Mango Markets V3
- Technique
- Spot Price Manipulation
- Classification
- Oracle Manipulation
- Target type
- DeFi Protocol
- Affected chains
- Solana
- Source
- No public source link
On October 11, 2022, at roughly 22:23 UTC, a trader who later identified himself as Avraham "Avi" Eisenberg extracted more than $110 million in assets from Mango Markets, a lending and perpetuals platform on Solana, leaving the protocol with roughly $115 million in bad debt (CFTC, sec3). No smart-contract bug was involved — the attack exploited how Mango priced its own governance token, MNGO, for collateral purposes.
How the attack worked
Eisenberg opened two Mango accounts funded with USDC routed through FTX. One took a large long position on the MNGO-USDC perpetual future; a second account, controlled by the same person, opened the matching short. On a net basis he was simply trading against himself, risking almost none of his own capital (sec3).
He then spent a comparatively small sum buying MNGO spot on Jupiter, Raydium and Serum — the same thin-liquidity venues Mango's oracle used to price the token. Within about 30 minutes the oracle price had risen more than thirteenfold, and continued climbing as the resulting wave of short liquidations forced further buying, before collapsing back toward zero once the position was closed (CFTC, rekt.news).
Because Mango's risk engine used that spot-derived oracle price to mark the long position's unrealized profit, Eisenberg's paper gains ballooned into the hundreds of millions. He settled that PnL on-chain, turning it into usable collateral, then borrowed and withdrew wrapped SOL, staked SOL, BTC, USDT and USDC against it — draining the lending pools before the price could correct (sec3). Regulators later described this as their first formal "oracle manipulation" enforcement case in DeFi (CFTC).
What happened next
Within hours, over 4,000 short positions were force-liquidated and Solana's total value locked fell more than 20% (rekt.news). Eisenberg publicly called the trade "a legal and profitable trading strategy," not theft, and offered Mango DAO a deal: he would return about $67 million and keep roughly $47 million as an informal bounty, on condition the DAO not pursue criminal complaints. Using governance weight tied to the exploit itself, he took part in the vote on his own proposal, which passed with over 99% approval (sec3).
That informal amnesty did not stop US regulators. The CFTC and SEC filed civil fraud and manipulation charges in January 2023, and federal prosecutors charged Eisenberg criminally with commodities fraud, market manipulation and wire fraud (CFTC). He was arrested in San Juan, Puerto Rico, on December 26, 2022, and a Manhattan jury convicted him on all three counts on April 18, 2024. In an unusual reversal, US District Judge Arun Subramanian vacated every criminal conviction on May 23, 2025, ruling that prosecutors had picked the wrong venue — Eisenberg traded entirely from Puerto Rico — and that the wire-fraud count failed because Mango had no terms of service defining "borrowing," so no false statement was ever made. Civil actions from the SEC and CFTC reportedly remain open (TRM Labs). Mango's DAO used its treasury and insurance fund to make depositors without exposure to the attacker's accounts whole, in exchange for those depositors waiving further claims (sec3).
What this means
- No code was broken — the exploit worked entirely through legitimate function calls. Audits that only check contract logic will not catch a design where a token's own market price, sourced from thin liquidity, doubles as its collateral valuation.
- A visible warning sign existed beforehand: MNGO had low market depth yet was accepted as high-leverage collateral through Mango's own perpetual market. Any protocol pairing a shallow-liquidity token with generous borrow limits against it carries the same structural risk.
- Post-incident governance is not neutral by default. Eisenberg voted on the settlement using influence tied to the very exploit under discussion — DAOs need a way to exclude implicated wallets from a remediation vote before it happens, not after.
- The 2025 reversal shows criminal law has not caught up with DeFi's lack of terms of service; an exploit-sounding action is not guaranteed to hold up as fraud in court, which raises the relative importance of on-chain safeguards — oracle diversification, borrow caps, circuit breakers — over after-the-fact prosecution.
Sources
- Mango Markets Rekt — Rekt.news ↗
- CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 Million from Mango Markets — U.S. Commodity Futures Trading Commission (CFTC) ↗
- Mango Markets Exploit: Technical Post-Mortem — sec3 ↗
- Federal Judge Overturns All Criminal Convictions in Mango Markets Case Against Avraham Eisenberg — TRM Labs ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.