{"id":37258,"date":"2022-10-12T01:06:52","date_gmt":"2022-10-12T05:06:52","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=37258"},"modified":"2022-10-12T15:32:53","modified_gmt":"2022-10-12T19:32:53","slug":"defi-platform-mango-markets-faces-100m-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/defi-platform-mango-markets-faces-100m-exploit\/","title":{"rendered":"DeFi platform Mango Markets faces $100M exploit"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-mango-markets-a-decentralized-finance-defi-exchange-based-on-the-solana-blockchain-has-reportedly-suffered-a-breach-of-over-100-million-as-a-result-of-an-attacker-manipulating-price-data\">Mango Markets, a decentralized finance (DeFi) exchange based on the <a href=\"https:\/\/coinscreed.com\/staging\/how-to-buy-an-nft-on-solana-blockchain.html\" target=\"_blank\" rel=\"noreferrer noopener\">Solana blockchain<\/a> has reportedly suffered a breach of over $100 million as a result of an attacker manipulating price data.<\/h5>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-37.png\" alt=\"DeFi platform Mango Markets faces $100M exploit\" class=\"wp-image-37260\" width=\"708\" height=\"307\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-37.png 576w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-37-300x130.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-37-150x65.png 150w\" sizes=\"(max-width: 708px) 100vw, 708px\" \/><figcaption>DeFi platform Mango Markets faces $100M exploit<\/figcaption><\/figure>\n\n\n\n<p>By manipulating the value of their Mango (MNGO) native token collateral and then taking out &#8220;large loans&#8221; from Mango Markets' treasury, the attacker was able to drain the exchange of over $100 million, according to a tweet from  blockchain security firm OtterSec.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/mangomarkets?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@mangomarkets<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> was just drained for over $100M. <a href=\"https:\/\/t.co\/SI4hccCIQx\" target=\"_blank\">https:\/\/t.co\/SI4hccCIQx<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>\ud83e\uddf5 <a href=\"https:\/\/t.co\/IAKyXgN8gM\" target=\"_blank\">pic.twitter.com\/IAKyXgN8gM<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; OtterSec (@osec_io) <a href=\"https:\/\/twitter.com\/osec_io\/status\/1579969927020412929?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 11, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Soon after, the <a href=\"https:\/\/www.google.com\/search?q=DeFi+platform+Mango+Markets+faces+%24100M+exploit&rlz=1C1SQJL_enNG889NG889&oq=DeFi+platform+Mango+Markets+faces+%24100M+exploit&aqs=chrome..69i57j33i160.1030j0j4&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">Mango Markets team<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> posted a tweet asking the attacker to get in touch with them to talk about a bug bounty and advising users not to deposit money until &#8220;the issue was more apparent.&#8221;<\/p>\n\n\n\n<p>Later, the team acknowledged that a price oracle\u2014a price data feed of the value of its MNGO token\u2014had been manipulated and declared that it has disabled deposits while looking into the matter.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We are currently investigating an incident where a hacker was able to drain funds from Mango via an oracle price manipulation. <br><br>We are taking steps to have third parties freeze funds in flight. 1\/<\/p>&mdash; Mango (@mangomarkets) <a href=\"https:\/\/twitter.com\/mangomarkets\/status\/1579979342423396352?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 11, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>According to data from CoinGecko, the price of the platforms' MNGO token has decreased by about 52% over the past 24 hours as a result of the news of the exploit.<\/p>\n\n\n\n<p>According to the exploiters' account on the network, the three biggest withdrawals totaled $50 million in USD Coin, over $26.7 million in Marinade Staked SOL (mSOL), a Solana staking token, and around $24 million in SOL.<\/p>\n\n\n\n<p>Mango reported that it was withdrawing MNGO worth over $14.7 million and that it is &#8220;taking steps to have third parties freeze monies in flight.&#8221;<\/p>\n\n\n\n<p>According to blockchain security firm Beosin, the QANplatform blockchain also experienced its own <a href=\"https:\/\/coinscreed.com\/staging\/network-and-token-freeze-raises-concerns-after-acala-vulnerability.html\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability <\/a>on October 11 when its Ethereum bridge was drained of roughly $1.89 million worth of its native QANX coin. According to QANplatform, it is looking into the incident.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mango Markets, a decentralized finance (DeFi) exchange based on the Solana blockchain has reportedly suffered a breach of over $100 million as a result of an attacker manipulating price data. By manipulating the value of their Mango (MNGO) native token collateral and then taking out &#8220;large loans&#8221; from Mango Markets&#8217; treasury, the attacker was able [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":37260,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[73,11476],"tags":[6115,197,2156,10732,275],"class_list":["post-37258","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defi-news","category-hacks-and-scams","tag-hackers-2","tag-defi","tag-exploit","tag-mango-markets","tag-solana"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-37.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/37258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=37258"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/37258\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/37260"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=37258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=37258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=37258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}