 millionThe “reward” retained by the attackers + indirect losses
Attack methodsPrice manipulationManipulating MNGO-PERP by feeding artificial price data through oracles to inflate the value of collateral.
August 2021rise

Mango Markets is now live.

Mango Markets has launched on Solana, offering decentralized spot and perpetual contract trading with leverage borrowing options, highlighted by its low latency and minimal transaction fees.

Q1 2022peak

The TVL has surpassed $200 million.

With a Total Value Locked of over $200 million, Mango Markets has emerged as one of the largest leveraged trading and lending protocols within the Solana ecosystem, experiencing continuous growth in user activity.

October 11, 2022crisis

Price manipulation attack: $114 million stolen

Avraham Eisenberg exploited two accounts on Mango Markets to manipulate the prices of MNGO perpetual contracts by aggressively buying MNGO-PERP contracts to drive up the price of the oracle, thereby borrowing out all available assets under the protocol—amounting to $114 million—in the form of inflated collateral values, including USDC, SOL, BTC, ETH, and others.

Total amount stolen$114 millionThe extent of price manipulation for MNGORosed from $0.03 to $0.54 (+1700%)Attack durationapproximately 20 minutes
October 14, 2022crisis

DAO voting negotiations for restitution

Through a governance vote proposal, Mango DAO approved Eisenberg to retain $47 million as a “bug bounty” and return $67 million. Eisenberg subsequently returned approximately $67 million in assets but kept the remaining balance.

Amount to be refunded$67 millionThe attacker retains it.$47 million
October 15, 2022crisis

The attackers have publicly identified themselves.

Avraham Eisenberg publicly admitted on Twitter that he was the attacker himself, claiming it was a “highly profitable trading strategy” and a legitimate market maneuver rather than a hacking attack.

December 27, 2022aftermath

Eisenberg was arrested in Puerto Rico.

The FBI arrested Avraham Eisenberg in Puerto Rico and charged him with commodity fraud and market manipulation. This marks the first criminal arrest in the United States related to market manipulation activities on DeFi protocols.

January 2023aftermath

The SEC has filed a civil lawsuit.

The U.S. Securities and Exchange Commission has filed a civil lawsuit against Eisenberg, accusing him of securities fraud and market manipulation on Mango Markets, and has classified the MNGO token as an unregistered security.

April 18, 2024resolution

Eisenberg was found guilty by the jury.

A jury at the U.S. District Court for the Southern District of New York found Eisenberg guilty of both commodity fraud and market manipulation. This marks the first criminal conviction related to DeFi market manipulation in U.S. history, making it a landmark case.

Number of chargesBoth conditions are met.Historical significanceFirst criminal conviction for DeFi manipulation
2025resolution

Mango Markets has ceased operations.

Following a DAO vote, Mango Markets officially ceased operations. The attack and subsequent regulatory pressures prevented the protocol from returning to normal functionality, with its TVL never recovering to pre-attack levels.

02

On-chain evidence

Transactions on the Solana Chain / Arkham Intelligence

MNGO price manipulation: $0.03→$0.54 (+1700%)price manipulation

The attacker used two Mango Markets accounts to first establish a large number of MNGO-PERP short positions in Account A, and then used Account B to buy large amounts of MNGO in the spot market and PERP market. Within just 20 minutes, the price of MNGO soared from $0.03 to $0.54, a increase of over 1700%. The unrealized profit of Account B surged to $114 million. · solana · Attacker Account B → Mango Markets Protocol · Records on the Solana chain / FBI court documents · Pre-manipulation price $0.03 · Manipulate peak value $0.54 · Increase rate +1700%

$1.14亿(未实现利润) Confirmed

Lend out all agreed assets using inflated collateralLiquidity drain

Attackers used the inflated unrealized profits of MNGO-PERP positions as collateral to borrow all available assets on Mango Markets, including USDC, SOL, BTC, SRM, MSOL, etc., totaling $114 million. The borrowing was completed within about 20 minutes after the price manipulation. · solana · Mango Markets Protocol Treasury → Attacker's external wallet · Solana chain records · Types of Assets Borrowed Out USDC/SOL/BTC/SRM/MSOL, etc. · Loan processing time About 20 minutes

$1.14亿 Confirmed
03

Loss distribution and cascading effects

Total amount stolen$114 millionAll available liquidity borrowed from the protocol
Negotiations with the DAO to recover the assets$67 millionThe portion returned by the attackers in accordance with the DAO proposal
The attacker retains it.$47 millionThe "bug bounty" retained by Eisenberg
Actual LP lossesOver $47 millionThe net losses incurred by liquidity providers and deposit users
Attack costapproximately $5 millionThe initial capital investment Eisenberg used to manipulate prices
$114 millionTotal Loss
The attacker retains the bounty.$47 million41.23%
Negotiations with the DAO to recover the assets$67 million58.77%

The attackers borrowed all available liquidity from the protocol by manipulating the price of MNGO tokens. After negotiations through the DAO, they returned $67 million, keeping $47 million as a “bug bounty.” The protocol’s LPs and depositors bore the ultimate losses.

A Paradigm Shift in DeFi Oracles Security:The Mango attack exposed the risks of oracle manipulation when tokens with low liquidity are used as collateral, prompting the industry to reevaluate oracle design. Several DeFi protocols have since implemented defensive mechanisms such as TWAP oracles, liquidity-weighted price feeding, and borrowing limits.

Legal precedents regarding market manipulation in the DeFi sector:The Eisenberg case became the first criminal conviction for DeFi market manipulation in the United States, setting a legal precedent that price manipulation in DeFi also constitutes a crime. The SEC’s classification of the MNGO token as a security has had a profound impact on the legal status of all DAO tokens.

Confidence in the Solana DeFi ecosystem suffers a setback.:The Mango Markets attack occurred one month before the FTX collapse, and coupled with the subsequent plunge in SOL prices following the FTX incident, the TVL of the Solana DeFi ecosystem dropped from over $1 billion to below $200 million, prompting multiple lending protocols to suspend operations or tighten their risk controls.

The ethical debate between "bug bounties" and "crime":Eisenberg claimed that his actions constituted a “legitimate trading strategy” and secured $47 million through DAO negotiations, sparking intense debate within the community. This incident ignited a major industry discussion regarding the principle of “code is law” versus legal frameworks in DeFi protocols.

04

Evolution of community sentiment

2022-10 — 2024-04
The Shock and Anger PhaseAn attack has erupted.
The bounty dispute periodEthical debates
Period of Judicial JusticeConviction
From shock to anger, from "bounty controversies" to judicial justice
Sense of anger/theft 40%Ethical controversies 25%Support for legal intervention 25%Learn from this experience. 10%

The Mango Markets attack sparked intense debates within the DeFi community regarding the principle that "code is law." The attackers revealing their identities and asserting legitimacy further exacerbated divisions within the community. Ultimately, after Eisenberg was convicted, community sentiment shifted in favor of legal intervention.

October 15, 2022 Avraham Eisenberg (attackers):I was involved with a team that operated a highly profitable trading strategy last week. I believe all of our actions were legal open market actions.

October 12, 2022 匿名LP (Mango Markets liquidity providers):I deposited $30,000 in LPs on Mango, and when I woke up, it was all gone. This isn’t some “trading strategy” — it’s outright theft.

April 18, 2024 DOJ检察官 (Federal prosecutors):Today’s ruling sends a clear message to anyone attempting to manipulate the digital asset market: regardless of the technical methods employed, market manipulation and fraud are illegal acts that will face severe legal consequences.

05

Legal developments

Convicted
DAO negotiations

Mango DAO votes in favor of the bounty program.

Through a governance proposal, Mango DAO agreed to have the attackers return $67 million while keeping $47 million as a “bug bounty.” The proposal was approved by a majority of MNGO holders, but it sparked significant controversy, with some holders arguing that these were unequal terms imposed under duress. · Mango DAO Governance Voting · decentralization · $47 million (reward) · Execution completed. · Mango DAO Governance

criminal arrest

The FBI arrested Eisenberg in Puerto Rico.

The FBI arrested Avraham Eisenberg in Puerto Rico, charging him with commodity fraud and market manipulation. This marks the first criminal arrest in U.S. history related to market manipulation in DeFi protocols. · Federal Bureau of Investigation (FBI) · United States · Arrest has been carried out. · DOJ press release

SEC civil lawsuit

The SEC has filed a securities fraud lawsuit against Eisenberg.

The U.S. Securities and Exchange Commission has filed a civil lawsuit against Eisenberg, accusing him of manipulating the price of the MNGO token—classified by the SEC as a security—in violation of anti-fraud provisions under securities law. The SEC’s lawsuit explicitly categorizes MNGO as a security of the “investment contract” type. · U.S. Securities and Exchange Commission (SEC) · United States · Legal proceedings are ongoing. · SEC Litigation Release

CFTC Enforcement Actions

The CFTC has filed a commodity fraud lawsuit against Eisenberg.

The U.S. Commodity Futures Trading Commission (CFTC) has filed a civil lawsuit against Eisenberg, accusing him of manipulating the prices of MNGO perpetual contracts in violation of relevant provisions of the Commodity Exchange Act. This marks the first time the CFTC has taken enforcement action regarding DeFi perpetual contract manipulation. · U.S. Commodity Futures Trading Commission (CFTC) · United States · Legal proceedings are ongoing. · CFTC Enforcement

criminal trial

The Eisenberg criminal trial has begun.

The U.S. District Court for the Southern District of New York has begun hearing the Eisenberg case. The prosecution presented detailed on-chain evidence showing how the attacker manipulated the MNGO price within 20 minutes and borrowed all assets held by the protocol. The defense argued that Eisenberg’s actions constituted “legitimate market trading.” · U.S. District Court for the Southern District of New York (SDNY) · United States · Under review · Court records

Conviction

The jury found the defendant guilty on both charges.

After deliberation, the jury found Eisenberg guilty of both commodity fraud and market manipulation. This marks the first criminal conviction for market manipulation involving a DeFi protocol in U.S. history, setting an important legal precedent that price manipulation can constitute a federal crime even within decentralized protocols. · U.S. District Court for the Southern District of New York (SDNY) · United States · Convicted · Decision by the DOJ/Court

Avraham Eisenberg was arrested in December 2022 and convicted by a jury in April 2024, becoming the first case in U.S. history to result in a criminal conviction for DeFi market manipulation. The SEC filed a civil lawsuit simultaneously, with the CFTC also joining the enforcement efforts.

06

Lessons Learned and Insights Gained

1Tokens with low liquidity should not be used as collateral for high-leverage trading.

MNGO’s daily trading volume is less than $1 million, yet attackers were able to drive its price up by 1,700% with just an investment of $5 million. DeFi protocols must enforce strict collateral limits and leverage caps for tokens with low liquidity. 重点:Tokens with low liquidity = high risk of manipulation

2The oracle design must be resistant to manipulation.

The oracle used by Mango Markets reflected manipulated prices in a short period of time. The protocol should adopt anti-manipulation mechanisms such as TWAP (Time-Weighted Average Price), multi-source oracles, and liquidity weighting. 重点:Utilizing a TWAP oracle combined with multi-source verification

3"Code is law" cannot replace actual legislation.

The court completely rejected Eisenberg’s argument regarding a “legitimate trading strategy.” DeFi protocols cannot operate outside the legal framework, as manipulative behavior constitutes a crime whether it occurs on-chain or off-chain. 重点:DeFi is not a lawless territory.

4The limitations of DAO governance during crises

Following the attack, Mango DAO was forced to choose between adopting a bounty program or rejecting it in favor of pursuing legal action. The voting rights held by DAO members—including the attackers themselves who owned large amounts of MNGO—raised doubts about the integrity of its governance process. 重点:DAO governance requires safeguards to prevent attackers from voting.

5The borrowing limit and risk control parameters serve as the final line of defense.

Even if oracles are manipulated, attackers cannot borrow out all available liquidity at once if the protocol incorporates parameters such as a single-account borrowing limit and restrictions on the proportion of total borrowed funds relative to TVL. Risk control parameters serve as the ultimate safety valve for DeFi protocols. 重点:Set a maximum borrowing limit per account along with a TVL percentage restriction.

The Mango Markets attack is one of the most instructive cases in DeFi security history, exposing flaws in oracle design, the manipulation risks associated with tokens with low liquidity, and the limitations of the principle that "code is law."

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions