Live data from Hacker News

Hackers drain $100M off Solana-based DeFi platform Mango Markets

p2eanalytics.com

81–90 of 105 posts

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#81
post #13

This attack was interesting because it's an economic, not software hack. https://twitter.com/joshua_j_lim/status/1579987648546246658?... is the source overview. The software all worked as expected, and it's difficult to see exactly which step you'd go "no, the person shouldn't have done that". Arguably the fault is with the loan protocols that valued collateral at the instant spot price rather than some kind of time-…

The person shouldn't be able to wash trades, that's the core of this "hack".

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#82

Hate to be that guy, but someone has to say it... In this case the code worked as expected and the "attacker" played within the rules of the game. Except they "won" too much. That's not supposed to happen.

"As expected" is doing a lot of lifting here. In some sense, this is true for all hacks. The code is just doing what you told it to do when it returns to some gadget in libc after the return address is smashed.

All exploits are making a program do what it says it does but where that behavior is different than what the developers hoped it would do.

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#83
post #2

This time it's one of Solana's largest DeFi protocols. Are these guys asleep at the wheel? I wonder if these hacks can ever be fully prevented.

Not sure this is the case in this hack but many of these hacks are related to human error.

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#84

"Then, he/she used the funds to buy the 483mm units of $MNGO perps (at a price of $0.0382 per unit). The perpetrator’s actions made $MNGO’s spot market price, reaching as high as $0.91" Is the second sentence sentence missing some words? Or is there something specific about Mango that makes this make sense? If 483mm units were bought for $0.0382 per unit (is that the average price, a fixed price?), why did the spot p…

First question: yes, the missing part is that the attacker also had to buy a bunch of spot mango tokens on centralized exchanges to drive the price up after establishing the large position. Second question: Mango Markets lets you trade perpetual futures with leverage, so you don't need collateral equal to the notional value of the contracts you buy.

Okay, let me see of I got this right.

User acquires an/a set of in perpetuity futures contracts. (A future without an expiry date, effectively, what? A pin I guess?) Idea being, this order indicates intent to swap at volume $MNGO to $USDC at $RATE.

Centralized exchanges sees the futures order, and starts cranking up the price of $MNGO due to the increased interest in swapping based on the presence of the Futures.

The Futures contracts are leveraged, but require no collateral, because there is no expiry date on the Future (no intended date of delivery).

So the order volume (spot token purchases) induced upward price movement and... What? Caused other uninvolved investors to buy his acquired tokens at a peak, and he just takes the money and cashes out never intending to actually honor or settle up the perps, which won't margin call, because they're still "good" but will never mature? I'm failing to see an exfil path for ill-gotten gains/financial chicanery beyond the seemingly obvious wash trading.

If anyone can help detangle this, I'd be much obliged. This kind of market weirdness is interesting, but inscrutable at times, when there's usually like 6 pieces of networked jargon needed to render something that doesn't tend to line up to anything tangible in the conventional sense.

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#86
post #32
post #15

"According to Lim, the hacker funded the main account (account A) and offered 483mm units of $MNGO perps on the order book. The attacker then funded a second account (account B) with 5mm $USDC collateral. Then, he/she used the funds to buy the 483mm units of $MNGO perps (at a price of $0.0382 per unit). The perpetrator’s actions made $MNGO’s spot market price, reaching as high as $0.91. $MNGO/USD price of $0.91 per u…

> Nothing above looks illegal. In regulated markets, if something went from $0.03 to $0.91 in a short space of time, trading would be shut down. Because the attacker owns both wallets, this is called a wash trade, which is something that has been illegal for over 80 years .

As if wash trades aren't rampant on crypto exchanges. I suspect crypto exchanges are using wash trades to prop up the entire house of cards.

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#87
post #54

Code is law working out real well over here. The code said that we should value MNGO at the current spot price, so that's what the code did, and poof went the entire network. In the real world we have things like leverage ratios, anti-manipulation laws, circuit breakers, etc. Some of this is regulatory, and others are just things we figured out were good ideas many years ago. I think there's a sense of hubris in the…

Playing devil's advocate here, since I'm generally of your opinion: there is nothing that prevents more code being written covering more unintended uses of the technology, including injuctions and reversals. If at all, there is a hubris that complex problems can be solved with clean, minimal code and simple concepts. After all, when rendering their decisions, human courts are also solely refering to rules written bef…

The problem is that a lot of these problems are only solvable within the network. Sure, if you steal a bunch of Ethereum, there could be a piece of code to reverse that theft under some conditions. But if you've cashed out, there's nothing the code will do. The code is only law within the tiny walled garden they've built. So not only do you have to improve the code, but you either need to prevent people leaving this walled garden so you can enforce your rules, or you create rules outside of the walled garden - which are called laws and the entire reason crypto exists was to evade those laws in the first place.

That's why these hacks are so often associated with Bridges - because the bridges are the locations where two different sets of rules are in force and you can exploit the difference between them.

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#88
post #54

Code is law working out real well over here. The code said that we should value MNGO at the current spot price, so that's what the code did, and poof went the entire network. In the real world we have things like leverage ratios, anti-manipulation laws, circuit breakers, etc. Some of this is regulatory, and others are just things we figured out were good ideas many years ago. I think there's a sense of hubris in the…

Playing devil's advocate here, since I'm generally of your opinion: there is nothing that prevents more code being written covering more unintended uses of the technology, including injuctions and reversals. If at all, there is a hubris that complex problems can be solved with clean, minimal code and simple concepts. After all, when rendering their decisions, human courts are also solely refering to rules written bef…

So in the end, we end up with the same system of regulation, only enforced in code.

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#89
I think the really great thing about this hack, is this platform is governed by a DAO. Apparently, the person who pulled this heist ended up with enough governance tokens that they could propose something to do the DAO along the lines of "I'll send you a bit of money back if you say you won't call the cops" and was able to vote for it themselves with 32million votes. https://dao-beta.mango.markets/dao/MNGO/proposal/3WZ5DpZXDvN...

Re: Hackers drain $100M off Solana-based DeFi platform Mango Markets

#90

Earlier quoted context omitted.

its a statement to focus on the system design of the organizations that got hacked instead of the asset/platform they happen to use, just like we do with non-crypto organizations

The platform that an organization uses is a critical piece of the design of an organization. If a bank gets hacked because they’re running Windows 95, would don’t turn around and absolve them of liability. And if an organization uses an anonymous, immutable platform that makes it vulnerable to manipulation and theft, well then they deserve every bit of criticism.

Sounds more like you could use a news service that made headlines about all the protocols and contracts that aren’t hacked

It is vastly larger in volume

Post reply on HN