MangoFarmSOL hack — January 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 6, 2024 |
| Target type | Other |
| Loss | $1,320,000Published estimates range $1,320,000 to $2,000,000Price at time of incident |
| Method | Rug pull or exit scamOperators withdrew all SOL held in the farming contract on behalf of depositors, then served a malicious frontend disguised as an 'EmergencyMigration' that induced users to sign further transfers. |
| Chains | Solana |
| Outcome | Unresolved |
What happened
MangoFarmSOL was a Solana yield-farming pool that took SOL deposits and promised depositors an airdrop of a MANGO token scheduled for 10 January 2024. From 3 January it used social-media KOL promotion to build credibility and attract users, and its TVL passed $1.3 million. Despite the similar name, no connection to the Mango Markets protocol has been established.
On 6 January 2024 the operators emptied it. CertiK's investigation found 13,512 SOL, about $1.26 million at the time, withdrawn from user deposits held in the project contract to the address 8ggviFegLUzsddm9ShyMy42TiDYyH9yDDS3gSGdejND7, in transfers of 135 and 13,379 SOL. Separately, the project's website was replaced with a frontend presenting an EmergencyMigration prompt; users who approved the transactions it requested lost a further $60,000 or so, bringing CertiK's total to about $1.32 million. Independent security researcher foobar publicly warned the same day that the MangoFarm frontend was compromised. The team then deactivated its X account, took down the site and closed its Telegram group.
Loss estimates differ. CertiK's traced figure is about $1.32 million; contemporaneous reporting including Blockonomi carried community estimates of around $2 million. This registry records the traced figure as the point estimate and $2 million as the upper bound.
CertiK traced the proceeds being swapped into USDC on Solana, bridged to Ethereum through Wormhole and Allbridge, then split across roughly 292 ETH sent to the eXch instant exchanger, about 263 ETH into the Railgun mixer and about 26 ETH through FixedFloat.
No operator has been publicly identified, charged or arrested. Screenshots circulated of messages said to be from the developer, and of a claimed link to another project, but their authenticity was never established and no named source has attributed the theft to a specific person.
Sources
- CertiKSecondary · retrieved 2026-08-01
- BlockonomiSecondary · retrieved 2026-08-01
- ChainCatcherSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "MangoFarmSOL hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/mangofarmsolhttps://itokenly.com/hacks/mangofarmsolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.