Canonical Investigation

Mango Markets Oracle Manipulation (2022)

EXPLOITED - PARTIAL RECOVERY|N/A/100
Solana·mv3ekLzL...DEBG68dex
ConcludedScanned 18 April 2024
Run your own scan

See the evidence before you trust the verdict.

Concluded

Historical Investigation

This investigation covers the October 11, 2022 exploit, the subsequent governance settlement (October 14, 2022), and the attribution chain through Avraham Eisenberg's conviction on April 18, 2024. The criminal case established the definitive record; the DoJ sought return of profits and disgorgement. Mango Markets relaunched in a revised form; the investigation is frozen at the acute incident and legal conclusion.

Executive summary

On October 11, 2022, Avraham Eisenberg drained approximately $116M from Mango Markets using an attack that required no code exploit. He manipulated the oracle price of MNGO - the protocol's native token, which served as collateral - by approximately 30x over a short window, then borrowed and withdrew essentially every asset in the protocol treasury against the inflated collateral. The protocol executed exactly as designed throughout. This investigation matters for three reasons. First, it isolates economic design failure as a distinct failure class: the oracle assumptions, the collateral model, and the borrowing limits all behaved correctly given what they were told; what they were told was false. Second, the attribution is the first judicial attribution in this corpus - not intelligence-based (Ronin, Harmony) but a criminal conviction in the Southern District of New York on April 18, 2024. That is a third attribution pathway under Attribution Policy V1: different evidence, same policy. Third, the recovery archetype is new: Eisenberg participated in a Mango governance vote, using retained governance tokens to legitimize a settlement where he kept approximately $67M as a self-described "bug bounty." That is neither operator-funded reimbursement nor negotiated return - the protocol's own governance mechanism was the settlement venue.

Evidence Confidence

Confidence per domain, not a single score.

Incident

Verified

Attribution

Verified

Loss

High

Recovery

High
Timeline

How the incident unfolded

  1. October 11, 2022

    Attack: opposing perpetuals + oracle manipulation + treasury drain

    Eisenberg funds two accounts with USDC and establishes large opposing MNGO-PERP positions - long on one account, short on the other. He then buys MNGO aggressively on spot markets, inflating the oracle price. As the oracle price rises, the long account's collateral value soars. He borrows essentially all available treasury assets against the inflated collateral and withdraws them. The drain takes place within hours.

    Mango Markets post-mortem; on-chain Solana records; governance forum; court record

  2. October 11, 2022

    Oracle price collapses; account rendered insolvent

    After the assets are withdrawn, the oracle price of MNGO falls back toward market levels. The long account is left as a deeply insolvent position - collateral worth far less than the borrowed assets. The protocol has an unrecoverable bad debt position of approximately the drained amount.

    On-chain Solana records; Mango Markets post-mortem

  3. October 13-14, 2022

    Eisenberg submits and executes governance settlement

    Eisenberg posts a governance proposal to the Mango DAO forum: in exchange for a release from DAO-level legal action, he will return assets to the treasury in excess of approximately $70M USD equivalent in MNGO. The DAO votes to approve the settlement. Approximately $47M in assets is returned.

    Mango Markets governance forum; on-chain governance record

  4. October 15, 2022

    Eisenberg publicly identifies himself on Twitter

    Eisenberg posts on Twitter claiming the attack was "a highly profitable trading strategy" and that all actions were "legal open market actions." He frames the settlement as a legitimate outcome and the retained funds as a bug bounty.

    Public Twitter post (widely archived)

  5. December 27, 2022

    Arrested; DoJ indictment unsealed

    Eisenberg is arrested in Puerto Rico. The DoJ unseals an indictment charging him with commodity fraud, commodity market manipulation, and wire fraud in the Southern District of New York. The CFTC simultaneously announces a parallel civil enforcement action.

    DoJ announcement; CFTC announcement; court filing

  6. April 18, 2024

    Conviction by jury (SDNY)

    A jury convicts Eisenberg on commodity fraud and commodity market manipulation charges. The verdict is the definitive legal record of the conduct and constitutes the qualifying primary evidence for ATTRIBUTED status under Attribution Policy V1 (judicial pathway). Sentencing and disgorgement proceedings follow.

    SDNY court record; DoJ announcement (April 18, 2024)

Evidence Summary

What the evidence shows

Root cause

VERIFIED

Oracle price manipulation via self-directed spot trading

Mango Markets used a price oracle that incorporated the protocol's own spot market prices for MNGO. The attacker established large opposing perpetual positions using two accounts, then bought MNGO aggressively in spot markets to inflate the oracle price. The inflated price caused the attacker's collateral to appear many times more valuable than its economic value. This mechanism is confirmed by the attacker's public description, the protocol's post-mortem, and the criminal conviction for commodity market manipulation.

Scale (total drained)

PARTIAL

~$116M across treasury assets

Total drained from the Mango Markets treasury corroborated across multiple independent post-mortems and security firm analyses. The figure commonly cited ranges from $114M to $117M; the variation reflects different asset price references at time of drain. Per-asset breakdown across USDC, SOL, mSOL, BTC, USDT, SRM and others is pending independent reconstruction from Solana transaction records.

Attribution

VERIFIED

Avraham Eisenberg (SDNY conviction, April 18, 2024)

Eisenberg publicly identified himself on Twitter on October 15, 2022, describing the attack as "a legal, highly profitable trading strategy." He was arrested December 27, 2022, in Puerto Rico. The DoJ and CFTC charged him with commodity fraud, commodity market manipulation, and wire fraud. A jury in the Southern District of New York convicted him on April 18, 2024. Criminal conviction is qualifying primary evidence under Attribution Policy V1 (judicial pathway).

Recovery

PARTIAL

~$47M returned via governance vote; ~$69M net loss

Eisenberg submitted a governance proposal to the Mango DAO on October 13-14, 2022: he would return assets in excess of approximately $70M USD equivalent in MNGO, and the DAO would agree not to pursue criminal charges. The DAO voted to approve the settlement. Approximately $47M in assets was returned. The net loss - funds retained by Eisenberg - was approximately $67-69M. The DAO's agreement not to pursue criminal charges was subsequently found not to bind the DoJ or CFTC, which prosecuted independently.

Governance settlement mechanism

VERIFIED

Attacker participated in his own settlement vote

Eisenberg retained MNGO tokens after the exploit (part of his inflated long position). He used those tokens to vote on the governance proposal he submitted, giving him disproportionate influence over the settlement outcome. The DAO approval was a formal on-chain governance action on a public protocol, documented in the governance forum and the on-chain record.

Findings

What XemaS found

Mango Markets was a Solana-based decentralized exchange offering spot trading, perpetual futures, and borrowing against collateral. Its MNGO governance token could be deposited as collateral to borrow other assets. The collateral value of any asset, including MNGO, was determined by an oracle - a price feed that incorporated Mango's own spot market prices. In October 2022, MNGO had relatively thin liquidity on those spot markets, meaning a concentrated buyer with enough capital could meaningfully move its oracle price.

Eisenberg's approach did not require exploiting any code path. He opened two accounts, each funded with approximately $5M USDC. The first account took a large MNGO-PERP long position; the second account took the opposing short, making the two positions internally offset. Then he bought MNGO aggressively across spot venues - including Mango's own markets and external exchanges - driving the oracle price from roughly $0.03 to a peak many times higher. The precise peak is PARTIAL in this investigation; sources vary on the exact figure.

As the oracle price soared, the collateral value of the first account's MNGO position inflated in tandem. With paper collateral now many times the economic value of the position, the account was within its borrowing limits - from the protocol's perspective, it was fully collateralized. Eisenberg used that collateral to borrow essentially every liquid asset in the Mango treasury: USDC, SOL, mSOL, BTC, USDT, SRM and others. Each borrowed asset was withdrawn. When the oracle price later fell back, the first account was deeply insolvent - but the borrowed assets were already gone.

Three days later, Eisenberg submitted a governance proposal to the Mango DAO. Its terms: Mango Markets would receive assets in excess of his retained amount back to the treasury; the DAO would agree not to pursue criminal action; Mango would deploy recovered assets to repay bad debt. The vote passed. Approximately $47M returned to the protocol. Eisenberg publicly framed the $67M he retained as a legitimate bug bounty on October 15, 2022.

The DoJ and CFTC took a different view. Eisenberg was arrested in Puerto Rico on December 27, 2022, charged with commodity fraud and commodity market manipulation. His defense - that the attack was legal market activity - was rejected by the jury. He was convicted on April 18, 2024. The DoJ sought disgorgement. The DAO's agreement not to prosecute did not bind federal authorities; DAO governance has no jurisdiction over federal criminal law.

Fund Flow

Where the value went

Capital flowed in two directions: ~$116M out of the Mango treasury across multiple borrowed assets, then ~$47M back via the governance settlement, with ~$69M retained as net proceeds. The recovery was not a return of stolen funds in the traditional sense - it was a DAO-voted settlement with a participant who held governance tokens from the attack. The settlement amount was what the attacker agreed to part with, not what the protocol recovered through enforcement.

StepMovement
1Two accounts funded with USDC; opposing MNGO-PERP positions established
2MNGO spot price driven up through concentrated buying across markets
3Treasury assets borrowed and withdrawn using inflated collateral
4Assets returned via governance settlement vote
5Net proceeds retained by Eisenberg pending DoJ/CFTC enforcement
Affected Protocols

Downstream impact

Mango Markets v3

The protocol treasury was drained of essentially all liquid assets. The insolvent position left by the attacker became unrecoverable bad debt. Trading and borrowing were suspended following the incident. Mango Markets eventually relaunched in a revised form with revised collateral and oracle parameters.

MNGO (Mango Governance Token)

MNGO was both the instrument of the attack and the collateral at its center. The token price experienced extreme artificial inflation during the manipulation window and then collapsed. MNGO token holders who voted on the governance settlement did so while Eisenberg held a material stake.

Related Entities

Who was involved

Avraham Eisenberg

VERIFIED

Attacker and subsequently convicted defendant. Publicly self-identified, was arrested in Puerto Rico in December 2022, and convicted by jury in the Southern District of New York on April 18, 2024 (commodity fraud and commodity market manipulation). First judicially attributed individual in this investigation corpus; distinct from the state-sponsored group attribution in Ronin and Harmony.

Mango Markets DAO

VERIFIED

Protocol governance body that voted to approve the settlement terms proposed by Eisenberg. The DAO vote returned approximately $47M to the treasury. The DAO's grant of legal immunity did not bind the DoJ or CFTC, which prosecuted independently. The DAO governance mechanism was the settlement venue.

US Department of Justice / CFTC

VERIFIED

Joint enforcement. The DoJ charged Eisenberg with commodity fraud, commodity market manipulation, and wire fraud. The CFTC filed a parallel civil enforcement action for commodity manipulation. The prosecution proceeded independently of the DAO settlement and established the criminal record that this investigation relies on for ATTRIBUTED status.

Interpretation

Why it matters

Protocol collateral is only as sound as the oracle that prices it. When a protocol uses its own markets to price a collateral asset - particularly one with thin liquidity - anyone with enough capital to move that market can manufacture collateral. No audit would flag the oracle mechanism as a "bug" because it was not a bug; it was a design choice that assumed market depth sufficient to resist manipulation. Users allocating to any protocol where thin-liquidity native tokens serve as collateral should treat the oracle specification as a core risk parameter, not a background assumption.

Evidence

Evidence table

FactState
Root cause: Mango oracle used protocol-internal MNGO market pricesVERIFIED
Eisenberg publicly claimed the attack on Twitter (October 15, 2022)VERIFIED
DoJ indictment unsealed December 27, 2022VERIFIED
Jury conviction on April 18, 2024 (SDNY)VERIFIED
CFTC civil action filed alongside DoJ chargesVERIFIED
Total assets drained approximately $116MPARTIAL
Governance settlement returned approximately $47MPARTIAL
Mango v3 program address: mv3ekLzLbnVPNxjSKvqBpU3ZeZXPQdEC3bp5MDEBG68PARTIAL
Honest Limits

What was not visible

Per-asset treasury breakdown not independently reconstructed

The ~$116M total is corroborated across post-mortems. The breakdown across USDC, SOL, mSOL, BTC, USDT, SRM and other deposited assets requires reconstruction from Solana transaction records and is not yet independently verified. The per-asset split carries post-mortem provenance at this stage.

MNGO oracle price peak is PARTIAL

The peak oracle price that MNGO reached during the manipulation varies across post-mortem sources. This investigation does not assert a specific peak price; the mechanism (thin-liquidity spot manipulation inflating the oracle) is VERIFIED, but the exact price level during the attack window is pending independent Solana on-chain reconstruction.

Eisenberg's Solana account addresses pending XemaS verification

The specific Solana wallet addresses used by Eisenberg (the two accounts established for the opposing perpetual positions) are documented in court filings and post-mortems. They have not been independently verified in XemaS and are not yet included as confirmed perpetrator addresses in the canonical evidence record.

Mango v3 program address is PARTIAL

The program address mv3ekLzLbnVPNxjSKvqBpU3ZeZXPQdEC3bp5MDEBG68 is referenced across security analyses. XemaS has not independently verified it on-chain. Verification would confirm this is the specific program that controlled the drained treasury vaults and is the correct canonical subject for this incident record.

DAO settlement does not bind federal prosecution

The Mango DAO vote included language that the DAO would not pursue criminal action against Eisenberg. This is a legal boundary that this investigation notes as context, not legal advice: federal criminal authorities (DoJ, CFTC) are not parties to a DAO governance vote, and the subsequent prosecution proceeded independently of the settlement. This investigation does not characterize the settlement's legal effect.

Lessons Learned

What this incident teaches

An oracle that uses your own markets can be manipulated by anyone with enough capital

Mango's oracle for MNGO incorporated prices from Mango's own spot markets. In any market with finite depth, a concentrated buyer can move the price. The cost of manipulation is bounded by the available liquidity, not by protocol security. Any protocol using an internal market price as an oracle for a collateral asset must treat the cost of manipulating that price as the effective attack cost - not the code review coverage. When the token has thin liquidity, the attack cost may be a fraction of the exploitable value.

Economic design failure is not detectable by security audit

Every code path Eisenberg used executed correctly. No overflow, no reentrancy, no unauthorized access, no missing check. A full security audit of Mango's code would not have flagged this vulnerability because it was not a code vulnerability. The oracle specification, the collateral model, and the borrowing mechanism interacted in a way that created exploitable economic behavior. This class of risk requires economic auditing - stress-testing the incentive model, not just the execution correctness.

Governance as settlement venue does not bind prosecution

Eisenberg used the DAO's own governance mechanism to settle the dispute on terms he proposed, with his own governance tokens as part of the vote. The DAO agreement to grant immunity had no legal force over the DoJ or CFTC. Protocol teams and legal counsel should be explicit with communities: a governance vote does not settle criminal liability, because a DAO is not a signatory to a criminal plea agreement. Communities can choose to accept a settlement; they cannot grant immunity from federal law.

Judicial attribution is a distinct evidentiary pathway from intelligence attribution

Ronin and Harmony are ATTRIBUTED based on US government intelligence (OFAC designation, FBI statement). Mango is ATTRIBUTED based on criminal conviction. Both are qualifying primary evidence under the same attribution policy - but they reflect different institutional processes and different certainty characteristics. A criminal conviction requires proof beyond a reasonable doubt; a sanctions designation requires a different standard. The corpus now demonstrates that the same policy accommodates both pathways without conflating their evidence types.

Related investigations

Structurally related incidents

Relationships derived from shared taxonomy - mechanism, failure pattern, protocol family, and attribution class.

Get started

Scan any address with the same evidence engine

EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.

Scan a token or wallet

No account required for a first scan.