Mango Markets Oracle Manipulation тарабынан 112 миллион долларга талкаланды

  • Mango is currently investigating an exploit of the oracle price feeds for its own governance token
  • The hacker responsible is asking DAO members to vote on a proposal that would return a portion of the stolen funds

Mango Markets, a decentralized finance (DeFi) trading platform on the Solana blockchain, said Tuesday it was investigating a hack worth approximately $112 million in digital assets.

Mango said the hacker was able to drain funds from its platform utilizing a technique known as oracle price manipulation — a form of economic attack that has hit other DeFi protocols before.

The actor managed to withdraw various digital assets — mostly stablecoins, including $53.7 million in USD Coin (USDC) and $3.2 million in Tether (USDT) — but also solana (SOL).

In an unusual twist, they’re proposing to return a portion of the stolen funds, namely Marinade staked solana (MSOL), a staking derivative, native SOL and the platform’s own MNGO governance token. The rest the culprit claims as a “bounty.”

That is, of course, if Mango’s DAO community votes yes on the thief’s proposal.

“By voting for this proposal, mango token holders agree to pay this bounty and pay off the bad debt with the treasury, and waive any potential claims against accounts with bad debt, and will not pursue any criminal investigations or freezing of funds once the tokens are sent back as described above,” the attacker wrote протоколдун башкаруу форумунда.

The hacker is requesting Mango use its treasury stash of 70 million USDC to repay “bad debt.” This debt derives from an окуя in June when the Mango community бөлүмү with another Solana-based lending and borrowing protocol, Solend, to deal with a systemic risk caused by a single large borrower, at risk of liquidation, that put the entire Solana DeFi ecosystem in jeopardy.

The Mango DAO, or stewards of the protocol, should also not pursue any criminal investigations or freeze the attacker’s funds — via centralized stablecoins like USDC and USDT — once the cryptoassets are returned.

But not all the assets will be returned; while a definitive amount for the bounty was not given, it can be assumed from the tokens omitted from the initial hack that the attacker is requesting to keep well over half of what they stole — substantially more than most “white hat” hackers or bug bounty hunters typically receive.

Still, Mango DAO members have so far voted in favor of the hacker’s proposal, with a 99.9% yes rate from roughly 33 million MNGO tokens — although just a single wallet address is responsible for the lion’s share of the vote. As DAO’s go, this one is extremely centralized, with most governance votes being decided by just a handful of addresses.

A further 67 million yes votes are required for the proposal to pass a quorum threshold during the three-day voting period.

Price oracle manipulation

While the consultation and investigation continue, the platform’s stewards have requested users to cease depositing assets until the situation becomes clearer.

Borrowing and lending dapps rely on oracles to pull on-chain data for specific tokens. Manipulation occurs when protocols such data feeds are corrupted, allowing transactions that were not intended.

In the case of Mango, the attacker was able to manipulate their collateral value via the platform before taking out “massive loans” totaling $112,199,876 from Mango’s treasury, security auditing firm OtterSec reported Твиттерде.

OtterSec founder Robert Chen confirmed the figure to Blockworks who said the price manipulation was suspected to have occurred on centralized exchanges which Mango used to reference the value of the collateral.

MNGO’s price briefly spiked about 300% to $0.15 in the space of 10 minutes on the FTX exchange, then dropped 88% to under $0.02 following the attack.

The MNGO/USD market on FTX, 1-minute time frame; Source: TradingView

Solana developer Tom Geshury was credited with being the first to bring the hack to the security auditing firm’s attention.

Geshury told Blockworks the hacker used $10 million to self-trade Mango perpetual contracts and then an estimated $3 million to pump the price of MNGO and execute the plan, before market participants got wind of the scheme and began dumping their tokens.

Shortly after OtterSec’s Twitter post, Mango released a statement saying they were taking steps to have third parties freeze funds in flight.

“We will be disabling deposits on the front end as a precaution and will keep you updated as the situation evolves,” the group Twitter аркылуу билдирди.

Blockworks attempted to contact several admins on the Mango Discord channel but was unsuccessful.

A number of protocols have been hit by such attacks this year alone, including DeFi platform Inverse Finance for $ 5.8 миллион in June and stablecoin lending platform Fortress Protocol for $ 3 миллион май айында.

The attack against Mango comes less than a week after Binance’s own network, BNB Chain, was targeted for жүздөгөн миллион доллар via a cross-chain bridge exploit. The amount stolen was contained to about $100 million.


катышуу ДАС: ЛОНДОН жана ири TradFi жана крипто институттары крипто институционалдык кабыл алуунун келечегин кантип көрөрүн угуңуз. Каттоо бул жерде.


  • Себастьян Синклер

    Блок иштери

    Азия жаңылыктар бөлүмүнүн улук кабарчысы

    Себастьян Синклер - Түштүк-Чыгыш Азияда иштеген блоктордун башкы кабарчысы. Ал крипто рыногун, ошондой эле тармакка, анын ичинде жөнгө салууга, бизнеске жана M&Aга таасир этүүчү белгилүү окуяларды камтыган тажрыйбасы бар. Учурда ал эч кандай криптовалютаны кармабайт.

    Себастьян менен электрондук почта аркылуу байланышыңыз [электрондук почта корголгон]

  • Маколи Петерсон

    Маколи Blockworks компаниясына кошулганга чейин 14 жыл бою профессионалдык шахмат дүйнөсүндө редактор жана контент жаратуучу болгон. Bucerius юридикалык мектебинде (Укук жана бизнес боюнча магистр, 2020) ал стабилкоиндерди, борбордон ажыратылган финансыны жана борбордук банктын санариптик валюталарын изилдеген. Ал ошондой эле кино таануу боюнча магистр даражасына ээ; тасмалардын кредиттерине 2016-жылы Netflix көркөм даректүү тасмасынын продюсеринин жардамчысы, шахмат боюнча Дүйнө чемпиону Магнус Карлсен жөнүндө "Магнус" кирет. Ал Германияда жайгашкан.

    Макаули менен электрондук почта аркылуу байланышыңыз [электрондук почта корголгон] же Твиттерде @yeluacaM

Source: https://blockworks.co/mango-markets-mangled-by-oracle-manipulation-for-112m/