CryptoReal
CASE FILE — Oct 12, 2022

How a Thin-Liquidity Token Spike Cost Mango Markets $115 Million

Solana's largest margin-trading platform became the latest DeFi casualty on October 12, 2022, after a well-capitalized trader engineered a spike in the protocol's native token and used the resulting paper profits to empty its lending pools. The maneuver left Mango Markets holding $115 million in bad debt, arriving a day after separate rumors, exploits, and SEC action had already unsettled SushiSwap, according to reports circulating at the time.

The attacker's Mango Markets account, traceable to address yUJw9a2PyoqKkH47i4yEGf4WXomSHMiK7Lp29Xs2NqM, had been seeded with more than $5 million pulled from FTX — a $2 million transfer and a $3.5 million transfer, both in USDC. Those funds were deposited into Mango Markets and used to open an outsized long position on the MNGO-PERP market.

Running a simultaneous counter-trade through a second account, the trader forced the spot price of MNGO — Mango's governance token — up from roughly $0.03 to $0.91, a swing made possible largely by the token's shallow liquidity and thin trading volume. With MNGO artificially elevated, the unrealized profit sitting on the long position was pledged as collateral to borrow out the protocol's lending pools. The account in question now shows a $115 million shortfall, made up of the various borrowed assets.

The rapid price move also forced more than 4,000 short positions into liquidation, and the broader fallout dragged Solana's total value locked down more than 20%.

Sums referenced in this case file

Mango's team initially urged users to stop depositing and asked the attacker to open a dialogue about a bounty — a courtesy notably absent back in March, when a community member had already flagged a similar vulnerability on the project's Discord. After some early confusion over whether an oracle had malfunctioned, the team confirmed that the incident was deliberate price manipulation rather than a faulty price feed.

Having drained essentially all available borrow liquidity — leaving about $70 million in the treasury against the debt, a gap of roughly $50 million — the attacker turned to Mango's own governance system to formalize the outcome. Using the voting power attached to the stolen tokens, they submitted a proposal offering to return enough funds to cover that shortfall, in exchange for a bounty of roughly $65 million — effectively all the USDC, BTC, USDT, and SRM remaining in the treasury — and a commitment not to pursue any criminal investigation. The vote stayed open at time of writing, with the attacker naturally casting all 32 million commandeered governance tokens in favor of their own terms.

If ratified, the deal would let depositors be made whole and allow the protocol to resume operating, essentially restarting from zero — an outcome that lines up closely with priorities Mango itself has publicly stated, raising uncomfortable questions about whether the exploit will simply be absorbed as a cost of doing business.

The case also surfaces a harder, unresolved question: how binding is a DAO governance vote when no legal framework yet exists for this kind of DeFi decision-making? Without clearer rules, similar hostile takeovers of treasury and governance systems — by hackers or by rival organizations — seem likely to recur, echoing tactics long familiar in traditional finance.

Credit for tracing the exploit's mechanics goes to Joshua Lim. Notably, a comparable attack hit Venus Protocol the previous year — distinct from the later Venus incident tied to Terra's collapse — and Mango itself had been warned of its exposure to this exact pattern more than six months before the attack occurred.

Mango Markets
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.