{"id":448,"date":"2023-01-30T12:41:08","date_gmt":"2023-01-30T10:41:08","guid":{"rendered":"https:\/\/ackeeblockchain.com\/blog\/?p=448"},"modified":"2023-01-30T12:41:08","modified_gmt":"2023-01-30T10:41:08","slug":"2022-solana-hacks-explained-mango-markets","status":"publish","type":"post","link":"https:\/\/ackee.xyz\/blog\/2022-solana-hacks-explained-mango-markets\/","title":{"rendered":"2022 Solana Hacks Explained: Mango Markets"},"content":{"rendered":"<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/mango.markets\/\"><strong>Mango Markets<\/strong><\/a> is a platform for <strong>cross-collateralized leverage trading<\/strong>. On October 12, 2022, an attacker drained over <strong>$116M<\/strong> worth of assets by<strong> manipulating the oracle price data.<\/strong><\/span><\/p>\n<p><b>Exploit Details<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The attacker used over <strong>$5M USDC<\/strong> to fund an account, <a href=\"https:\/\/trade.mango.markets\/account?pubkey=CQvKSNnYtPTZfQRQ5jkHq8q2swJyRsdQLcFcj3EmKFfX\">took a short MANGO-PERP position<\/a>, and offered 488M MANGO-PERP to sell at $0.0382. Next, he funded another account with <strong>additional $5M USDC<\/strong>, took<a href=\"https:\/\/trade.mango.markets\/account?pubkey=4ND8FVPjUGGjx9VuGFuJefDWpg3THb58c277hbVRnjNa\"> a long MANGO-PERP position<\/a>, and <strong>bought 488M MANGO-PERP<\/strong>. Due to <strong>low liquidity<\/strong> on the exchange between <strong>MANGO<\/strong> and <strong>USDC<\/strong>, the attacker was able to <strong>pump the price<\/strong> of MANGO on various exchanges <strong>5-10x<\/strong> in a matter of minutes. The updated prices by Oracles were pumped up to $0.91 per unit and allowed the attacker <strong>to take out a loan of $116M<\/strong> worth and withdraw BTC (Sollet), USDT, SOL, mSOL, USDC from Mango.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After the exploit, the <strong>hacker<\/strong> <strong>proposed on the Mango DAO<\/strong> vote that he would <strong>keep the $70M bounty and send back $50M<\/strong> if Mango Markets uses the remaining funds to <strong>pay<\/strong> <strong>back users<\/strong> with and without bad debt and, in addition, <strong>will not pursue any criminal investigations<\/strong> or freezing of funds once the tokens are sent back. Finally, the <strong>Mango DAO <a href=\"https:\/\/app.realms.today\/dao\/MNGO\/proposal\/GYhczJdNZAhG24dkkymWE9SUZv8xC4g8s9U8VF5Yprne\">offered<\/a> a $47M worth bounty<\/strong> along with the promise not to press charges if he sent back <strong>$67M<\/strong> worth of tokens.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Shortly after the exploit, the <strong>identity<\/strong> of the exploiter <strong>was revealed<\/strong>; the man&#8217;s name was <strong>Avraham Eisenberg<\/strong>, and he didn&#8217;t really hide. Instead, allegedly, he created a <a href=\"https:\/\/twitter.com\/avi_eisen?lang=en\"><strong>Twitter<\/strong> <\/a>account where he bragged about the exploit and gained lots of followers. Even though <strong>a part of the stolen funds was returned<\/strong> as per the DAO vote, the U.S. Department of Justice <a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.nysd.591629\/gov.uscourts.nysd.591629.3.0.pdf\">announced<\/a> <strong>the arrest of Abraham Eisenberg,<\/strong> and later on, the CFTC (Commodity Futures Trading Commission) <strong>filed <a href=\"https:\/\/www.courtlistener.com\/docket\/66707334\/1\/unknown-case-title\/\">charges<\/a> against him <\/strong>along with <a href=\"https:\/\/cointelegraph.com\/news\/mango-markets-sues-avraham-eisenberg-for-47m-in-damages-plus-interest\">Mango Markets<\/a>.<\/span><\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_450\" aria-describedby=\"caption-attachment-450\" style=\"width: 236px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-450 \" src=\"https:\/\/abchprod.wpengine.com\/wp-content\/uploads\/2023\/01\/c339c6ec-16e6-409f-b004-03eb93d8a74b-e1675075169410-300x268.webp\" alt=\"\" width=\"236\" height=\"211\" srcset=\"https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/c339c6ec-16e6-409f-b004-03eb93d8a74b-e1675075169410-300x268.webp 300w, https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/c339c6ec-16e6-409f-b004-03eb93d8a74b-e1675075169410-768x685.webp 768w, https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/c339c6ec-16e6-409f-b004-03eb93d8a74b-e1675075169410-370x330.webp 370w, https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/c339c6ec-16e6-409f-b004-03eb93d8a74b-e1675075169410-760x678.webp 760w, https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/c339c6ec-16e6-409f-b004-03eb93d8a74b-e1675075169410.webp 948w\" sizes=\"auto, (max-width: 236px) 100vw, 236px\" \/><figcaption id=\"caption-attachment-450\" class=\"wp-caption-text\">Avraham Eisenberg. Source: <a href=\"https:\/\/cointelegraph.com\/news\/mango-markets-sues-avraham-eisenberg-for-47m-in-damages-plus-interest\">Cointelegraph<\/a><\/figcaption><\/figure>\n<p><b>In simple words, <\/b>unlike <a title=\"2022 Solana Hacks Explained: Wormhole\" href=\"https:\/\/ackeeblockchain.com\/blog\/2022-solana-hacks-explained-wormhole\/\">Wormhole<\/a> or <a title=\"2022 Solana Hacks Explained: Cashio\" href=\"https:\/\/ackeeblockchain.com\/blog\/2022-solana-hacks-explained-cashio\/\">Cashio<\/a>, <span style=\"font-weight: 400;\">Mango Markets <strong>wasn\u2019t hacked<\/strong> at all, it was <strong>exploited<\/strong>. Avraham Eisenberg <strong>pumped<\/strong> the price of the Mango\u2019s native token, then sold, thus <strong>dumped<\/strong> the price and <strong>profited from the spread<\/strong>.\u00a0<\/span><\/p>\n<p><strong>References<\/strong><\/p>\n<p><a href=\"https:\/\/twitter.com\/mangomarkets\/status\/1580053208130801664\">1, <\/a><a href=\"https:\/\/twitter.com\/joshua_j_lim\/status\/1579987655110324224\">2, <\/a><a href=\"https:\/\/www.bankinfosecurity.com\/everything-we-know-about-mango-markets-hack-a-20250\">3<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mango Markets is a platform for cross-collateralized leverage trading. On October 12, 2022, an attacker drained over $116M worth of assets by manipulating the oracle price data. Exploit Details The attacker used over $5M USDC to fund an account, took a short MANGO-PERP position, and offered 488M MANGO-PERP to sell at $0.0382. Next, he funded another account with additional $5M USDC, took&hellip;<\/p>\n","protected":false},"author":15,"featured_media":449,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[85,84,5],"tags":[14,86,6,19],"class_list":["post-448","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-exploits","category-hacks","category-solana","tag-exploit","tag-hack","tag-solana","tag-solana-security"],"aioseo_notices":[],"featured_image_src":"https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/Mango-600x400.png","featured_image_src_square":"https:\/\/ackee.xyz\/blog\/wp-content\/uploads\/2023\/01\/Mango-600x600.png","author_info":{"display_name":"Aleksandra Yudina","author_link":"https:\/\/ackee.xyz\/blog\/author\/aleksandra-yudina\/"},"_links":{"self":[{"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/posts\/448","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/comments?post=448"}],"version-history":[{"count":0,"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/posts\/448\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/media\/449"}],"wp:attachment":[{"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/media?parent=448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/categories?post=448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ackee.xyz\/blog\/wp-json\/wp\/v2\/tags?post=448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}