The most uncomfortable entry on the list, because there is no vulnerable line to show you. The attacker funded two accounts, took both sides of a huge MNGO perpetual trade against himself, and pushed the mark price of a token with a few hundred thousand dollars of real depth up more than 1,000% in about twenty minutes. Mango's risk engine did exactly what it was written to do: it valued his position at the oracle price and let him borrow $115M against it. He then walked away and argued publicly that it was a legitimate trading strategy. The jury disagreed; a judge later overturned the conviction.
// The risk engine, faithfully implemented: collateral_value = position_size × oracle_price(MNGO) └── a token with ~$200k of real depth on a market the borrower can move himself // ❌ What was missing was not a check — it was a limit: · no cap on how much of one account's collateral may be a single illiquid asset · no borrow cap scaled to the asset's real market depth · no confidence / deviation band on the oracle price · no time-weighting to make a 20-minute pump economically useless → the contract never malfunctioned. the economic model did.
Entries in the SAFE database that describe this failure. The first ones name this incident directly.
Every figure on this page comes from the post-mortems above, not from us. Losses are US dollars at the time of the incident.
Oracle manipulation is one of the 203 classes the SaferICO scanner checks for. It will not review your signing process — but it will read your Solidity.