Mango Markets: $114M MNGO Perpetual Oracle Manipulation & Bad Debt Extraction
Decision_Node (smart contract lending pool) determined borrowing capacity from single-source illiquid oracle State_Telemetry. Asymmetric state distortion drained entire protocol liquidity buffer.
An attacker funded two accounts with $5M each on Solana lending protocol Mango Markets, opened massive opposing perpetual futures contracts on the low-liquidity MNGO token, and simultaneously bought spot MNGO across decentralized exchanges to manipulate the Pyth oracle price from $0.038 to $0.91 (+2,300%). The inflated unrealized collateral allowed the attacker to borrow and drain $114M in protocol liquidity.
Decision_Node (smart contract lending pool) determined borrowing capacity from single-source illiquid oracle State_Telemetry. Asymmetric state distortion drained entire protocol liquidity buffer.
Bought spot tokens on illiquid DEX to push oracle price up 2,300%
Reported $0.91 price to Mango lending contract without cross-checking global market depth
Calculated account borrowing power as $114M based on temporary inflated valuation
Released all USDC, SOL, and BTC collateral, leaving protocol insolvent
"The smart contract was tricked into valuing low-liquidity collateral at hundreds of millions of dollars."
Cross-Domain Invariant Twin Failures (48)
Decision_Node (smart contract lending pool) determined borrowing capacity from single-source illiquid oracle State_Telemetry. Asymmetric state distortion drained entire protocol liquidity buffer.
Decision_Node (smart contract logic) calculated account solvency using decoupled internal balances without verifying external physical reserves. Asynchronous state exploitation drained total protocol buffer.
Decision_Node (smart contract lending pool) determined borrowing capacity from single-source illiquid oracle State_Telemetry. Asymmetric state distortion drained entire protocol liquidity buffer.
Stabilization algorithms with identical risk-mitigation rules executed simultaneous quote cancellations. The collective withdrawal amplified the price collapse exponentially, draining the entire market buffer reserve.
Decision_Node (smart contract lending pool) determined borrowing capacity from single-source illiquid oracle State_Telemetry. Asymmetric state distortion drained entire protocol liquidity buffer.
Asynchronous deployment divergence left one Decision_Node running deprecated logic under repurposed telemetry flags. The unconstrained automated loop flooded State_Telemetry channels with 4M orders, consuming the entire firm capital reserve in 2,700 seconds.