Crime

DeFi Exploits: How Mango Markets Was Drained in the Eisenberg Case

DeFi Exploits: How Mango Markets Was Drained in the Eisenberg Case

United States v. Avraham Eisenberg tested commodities fraud, market manipulation, wire fraud, decentralized governance, and the legal consequences surrounding a cryptocurrency operation that removed approximately $110 million from Mango Markets.

WASHINGTON — The extraordinary manipulation of Mango Markets demonstrated how decentralized-finance platforms can lose nearly their entire available treasury within minutes when thinly traded governance tokens, automated price oracles, leveraged derivatives, and permissive borrowing systems interact without adequate safeguards.

Avraham Eisenberg used coordinated accounts, substantial purchases of Mango’s MNGO token, offsetting perpetual-futures positions, and rapidly inflated collateral values to withdraw approximately $110 million in cryptocurrency from the Solana-based protocol during October 2022.

Federal prosecutors initially transformed that operation into the United States government’s first criminal prosecution involving cryptocurrency manipulation through open-market trades, securing jury convictions for commodities fraud, commodities manipulation, and wire fraud during April 2024.

However, United States District Judge Arun Subramanian overturned those convictions during May 2025, finding insufficient New York venue for the commodities counts and inadequate proof of a materially false representation supporting the wire-fraud verdict.

The Justice Department subsequently appealed that decision, leaving the landmark prosecution procedurally unresolved while its central facts continue influencing developers, regulators, investors, lawyers, compliance professionals, and decentralized autonomous organizations confronting the meaning of manipulation within automated financial markets.

Mango Markets Combined Trading, Lending, and Governance

Mango Markets operated as a decentralized trading and lending protocol on the Solana blockchain, allowing participants to deposit cryptocurrency, borrow digital assets, exchange tokens, and establish leveraged positions through perpetual futures contracts without using a conventional brokerage.

The protocol’s native MNGO token performed several functions within this ecosystem, including providing governance participation, serving as a traded asset, and supplying reference prices that influenced the valuation of related derivatives and collateral recorded inside customer accounts.

Unlike a traditional exchange employing centralized risk officers, telephone intervention, discretionary credit committees, and established clearing procedures, Mango Markets depended heavily upon software rules, automated liquidations, interconnected smart contracts, external pricing information, and governance decisions made through token voting.

That structure created speed and accessibility, but it also produced an environment where a sufficiently capitalized trader could influence a lightly traded token outside the protocol, transmit that distorted value through an oracle, and immediately borrow against the resulting paper gains.

The Operation Began with Two Controlled Accounts

According to evidence presented during the criminal trial, Eisenberg funded two Mango Markets accounts with approximately $5 million in USD Coin, a dollar-linked stablecoin frequently used for collateral, settlement, lending, and trading across decentralized-finance applications.

One account established a substantial long position in MNGO perpetual-futures contracts, meaning it benefited when the referenced MNGO price increased, while another controlled account accepted the corresponding short side of those transactions.

Because Eisenberg allegedly controlled both sides, the paired positions did not initially represent ordinary market participants independently expressing opposing views; instead, they created enormous derivative exposure between accounts controlled by the same person.

That arrangement positioned one account to report extraordinary gains if MNGO’s oracle price increased dramatically, while losses accumulated within the opposing account whose available collateral limited what the protocol could realistically recover.

Spot Purchases Drove MNGO Sharply Higher

After establishing the derivative positions, Eisenberg purchased significant quantities of MNGO on outside exchanges whose prices contributed information to Mango Markets’ oracle, creating aggressive demand in markets with relatively limited trading depth.

MNGO’s price increased by more than 1,000 percent during an extremely short period, causing the profitable perpetual-futures position to appear extraordinarily valuable even though the price movement arose from concentrated purchases within thin external markets.

The oracle transmitted those elevated prices into Mango Markets automatically, allowing the protocol to calculate enormous unrealized gains and recognize the profitable account as possessing collateral capable of supporting substantial cryptocurrency borrowing.

This interaction exposed a critical distinction between a market price and a dependable liquidation value, because the displayed MNGO valuation could not necessarily support widespread selling once Eisenberg’s concentrated purchasing activity stopped.

Inflated Collateral Opened the Treasury

With the profitable account showing enormous paper gains, Eisenberg borrowed and withdrew stablecoins and other digital assets deposited by Mango Markets users, removing essentially all readily available lending liquidity from the protocol.

The withdrawn assets included tokens possessing established external liquidity and comparatively dependable prices, while the platform retained claims supported by an inflated MNGO position whose value collapsed after the concentrated buying ended.

This transformation allowed volatile, temporarily elevated collateral to be exchanged for approximately $110 million in more liquid cryptocurrency, leaving customers unable to withdraw assets they reasonably believed remained available through the lending platform.

The operation did not require breaking private keys, modifying Mango Markets’ source code, penetrating a server, or forging blockchain signatures, because every transaction passed through functions that the protocol’s software technically permitted.

An Exploit Without Conventional Hacking

Mango Markets therefore became an influential example of an economic exploit, where an attacker manipulates assumptions surrounding pricing, liquidity, leverage, or collateral rather than defeating cryptographic protections or inserting unauthorized programming instructions.

Smart contracts can execute exactly as developers wrote them while still producing disastrous results, particularly when those contracts assume that external prices remain trustworthy, markets remain liquid, and traders behave within conventional economic boundaries.

Eisenberg publicly characterized the transactions as a highly profitable trading strategy conducted according to the protocol’s designed features, advancing a position sometimes summarized within cryptocurrency communities as “code is law.”

Prosecutors rejected that characterization, arguing that deliberate market manipulation does not become lawful merely because an automated protocol processes every transaction without recognizing the trader’s strategy, concentrated control, or ultimate objective.

The Treasury Loss Exceeded Ordinary Trading Damage

The immediate damage extended beyond MNGO traders who knowingly accepted price volatility, because Mango Markets depositors discovered that assets supplied for lending had been withdrawn against collateral whose inflated valuation could not survive liquidation.

Mango Markets consequently faced a treasury and liquidity crisis estimated at approximately $110 million to $116 million, depending on valuation timing, asset prices, and whether calculations described borrowed property, protocol losses, or total cryptocurrency obtained.

A protocol can display sophisticated interfaces and substantial total value locked while remaining vulnerable to one weak collateral market, particularly when its borrowing system grants immediate access to unrelated assets based upon unrealized derivative profits.

The event demonstrated how interconnected DeFi functions can convert a local pricing distortion into a platform-wide insolvency crisis, transferring losses from speculative traders toward lenders, depositors, governance participants, and treasury reserves.

Governance Became Part of the Recovery Negotiation

After the withdrawals, Eisenberg submitted a governance proposal offering to return a substantial portion of the cryptocurrency while retaining approximately $47 million under an arrangement presented as a settlement or exceptionally large bug bounty.

The proposal also sought assurances that Mango Markets would not pursue criminal investigations or request that authorities freeze the remaining assets, placing token voters under extraordinary pressure while much of the platform’s liquidity remained under Eisenberg’s control.

Mango’s decentralized autonomous organization approved the negotiated proposal, after which approximately $67 million was returned, although the vote could not bind federal prosecutors, regulatory agencies, customers, or courts that were not parties to the arrangement.

This episode exposed serious weaknesses within emergency governance because voting power, financial pressure, uncertain legal authority, anonymous participation, and depleted customer funds can prevent a distressed DAO from providing genuinely voluntary and informed consent.

A DAO Vote Could Not Provide Criminal Immunity

Private organizations generally cannot grant immunity from federal prosecution, and a governance proposal executed through token voting possesses no greater authority to prevent the government from enforcing criminal statutes or protecting broader market interests.

The agreement could influence civil claims between specific participants, but prosecutors remained free to investigate whether the underlying transactions violated commodities, wire fraud, money laundering, or other federal laws applicable to the conduct.

Eisenberg’s retention of cryptocurrency after the vote also did not automatically transform the original withdrawals into a lawful bug bounty, particularly because Mango’s existing vulnerability-reward criteria reportedly excluded previously exploited weaknesses and imposed considerably lower compensation limits.

A genuine bug bounty ordinarily involves responsibly disclosing a vulnerability before removing customer property, allowing developers to repair the problem, documenting the discovery, and accepting compensation determined through established program rules.

Federal Authorities Arrested Eisenberg

Federal authorities arrested Eisenberg in Puerto Rico during December 2022, beginning a criminal case that prosecutors framed as an intentional scheme to manipulate cryptocurrency derivatives and fraudulently obtain assets belonging to Mango Markets and its customers.

The Justice Department’s description of the original jury verdict stated that Eisenberg artificially manipulated perpetual-futures prices before using the resulting inflated account value to withdraw approximately $110 million in cryptocurrency.

Prosecutors charged commodities fraud, commodities market manipulation, and wire fraud, relying upon established federal statutes rather than a specialized criminal law written exclusively for decentralized exchanges, smart contracts, governance tokens, or blockchain-based lending.

That approach presented an important enforcement principle because technological novelty does not necessarily prevent prosecutors from applying traditional fraud and manipulation laws when familiar economic misconduct appears through new software infrastructure.

The Government Presented Manipulation as Deliberate

At trial, prosecutors argued that Eisenberg deliberately created offsetting positions, understood MNGO’s limited liquidity, purchased the underlying token to influence oracle prices, and withdrew liquid cryptocurrency before the artificially supported valuation inevitably collapsed.

Evidence reportedly included internet searches, private communications, transaction records, blockchain analysis, trading behavior, and Eisenberg’s public statements explaining that he had operated through the protocol’s available mechanisms.

The government maintained that the coordinated sequence mattered more than any isolated trade because each transaction contributed toward a single strategy designed to manufacture collateral value and drain unrelated assets from the platform.

Eisenberg’s defense countered that Mango Markets was permissionless, operated automatically, contained no applicable prohibition against his strategy, and processed legitimate transactions according to publicly available software rules accepted by every participant.

A Jury Initially Convicted Eisenberg

Following a nine-day trial, jurors convicted Eisenberg during April 2024 upon all three counts, producing what authorities described as the first United States criminal conviction involving cryptocurrency manipulation accomplished through open-market trading.

A Reuters report covering the verdict explained that prosecutors accused Eisenberg of rigging Mango Markets, while the defense maintained that his profitable trades remained lawful and involved no actionable deception.

The verdict initially appeared to establish a powerful precedent against traders who intentionally exploit oracle systems and thin token markets, suggesting that technically valid smart-contract interactions could nevertheless produce criminal responsibility.

That interpretation changed substantially thirteen months later, when Judge Subramanian granted Eisenberg’s post-trial motion and dismantled the verdict through separate findings concerning constitutional venue and insufficient proof supporting the wire-fraud count.

The Court Vacated the Commodities Convictions

The judge concluded that prosecutors had not adequately established venue within the Southern District of New York for the commodities-fraud and commodities-manipulation charges, even though the jury had accepted the government’s theory.

Eisenberg conducted the relevant trading from Puerto Rico, while Mango Markets operated through decentralized blockchain infrastructure without an ordinary headquarters or trading floor located within the district where prosecutors brought the case.

The government relied partly upon connections involving a Mango user in New York and technology associated with external trading activity, but the court determined that those contacts did not establish the constitutionally required connection.

Importantly, the venue ruling did not declare that manipulating MNGO prices was lawful, because it concerned where the government could prosecute particular criminal allegations rather than resolving every substantive question about Eisenberg’s conduct.

The Wire-Fraud Acquittal Reached Deeper Questions

Judge Subramanian entered a judgment of acquittal upon the wire-fraud count after finding insufficient evidence that Eisenberg made a materially false representation capable of supporting that particular criminal conviction.

Mango Markets operated automatically and apparently lacked explicit rules prohibiting price manipulation, requiring repayment, or demanding that borrowers maintain collateral beyond what the protocol’s own calculations accepted when transactions occurred.

The government argued that requesting loans against manipulated collateral implicitly represented that the displayed values were genuine, but the court found insufficient proof of actionable falsity within a permissionless system lacking conventional borrower representations.

That reasoning raised a difficult question extending across decentralized finance: whether interacting strategically with software can constitute deception when no human decision-maker receives a statement and the program mechanically approves conduct its developers failed to prohibit.

The Decision Did Not Validate the Entire Strategy

The 2025 ruling should not be summarized as judicial approval of oracle manipulation, because the court recognized evidence of manipulated pricing while resolving the criminal counts through venue requirements and deficiencies within the prosecution’s specific wire-fraud theory.

Different statutes, contractual terms, jurisdictions, protocol designs, representations, victims, or evidence could produce materially different results, particularly when users conceal identities, circumvent controls, submit false information, or access restricted computer functions.

Developers also cannot assume that omitting written rules automatically transforms every exploit into lawful conduct, since manipulation, commodities, securities, computer-fraud, theft, conspiracy, sanctions, and money-laundering laws may operate independently.

The decision instead illustrated how criminal prosecution requires proof of every statutory element and proper venue, regardless of how damaging, opportunistic, carefully planned, or ethically questionable the underlying transactions may appear.

The Government Appealed the Reversal

Federal prosecutors appealed the post-trial ruling, preserving an opportunity for appellate judges to examine the venue analysis, wire-fraud reasoning, and legal treatment of automated interactions within decentralized financial protocols.

As of July 2026, the appeal means the criminal case’s most consequential legal conclusions should not be described as permanently settled, because an appellate decision could affirm, modify, or reverse important portions of the district court’s judgment.

The procedural history consequently contains both a unanimous jury verdict and a subsequent judicial reversal, requiring accurate reporting that distinguishes allegations, proven trial facts, vacated convictions, acquittal, civil claims, and continuing appellate proceedings.

Reporting only the 2024 conviction would materially misrepresent Eisenberg’s present legal status, while reporting only the reversal would conceal the extensive trial, jury findings, admitted trading strategy, and government’s unresolved appellate challenge.

Regulators Pursued Parallel Civil Cases

The Commodity Futures Trading Commission alleged that Eisenberg used manipulative and deceptive conduct involving swaps to misappropriate more than $110 million, while the Securities and Exchange Commission separately characterized MNGO as a security offered and sold within the protocol.

Those civil proceedings raised regulatory questions distinct from the criminal prosecution, including whether MNGO tokens constituted securities, whether the perpetual contracts qualified as swaps, and whether Eisenberg violated market-manipulation provisions enforced under lower civil proof standards.

A criminal acquittal or vacated conviction does not automatically eliminate civil liability because regulatory cases can involve different statutes, legal elements, remedies, evidentiary standards, jurisdictions, and classifications of the relevant digital assets.

The overlapping actions nevertheless demonstrate regulatory fragmentation, since the same blockchain operation supported allegations involving commodities, swaps, securities, wire fraud, market manipulation, and misappropriation across several federal enforcement authorities.

Oracle Design Created the Operational Vulnerability

A price oracle supplies blockchain applications with information originating outside their native smart contracts, allowing lending protocols and derivatives platforms to determine collateral values, trading profits, liquidation thresholds, and account health.

If an oracle relies upon thin markets, short averaging periods, limited venues, or easily influenced spot prices, a determined trader can spend millions purchasing one asset and create substantially greater artificial borrowing capacity elsewhere.

Mango Markets’ vulnerability arose because the protocol treated the dramatically rising MNGO price as dependable collateral information without sufficiently accounting for market depth, concentration, manipulation cost, or probable liquidation value.

A secure oracle system must evaluate not only the most recently reported price, but also whether enough genuine liquidity exists to sell the collateral if a borrower immediately withdraws every available asset.

Liquidity Matters More Than a Screen Price

A token might display a market capitalization worth hundreds of millions of dollars while supporting only a small quantity of genuine trading, making the headline valuation unreliable when a large holder attempts to sell.

Collateral policies should therefore examine order-book depth, daily turnover, holder concentration, exchange diversity, price impact, volatility, oracle confidence, and historical stress behavior before granting substantial borrowing capacity.

Mango Markets effectively allowed temporary MNGO appreciation to support withdrawals involving stablecoins and established cryptocurrencies possessing far deeper external liquidity, creating a mismatch between fragile collateral and immediately transferable loan proceeds.

Once the concentrated purchases stopped, the protocol could not liquidate the inflated position near its recorded value, leaving a deficit that automated software recognized only after customers’ liquid assets had already departed.

Risk Controls Must Limit Concentrated Positions

Decentralized lending platforms can reduce exposure by imposing borrowing caps, collateral limits, open-interest ceilings, position concentration rules, dynamic margin requirements, and withdrawal delays triggered by abnormal price movements.

Circuit breakers can temporarily suspend borrowing when an asset appreciates beyond defined thresholds, while time-weighted price calculations may reduce the influence of brief trading bursts occurring across shallow external markets.

Protocols should also simulate adversarial behavior, asking how much capital an attacker would need to move a supported asset and how much unrelated cryptocurrency could be extracted before liquidation systems responded.

Risk modelling must assume that sophisticated participants will combine every permitted feature strategically, rather than evaluating trading, lending, collateral, oracle, governance, and withdrawal functions as isolated products.

Automated Systems Still Require Human Judgment

DeFi advocates sometimes describe smart contracts as eliminating intermediaries, although every protocol still incorporates human decisions concerning code, oracle selection, collateral eligibility, leverage, governance authority, emergency powers, and software upgrades.

Those decisions can remain hidden behind technical complexity, creating an impression of mathematical neutrality even when developers have selected assumptions that transfer substantial risk toward depositors and governance participants.

Mango Markets demonstrated that software cannot independently determine whether an unusual profitable strategy represents legitimate price discovery, economic manipulation, malicious exploitation, or behavior requiring emergency intervention.

Human governance remains necessary, but emergency authority must be transparent, limited, secured, and accountable so insiders cannot abuse protective controls for censorship, self-dealing, selective liquidations, or unauthorized asset transfers.

DAO Governance Can Become Coercive During Crises

The post-exploit vote showed how decentralized governance may become vulnerable when one participant controls assets desperately needed for customer repayment and conditions their return upon approval of favorable terms.

Token holders voting under severe financial pressure may accept an arrangement they would reject under ordinary circumstances, particularly when alternatives include prolonged litigation, uncertain recovery, additional price collapse, and permanent platform failure.

Governance systems should establish incident-response procedures before losses occur, including independent negotiators, legal representation, conflict disclosures, quorum protections, voting exclusions, emergency committees, and clearly defined authority for recovering misappropriated property.

Without predetermined rules, a blockchain vote may provide visible procedural legitimacy while concealing concentrated influence, inadequate information, limited participation, financial coercion, and uncertainty concerning whether the resulting agreement remains legally enforceable.

Bug Bounties Cannot Replace Responsible Disclosure

Generous bug-bounty programs encourage researchers to report vulnerabilities before criminals exploit them, giving developers an opportunity to protect customer assets while appropriately rewarding valuable security discoveries.

However, allowing exploiters to drain a platform and negotiate afterward creates a destructive incentive structure in which attackers can demand enormous compensation while threatening depositors with otherwise irreversible losses.

Protocols should publish eligibility requirements, maximum rewards, disclosure procedures, testing limitations, prohibited conduct, safe-harbor terms, and consequences for moving assets beyond controlled demonstration amounts.

Researchers should obtain written authorization whenever testing could affect customer property, because assuming that permissionless software authorizes unlimited adversarial experimentation can create civil, criminal, contractual, and reputational consequences.

Investors Must Evaluate Economic Security

Traditional code audits examine whether smart contracts contain programming errors, access-control weaknesses, re-entrancy vulnerabilities, or unexpected execution paths, but technically correct software can remain economically unsafe.

Investors should examine whether token prices can be manipulated cheaply, whether collateral can be liquidated during volatility, whether borrowing limits reflect genuine liquidity, and whether oracle failures could spread across interconnected markets.

They should also investigate administrator powers, upgrade controls, multisignature arrangements, insurance resources, treasury diversification, governance concentration, incident history, audit scope, and procedures governing emergency suspension.

A protocol advertising completed audits should clarify whether reviewers evaluated only source-code correctness or also tested economic incentives, price dependencies, liquidity assumptions, governance attacks, and coordinated market manipulation.

Cross-Border Planning Requires Verifiable Assets

Individuals and businesses using decentralized finance for legitimate international activity should maintain transaction histories, wallet records, acquisition costs, tax calculations, ownership evidence, and source-of-funds documentation capable of surviving regulatory or banking review.

Responsible cross-border asset protection and international planning require transparent beneficial ownership, consistent identification, lawful taxation, reputable counterparties, and structures designed to preserve assets without misleading financial institutions or governmental authorities.

A profitable blockchain transaction may still trigger litigation, compliance restrictions, tax obligations, sanctions screening, or asset-freezing requests, particularly when funds originate from compromised protocols, mixers, exploits, or wallets identified through enforcement investigations.

Users should never assume that pseudonymous addresses eliminate accountability, because public ledgers permanently record movements that investigators can connect with exchanges, devices, communications, bank accounts, internet records, and identifiable counterparties.

Privacy Is Different from Exploit Concealment

Financial privacy can legitimately protect individuals from identity theft, harassment, commercial espionage, political persecution, or unnecessary public exposure while preserving accurate records for institutions possessing lawful verification rights.

Lawful privacy and international risk-management services should create defensible documentation, reliable succession arrangements, compliant ownership structures, and coherent financial histories rather than mechanisms intended to obscure stolen or manipulated assets.

Moving exploit proceeds across wallets, blockchains, exchanges, bridges, or privacy services does not erase their origin, while every additional transaction can provide investigators with timing evidence, counterparties, service records, and operational mistakes.

The strongest privacy planning reduces unnecessary exposure without producing contradictory identities, false declarations, concealed beneficial ownership, fabricated transactions, or unexplained wealth likely to collapse during institutional examination.

The Case Changed DeFi Enforcement

United States v. Avraham Eisenberg became important because it forced courts and prosecutors to translate manipulation doctrines developed for human-operated markets into an environment where algorithms execute loans automatically, and participation may occur without written agreements.

The jury initially accepted the government’s argument that familiar fraud and market-manipulation principles could govern sophisticated blockchain conduct, but the district court’s reversal demonstrated that conventional criminal elements cannot be presumed merely because substantial losses occurred.

The pending appeal will influence how prosecutors frame future cases, particularly when establishing venue, identifying implicit representations, proving deception against automated systems, and distinguishing aggressive trading from unlawful manipulation.

Future enforcement actions will probably rely more heavily upon explicit platform rules, evidence of concealed coordination, false identity information, technical circumvention, communications proving intent, and precise connections between charged conduct and the chosen judicial district.

The Enduring Warning from Mango Markets

Mango Markets lost approximately $110 million not because blockchain cryptography failed, but because its economic design allowed a concentrated trader to manufacture collateral value faster than risk controls could measure, challenge, or contain it.

Eisenberg’s strategy demonstrated that permissionless markets remain governed by consequences extending beyond their source code, including commodities regulation, securities litigation, criminal procedure, civil recovery, contractual disputes, governance legitimacy, and customer expectations.

The overturned convictions simultaneously show that devastating economic harm does not relieve prosecutors of the need to prove proper venue, materially false representations, statutory coverage, criminal intent, and every other element required under federal law.

For developers, the lesson involves stronger oracles, borrowing caps, liquidity-adjusted collateral, adversarial simulations, circuit breakers, and emergency governance, while investors must investigate whether a protocol can survive coordinated behavior that its interface technically allows.

For regulators and courts, the unresolved case represents a continuing test of whether existing financial laws can address decentralized manipulation without stretching statutory language beyond constitutional limits or treating every unexpected algorithmic outcome as criminal fraud.

The central conclusion remains unmistakable: decentralized software can remove intermediaries from transaction execution, but it cannot remove economic incentives, legal accountability, governance failures, market manipulation, or the need for disciplined human judgment.