Mango Market遭受攻击,损失1.16亿美元

CertikPublished on 2022-10-13Last updated on 2022-10-13

Abstract

北京时间2022年10月11日6:19,CertiK Skynet天网监测到Mango Market遭到黑客攻击,截至目前已损失1.16亿美元。

北京时间2022年10月11日6:19,CertiK Skynet天网监测到Mango Market遭到黑客攻击,截至目前已损失1.16亿美元。攻击者操纵MNGO代币的价格,并恶意借贷超出应有数额的资产——攻击者使用两个地址操纵Mango代币和MNGO的价格,将其(Mango Market里面的市场价格)从0.038美元抬升至0.91美元。这使得攻击者可以利用MNGO大举借贷,最终导致约1.16亿美元的损失,不过,由于项目价格受到影响,这个数字正在波动。

攻击步骤

① 在此交易中,攻击者向第一个账户(CQvKSNn...)提供了500万枚USDC。

② 攻击者在订单簿中提供了4.83亿单位的MNGO perps(做空)。

③ 之后攻击者向第二个账户(4ND8FVPjU...)注资。

④ 然后以每单位0.0382美元的价格做多了4.83亿单位的MNGO perps。

⑤ 攻击者通过操纵价格预言机上MNGO的价格(在Mango Market里面的市场价格),将其拉高到0.91美元,从而在第二个账户上获利。

⑥ 由于MNGO/美元的价格为每单位0.91美元(在Mango Market里面的市场价格),第二个账户能够在Mango Market上借用其他代币。攻击者还用第二个账户中的资金(原始存款+将借贷的MNGO资金出售所得)在Mango Market上借入其他代币。

⑦ 上述借款行为使第一个账户的坏账总额为11,306,771.61美元,造成了115,182,674.43美元的资产损失。

除此之外,攻击者似乎已经与社区取得联系,在Mango DAO论坛的这篇帖子中提交将代币发回的建议:https://dao.mango.markets/dao/MNGO/proposal/3WZ5DpZXDvNAK4JwPS1HDPzSinEJUGpBC4XXx9vPtnVS

漏洞分析

攻击者操纵了价格预言机中Mango代币的价格。

例如其中一个价格预言机Switchboard使用的是FTX和Raydium提供的价格。Raydium(https://solscan.io/account/34tFULR...)的流动性极低,易于操作。

写在最后

此次攻击一部分原因源自MNGO/USDC市场的流动性不足,但今年3月时,这个确切的攻击向量已在在Mango Market的Discord频道中被提出。

目前Mango Market在推特上回应,呼吁用户避免与平台互动,并采取行动禁用存款。

Trending Cryptos

Related Reads

Chip Stocks Lead U.S. Market Decline: Is AI Trading Being Hit by Both Interest Rates and Returns?

Chip stocks led a broad decline in US markets, with the Nasdaq dropping 2.2% and the S&P 500 falling 1.4%. This selloff reflects a dual challenge for the once-high-flying AI hardware trade: rising interest rate expectations and growing investor impatience for clear returns from massive AI capital expenditures. The pressure was most acute on hardware leaders. Nvidia fell about 4%, dipping below a $5 trillion market cap, while Micron plunged 13.2% ahead of its earnings report. Declines across memory, storage, AI, and mobile chips indicated a sector-wide retreat. The selloff spread globally, with South Korea's KOSPI index dropping nearly 10% as key suppliers SK Hynix and Samsung recorded double-digit losses. Investors appeared to be taking profits from the most crowded trades first. Macro headwinds intensified as market expectations shifted toward a more aggressive Federal Reserve. Forecasts for multiple rate hikes in 2026 pressured high-valuation tech stocks, which rely on long-term growth projections that become less attractive as discount rates rise. Concurrently, investors are scrutinizing the profit potential of the immense AI spending by cloud giants like Alphabet, Amazon, and Meta. While these expenditures drive demand for chips and hardware, the market is now questioning whether AI services will generate sufficient returns to justify the ongoing costs. This adjustment is not necessarily a bubble burst but a recalibration. AI demand fundamentals remain, but the narrative of endless growth can no longer fully offset concerns over higher interest rates and a longer path to profitability. Near-term direction may hinge on Micron's upcoming earnings guidance and incoming inflation data, which will influence both the AI demand outlook and the Fed's policy path. The market is transitioning from blindly buying growth to demanding clearer visibility on returns.

marsbit56m ago

Chip Stocks Lead U.S. Market Decline: Is AI Trading Being Hit by Both Interest Rates and Returns?

marsbit56m ago

OpenAI's New Paper: How to Train an AI that "Doesn't Deteriorate Under Pressure"?

OpenAI's new paper "Reinforcement Learning Towards Broadly and Persistently Beneficial Models" explores training AI to maintain safe, helpful, and honest behavior even under pressure, in unseen scenarios, or after being fine-tuned for harmful purposes. Moving beyond simple rule-based "don'ts," the research focuses on cultivating "beneficial traits" like honesty, risk-awareness, corrigibility, and transparency. It investigates if reinforcement learning (RL), often prone to "reward hacking" where models exploit loopholes, can instead be used to instill robust, generalized positive behaviors. Researchers created a multi-domain synthetic dialogue dataset covering areas like healthcare and law. They trained a model by replacing 5% of standard RL data with "beneficial trait" data. This model outperformed the baseline in 83% of 53 evaluations, showing average gains of 9.1% in alignment, safety, and helpfulness. Crucially, improvements generalized: a model trained only on healthcare "good behavior" data also performed better in 17 out of 19 non-healthcare alignment tests. The paper also tests "alignment persistence." When subjected to adversarial prompts or harmful fine-tuning, the beneficial trait model showed greater resilience, with smaller performance drops and less "spillover" of bad behavior to unrelated tasks. While not a complete solution, this work suggests a shift from post-hoc correction to proactively shaping robust, principled AI behavior, a critical step for deploying models in high-stakes, complex decision-making scenarios.

marsbit59m ago

OpenAI's New Paper: How to Train an AI that "Doesn't Deteriorate Under Pressure"?

marsbit59m ago

Semiconductor Stock Rebound: Is the Technical Correction Over or a Trend Reversal?

The core of recent semiconductor stock volatility is not about daily price swings, but rather the market questioning whether AI-driven semiconductor pricing has entered a new phase. Following a sharp sell-off in Korean stocks on June 23rd, led by Samsung and SK Hynix, a subsequent rebound is seen more as a technical positioning adjustment rather than a confirmed trend reversal. The key variable is HBM (High Bandwidth Memory), essential for AI chips. Its supply-demand imbalance granted memory makers significant pricing power. The current market focus is on whether this dynamic remains strong enough to justify elevated valuations. All eyes are on Micron's upcoming earnings report. The critical factor is not whether results meet already high expectations, but whether the company's guidance confirms that AI memory pricing power, order visibility, and future margins are still expanding. Micron's outlook will serve as a crucial test for the broader AI semiconductor chain, including Samsung, SK Hynix, and other infrastructure players. The recent bounce appears to be a pre-earnings positioning repair. For it to evolve into a sustained uptrend, concrete evidence is needed that the AI infrastructure expansion cycle's fundamentals—particularly for high-end memory—remain robust and can continue to surpass elevated market expectations. The risk is that strong demand alone may not be sufficient if future guidance hints at peaking momentum or increasing supply-side pressures.

marsbit1h ago

Semiconductor Stock Rebound: Is the Technical Correction Over or a Trend Reversal?

marsbit1h ago

Trading

Spot
Futures

Hot Articles

What is USDC(WORMHOLE)

USD Coin (Wormhole): A Comprehensive Overview Introduction In the rapidly evolving world of cryptocurrencies, USD Coin (Wormhole), referred to as $USDC(Wormhole), stands out as a pioneering solution within the DeFi (Decentralized Finance) landscape. Operating on several blockchain platforms, including Solana, USD Coin (Wormhole) is more than just a digital representation of the United States dollar. It embodies the innovative spirit of modern finance, enabling seamless cross-chain transactions and enhanced interoperability among diverse blockchain ecosystems through the advanced Wormhole protocol. What is USD Coin (Wormhole)? USD Coin (Wormhole) is a tokenized version of the US dollar designed to facilitate frictionless transactions across different blockchain networks. Its primary aim is to bolster liquidity and enhance the functionality of the DeFi ecosystem. By leveraging the Wormhole protocol, which establishes a robust cross-chain communication network, users can effortlessly transfer USDC tokens across various platforms. This cross-chain capability marks a significant advancement in cryptocurrency use, promoting a more interconnected and efficient ecosystem where assets can flow freely between different blockchains. The value proposition of USD Coin (Wormhole) lies not only in its stability, being pegged to the US dollar, but also in its ability to bridge gaps between disparate blockchain environments. This innovative approach fosters a greater level of participation among users and developers, paving the way for new and exciting applications within decentralized finance. Who is the creator of USD Coin (Wormhole)? The origins of USD Coin (Wormhole) are intricately tied to the Wormhole network, which was developed by Jump Crypto. While specific individual creators are not prominently documented, Jump Crypto is notable for its involvement in advancing blockchain technology and supporting its applications in finance. By creating the Wormhole network, Jump Crypto has played a vital role in promoting cross-chain asset transfers, enhancing the efficiency and diversity of cryptocurrency usage. Who are the investors of USD Coin (Wormhole)? The success of USD Coin (Wormhole) is supported by investments from several notable funds and organizations within the cryptocurrency realm. Key investors include: Coinbase Ventures: A prominent venture capital arm backed by one of the leading cryptocurrency exchanges in the industry, Coinbase Ventures provides essential capital and strategic support to promising blockchain projects. Arrington XRP Capital: Specializing in digital assets, Arrington XRP Capital recognizes the potential of innovative projects like USD Coin (Wormhole) and has invested accordingly to back its development. Jump Trading: As the parent organization of Jump Crypto, Jump Trading brings not only investment but a wealth of expertise in trading technology and market dynamics to bolster the Wormhole project. How Does USD Coin (Wormhole) Work? The operational framework of USD Coin (Wormhole) is intricately designed to facilitate effective cross-chain transactions, maximizing security and efficiency. Here’s a simplified overview of how it functions: Asset Locking: When a user wishes to transfer USDC from one blockchain to another, they first lock their tokens on the source blockchain. This process ensures that the assets are secure and are set to be either burned or moved later. Token Minting: After the tokens are locked, an equivalent amount of USDC is minted on the destination blockchain. This provides the user with access to their funds on a new platform, reflecting the flexibility that the Wormhole protocol enables. Cross-Chain Transfer: The Wormhole protocol efficiently facilitates the entire transfer process. It ensures that once the USDC is minted on the destination chain, the equivalent tokens are burned on the source chain. The result is a seamless transfer of value between two distinct blockchain environments. This cross-chain methodology ensures that transactions remain secure and transparent, significantly enhancing liquidity within the different DeFi ecosystems. Timeline of USD Coin (Wormhole) Understanding the evolution of USD Coin (Wormhole) provides vital context for its significance in the cryptocurrency arena. Here’s a timeline highlighting important milestones in the project’s history: 2021: The Wormhole project is launched, establishing a framework for cross-chain asset transfers and setting the stage for the development of USD Coin (Wormhole). 2022: The Wormhole network experiences a significant challenge with a security breach that results in a $325 million theft. However, the incident is later addressed and refunded by Jump Crypto, showcasing the project’s commitment to security and transparency. 2023: USD Coin (Wormhole) integrates with Circle’s Cross-Chain Transfer Protocol (CCTP), enhancing its capabilities for cross-chain transfers and further solidifying its place within the DeFi ecosystem. 2024: Ongoing development and expansion of the Wormhole network continue, aimed at increasing the utility and reach of USD Coin (Wormhole) as well as enhancing its operational framework. Key Features The success of USD Coin (Wormhole) can be attributed to several key features that differentiate it from other cryptocurrency offerings: Cross-Chain Interoperability At the core of USD Coin (Wormhole) is its ability to facilitate seamless transfers across multiple blockchain networks. This interoperability serves as a cornerstone for decentralized finance, allowing various platforms to interact with each other, thereby accelerating the evolution of financial services. Security Wormhole employs a well-designed Guardian Network comprised of node validators that ensure secure cross-chain transactions. This collective oversight minimizes the risk of fraud and provides users with confidence that their assets are protected during cross-chain transfers. Liquidity Enhancement By enabling USDC to circulate freely across different blockchains, USD Coin (Wormhole) enhances liquidity in the DeFi ecosystem. This increased liquidity can foster more efficient trading, contribute to better pricing strategies, and improve the overall market dynamics encompassing various digital assets. Conclusion USD Coin (Wormhole) is a pivotal innovation in the blockchain space, reinforcing the capabilities of decentralized finance (DeFi) and establishing a more connected financial ecosystem. With its robust framework for cross-chain transactions, security features, and strong backing from reputable investors, USD Coin (Wormhole) is positioned to play a key role in the future of cryptocurrency. As the digital finance landscape continues to evolve, USD Coin (Wormhole) not only embraces the future of interconnectivity among blockchain networks but also reaffirms the power of tokenization and blockchain technology in transforming how we perceive and utilize value in a digital world. By navigating the complexities of cross-chain functionality, it demonstrates a sophisticated approach to enabling financial inclusivity and innovation in the world of cryptocurrencies.

1.2k Total ViewsPublished 2024.04.01Updated 2024.12.03

What is USDC(WORMHOLE)

What is $USDC

Classic USDC: A Comprehensive Overview Introduction to Classic USDC In the rapidly evolving landscape of the cryptocurrency market, stablecoins have emerged as critical components, particularly in providing stability amid the volatility that characterizes digital assets. One such project is Classic USDC, a digital currency initiative that aims to deliver a stable and reliable medium of exchange. By maintaining a 1:1 peg with the US dollar, Classic USDC strives to offer users a dependable digital asset, equipped for various applications within the web3 and cryptocurrency ecosystems. What is Classic USDC? Classic USDC is fundamentally a stablecoin, which is a type of cryptocurrency designed to minimize the price volatility typically seen in the digital asset market. Specifically, Classic USDC aspires to represent the value of the US dollar closely, ensuring that users can leverage this digital currency for transactions, savings, and other financial activities without the fear of sudden price fluctuations that can otherwise plague many cryptocurrencies. The primary aim of Classic USDC is to provide a reliable and trustworthy digital equivalent of the US dollar, designed for seamless integration into a wide range of web3 applications, decentralized finance (DeFi) platforms, and other crypto-related financial systems. By delivering a stable digital currency, Classic USDC seeks to facilitate everyday commerce, make blockchain technology more user-friendly, and encourage the adoption of cryptocurrencies for mainstream usage. Creator of Classic USDC The identity of the creator or the development team behind Classic USDC remains largely unknown, and the lack of transparency has led to a degree of uncertainty regarding the project’s origins. While many cryptocurrency initiatives prominently showcase their founders and development teams, Classic USDC does not provide clear information about its creators, which poses challenges for potential users or investors weighing the project's credibility and reliability. Investors of Classic USDC Alongside the ambiguity surrounding its creators, Classic USDC also lacks specificity with regards to its investors. The financial backing of a project can often lend it credibility and stabilize its operations; however, the absence of documented investment foundations or organizations supporting Classic USDC raises questions about its funding structure. This lack of clarity could potentially hinder stakeholder confidence in the project. How Does Classic USDC Work? The operational mechanics of Classic USDC rely heavily on its reserve system, which is fundamental to the underpinnings of any stablecoin. Classic USDC undertakes to maintain a reserve of assets that directly correspond to the value of the digital currency in circulation. Specifically, for every Classic USDC token issued, an equivalent amount of backing assets is retained in reserve, whether in cash or near-cash equivalents. This strategy is designed to uphold the value of Classic USDC, offering reassurance to users that redeeming their tokens for US dollars is feasible at any time. This reserve structure aims to enhance the stability and reliability of Classic USDC, positioning it as a secure alternative in the cryptocurrency market. By ensuring that the value of Classic USDC is consistently correlated with the US dollar, the project aspires to engender trust among users who may be wary of the broader market dynamics. Timeline of Classic USDC The history of Classic USDC is marked by several key milestones that reflect its journey and evolution within the cryptocurrency ecosystem: 2021: The inception of Classic USDC is noted, introducing a new digital currency option designed for stability. During this year, the first records of the token’s activity surfaced and its initial price levels were established. 2024: Classic USDC begins to experience notable price fluctuations, as the crypto market overall grapples with various trends and user sentiment. Predictions regarding its future potential emerge, indicating a strong interest from market observers and analysts who foresee growth opportunities. Future Projections Experts speculate that Classic USDC may reach higher levels of adoption and stability in the years to come, with potential further developments anticipated around 2025 and 2026. However, these projections should be approached with cautious optimism, as the cryptocurrency market is inherently unpredictable, and various external factors may influence the trajectory of Classic USDC. Key Points About Classic USDC Stability: Classic USDC’s core proposition revolves around providing a digital currency that parallels the value of the US dollar, thereby ensuring stability in an often volatile marketplace. Reserve System: The project’s commitment to maintaining a reserve of assets to back its value underscores its reliability and operational soundness. Web3 and Crypto Integration: Classic USDC is engineered to facilitate easy integration within various applications, aiming to enhance the user experience and broaden the acceptance of cryptocurrency in everyday transactions. Future Growth Potential: While still emerging, Classic USDC holds prospective avenues for growth as awareness and utilization of stablecoins increases in the web3 and crypto contexts. Conclusion Classic USDC presents itself as a notable stablecoin initiative within the cryptocurrency sphere, striving to provide users with a reliable digital currency that embodies the stability of the US dollar. Despite uncertainties regarding its creators and financial backing, the underpinning principles of Classic USDC—centered on reserve-backed assurances—endeavour to position it as a trustworthy option for individuals and businesses navigating the digital economy. With an eye towards the future, market analysts are keen to observe how Classic USDC evolves in response to the shifting dynamics of the cryptocurrency landscape, potentially establishing itself as a significant player in the realm of stablecoins.

638 Total ViewsPublished 2024.05.01Updated 2024.12.03

What is $USDC

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of USDC (USDC) are presented below.

活动图片