Oracle Manipulation on Trial: When Draining DeFi Isn’t a Crime
Prosecutors are appealing the ruling that cleared the Mango Markets exploiter. It is the clearest sign yet that oracle manipulation is the DeFi attack the law keeps failing to punish.
On December 22, 2025, federal prosecutors did something unusual in a crypto case: they asked an appeals court to undo their own defeat. Their target was the ruling that erased every criminal conviction against Avraham Eisenberg, the trader who drained roughly $110 million from the decentralized exchange Mango Markets in October 2022 by manipulating the protocol’s price oracle. In their filing to the U.S. Court of Appeals for the Second Circuit, the government warned that the trial judge’s reasoning, if left standing, would unsettle traditional understandings of fraud.
The Exploit That Keeps Beating the Courtroom
The appeal matters far beyond one defendant. Oracle manipulation is the most intellectually distinctive attack in decentralized finance, and it is also the one the legal system has had the hardest time punishing. A hacker who steals private keys has clearly stolen something. A phisher who tricks a user has clearly lied. But an oracle manipulator often does nothing more than trade, aggressively and cleverly, against a protocol that agreed in advance to believe whatever price its feed reported. That is the puzzle at the center of the Mango case, and it is why a permissionless money market can lose nine figures while the person who emptied it argues, with a straight face and a real legal chance, that no crime occurred.
This is the third piece in our oracle-manipulation series. The first explained how DeFi price feeds get attacked; the second traced the 2026 wave that moved from manipulating markets to compromising the feed infrastructure itself. This one asks the question the incidents keep raising and the courts keep dodging: when someone reprices a market and walks away with the money, who, if anyone, is guilty, and who ends up paying? The answer, in 2026, is still mostly nobody and mostly the protocol.
Oracle Manipulation in One Paragraph
A price oracle is the bridge that tells a smart contract what an asset is worth. Lending markets and perpetual-futures venues use that number for everything that matters: how much you can borrow, when you get liquidated, and what a trade settles at. Manipulation means feeding the contract a wrong number long enough to borrow against phantom collateral or cash out a fake profit before anyone can react. A flash loan is the amplifier, not the flaw: it lets an attacker borrow millions with no collateral, shove a thin market, act, and repay it all inside a single atomic transaction. The real bug is an oracle that trusts a single low-liquidity venue, or, in the newer pattern, an oracle that treats a derived accounting number (an ERC-4626 vault share price, a wrapped-token exchange rate) as if it were a genuine market price. The OWASP Smart Contract Top 10 for 2026 still lists price-oracle manipulation as SC03, a fixture near the top of the list years after the first attacks.
It helps to separate three places the number can go wrong. The source can be corrupted, when an attacker moves the underlying market the oracle reads. The delivery can be corrupted, when the signed message that carries a price on-chain is forged or its signer key is stolen. And the consumption can be corrupted, when a protocol feeds the oracle an input that was never a real price to begin with, like the internal share value of a yield vault. The same word, manipulation, covers all three, but the defenses for each are completely different, and 2026 produced fresh casualties in every category.
Six Years of the Same Trick
The recipe has barely changed since it first worked. In February 2020, the bZx protocol lost around $350,000 in what is generally recognized as the first flash-loan-powered oracle attack. That October, Harvest Finance lost about $24 million when a flash loan skewed a Curve pool it used for pricing. Mango Markets followed in 2022, UwU Lend in 2024, Polter Finance weeks later, and then a fresh cluster arrived across 2025 and 2026. The names and chains rotate; the underlying mistake, trusting a price that one actor can move, keeps coming back.
| Incident | Date | Approx. loss | What the oracle trusted |
|---|---|---|---|
| bZx | Feb 2020 | ~$350K | ETH spot on a thin lending market (first flash-loan oracle attack) |
| Harvest Finance | Oct 2020 | ~$24M | A Curve pool price bent by a flash loan |
| Mango Markets | Oct 2022 | ~$110M | MNGO spot across the exchanges feeding its oracle |
| UwU Lend | Jun 2024 | ~$19.3M | An sUSDE price read from a Curve pool |
| Polter Finance | Nov 2024 | ~$8.7M | A single-DEX price for BOO |
| YieldBlox | Feb 2026 | ~$10.2M | A VWAP feed with no liquidity behind it |
| Bonzo Lend | Jul 2026 | ~$9M | A signed price update its verifier failed to check |
| Ostium | Jul 2026 | ~$18M | Signed reports from a compromised signer key |
The Mango Blueprint
Mango remains the cleanest textbook example, which is exactly why the courtroom fight over it carries so much weight. Eisenberg funded two accounts with about $5 million and opened offsetting long and short positions in MNGO perpetual futures, so his net market exposure was small. Then he bought MNGO aggressively across the three exchanges that supplied prices to Mango’s oracle. According to the CFTC complaint filed in January 2023, the price of MNGO as reported by the oracle jumped more than 13-fold during a 30-minute span. The oracle did its job and reported the inflated number; his long position showed an enormous unrealized profit; and he borrowed more than $110 million against that paper gain, draining the treasury before the price fell back.
Two design details made it possible. The oracle read spot prices from centralized venues that a single determined buyer could move for a few minutes, the same exchange prices that anchor much of crypto and that we compared in our look at the major exchanges and the bank test. And Mango let a user borrow against unrealized profit in real time, with no delay, no dampening, and no sanity check against a slower reference price. Neither piece was a coding bug in the narrow sense. Both were policy choices baked into a live financial system, and together they turned a temporary price spike into a permanent withdrawal.
A Successful and Legal Trading Strategy
What set Mango apart from an ordinary theft was how the perpetrator behaved afterward. Within days, Eisenberg publicly identified himself, describing his role in a team that had operated what he called a highly profitable trading strategy. He negotiated directly with Mango’s DAO through an on-chain governance vote, returning roughly $67 million in exchange for a pledge that the community would not pursue criminal charges, and kept about $47 million. His position, then and now, is that he executed a successful and legal trading strategy that exploited a design flaw, not a fraud.
The government disagreed emphatically. The Department of Justice arrested him and charged commodities fraud, commodities manipulation, and wire fraud. On the same day in January 2023, the CFTC and the SEC each filed parallel civil suits, the CFTC framing MNGO and the swaps as commodities and market manipulation, the SEC arguing MNGO was a security and the conduct was securities fraud. Three federal bodies, three theories, one exploit. A jury convicted him in 2024. And then the case, which prosecutors had treated as a signal to the entire DeFi world, came apart.
Why the Case Fell Apart
In May 2025, U.S. District Judge Arun Subramanian in the Southern District of New York vacated the two fraud-related counts and entered an acquittal on the wire fraud charge. He gave two reasons, and both cut to the heart of how DeFi works. The first was venue. Eisenberg had executed the whole thing from Puerto Rico. As the judge put it, he did not make trades in New York, call or email anyone in New York, or go to New York in connection with his scheme, so a Manhattan court was the wrong place to try him.
The second reason was more consequential. Wire fraud requires a material misrepresentation, a lie. But Mango was a permissionless protocol with no terms of service, no rulebook, and no promise a user could be said to have broken. In the judge’s words, on a platform with no rules, instructions, or prohibitions about borrowing, the government needed more to show that Eisenberg made an implicit misrepresentation. The code used the word borrow, but, the reasoning went, that label carried no enforceable promise to repay; it could have said access collateral or utilize assets and meant the same thing to the contract. If the machine invites you to take whatever the rules allow, taking a lot is not a lie. That single idea, permissionless design leaves prosecutors without a lie to point at, is the reason oracle manipulation is so hard to charge as fraud.
The Appeal That Could Rewrite DeFi’s Rules
That is the ruling prosecutors are now trying to reverse. In their December 2025 appeal, the government argues the judge ignored critical evidence and adopted an overly narrow reading of fraud. Their central claim is linguistic and blunt: the plain meaning of the word borrow conveys an intent to repay, and Mango’s own user guide did set expectations, including keeping a health ratio above zero and paying interest. Strip away the DeFi packaging, they say, and this was a lie about intent to repay, the oldest fraud there is. If the reasoning below survives, the filing warns, it would unsettle traditional understandings of fraud well outside crypto.
There is a procedural nuance worth stating plainly, because it is often garbled. The government normally cannot appeal an acquittal. Here it can, because a jury had already convicted, and the judge set that verdict aside afterward; if the Second Circuit reverses, the original verdict can be reinstated without a new trial, so double jeopardy is not triggered. The stakes are hard to overstate. Affirm the lower court, and permissionless-means-no-fraud hardens into appellate precedent that future exploiters will cite by name. Reverse it, and the code-is-law defense narrows sharply overnight. One footnote for accuracy: Eisenberg is not a free man, but not because of Mango. He is separately serving a four-year sentence on an unrelated conviction. On the oracle exploit itself, as of today, he has been convicted of nothing that still stands.
Security, Commodity, or Neither?
The criminal case is only half the accountability problem. The civil side is just as unsettled, and it starts with a question nobody in Washington has fully answered: who even owns oracle manipulation? The CFTC treated MNGO and its perpetual swaps as commodities and swaps under its jurisdiction. The SEC treated MNGO as an unregistered security and the manipulation as securities fraud. Both cannot be fully right, and which regulator has the stronger claim turns on the Howey test, the decades-old standard for what counts as an investment contract. A manipulated governance token sits in genuinely contested territory between the two agencies.
In 2026, that boundary is being redrawn by legislation rather than litigation. Congress spent the year working through market-structure proposals, including the CLARITY Act, that would formally divide oversight of digital assets between the SEC and the CFTC, after already setting rules for one corner of the market through the stablecoin regime we covered in the GENIUS rulebook and its offshore reach. Until that line is drawn in statute, an oracle manipulator faces a jurisdictional coin flip: the SEC if the token is deemed a security, the CFTC if it is a commodity, and a live argument in the gap between them. For a defendant, ambiguity is a gift. For a victim, it is one more reason the phone rings and nobody clearly has to answer.
When the Fix Misfires and No One Broke In
Not every oracle loss has a villain, which complicates the accountability question further. In March 2026, Aave suffered a rare wave of unwarranted liquidations, and there was no attacker at all. The culprit was CAPO, the Correlated Asset Price Oracle, a mechanism specifically built to stop donation-style manipulation of assets like wstETH by capping how fast a derived exchange rate is allowed to grow. A stale snapshot timestamp, stuck about a week behind, made CAPO undervalue wstETH by roughly 2.85 percent. That was enough to trigger around $26 million in liquidations across 34 accounts, with liquidators pocketing the bonuses, though the protocol recorded no bad debt. The safety rail, misconfigured, did the damage the attack was supposed to.
Because wstETH is a liquid-staking token whose value is a derived ratio rather than a market price, the incident is a close cousin of the collateral risks running through the restaking unwind of 2026. Chaos Labs, the risk-management firm behind the parameters, published a detailed post-mortem and its founder Omer Goldberg committed to reimbursing every affected user in full. That is the pattern worth noticing. When the safety mechanism itself misfires, there is no one to prosecute, no jurisdiction to argue over, and no lie to prove. The protocol and its risk manager simply absorb the cost and make users whole, because there is no other candidate to hold responsible.
From Moving Markets to Forging Feeds
The 2026 wave changed where attackers aim. Rather than move a real market that an honest oracle then reports, several attacks went straight for the delivery layer, the plumbing that signs and ships prices on-chain. Bonzo Lend on Hedera lost about $9 million in July when an attacker submitted a price update to Supra’s on-demand oracle inflating the SAUCE token by roughly twelve orders of magnitude, carried by a cryptographic signature made entirely of zeros; a bug in the verifier accepted it anyway, as CoinDesk reported. Ostium on Arbitrum lost about $18 million to a compromised oracle signer key and future-dated signed reports pushed through a registered forwarder. And in the Edel Finance exploit, a donation attack inflated a tokenized Google stock wrapper by 7,700 percent while the underlying Chainlink feed stayed perfectly correct the entire time. The oracle was not wrong; the protocol simply asked it the wrong question.
Not every 2026 attack was so exotic. In February, YieldBlox on Stellar lost about $10.2 million to the oldest trick in the book, executed on an empty market. Its Reflector oracle priced the USTRY token using a volume-weighted average, but the sole market maker had pulled its liquidity, leaving no real trades for about fifteen minutes. The attacker placed a single sell that lifted the price from around $1.06 to more than $100, roughly a hundredfold, then deposited far more USTRY, whose collateral value the protocol now read in the millions against a true worth of a few hundred thousand dollars, as Halborn documented in its breakdown. No key was stolen and no signature was forged; the market was simply too thin to trust, and the oracle trusted it anyway.
This is the shift the trackers keep flagging: away from clever smart-contract math and toward keys, signatures, and operational blind spots, the same move from code to credentials that runs through the machine-driven phishing wave of 2026. The aggregate numbers are disputed by design, since every firm draws the line differently, but the direction is not. Immunefi counted a record 207 incidents in the first half of 2026 for roughly $972 million, while other trackers using broader definitions put total crypto losses above a billion dollars. The counts agreed on the shape of the year, though: a large share of the damage came not from exotic contract bugs but from operational compromises, exactly the category oracle key theft belongs to.
| Incident | Where it broke | How |
|---|---|---|
| bZx, Mango, UwU, Polter | The market (source) | Attacker moved a real but thin market that the oracle honestly reported |
| YieldBlox | The market (source) | The sole market maker pulled liquidity; one trade set the VWAP |
| Venus (wUSDM) | Protocol use of a derived number (consumption) | An ERC-4626 share price inflated by repeated donations |
| Edel Finance | Protocol use of a derived number (consumption) | A wrapper exchange rate treated as a price; the real feed stayed correct |
| Bonzo Lend | The feed’s signature check (delivery) | A zeroed signature accepted by a buggy verifier |
| Ostium | The signer key (delivery) | A compromised key produced valid-looking future-dated reports |
| Aave CAPO (not an attack) | The safety cap itself (consumption) | A stale snapshot undervalued wstETH and forced liquidations |
OEV: Manipulation With a License
Here is the uncomfortable mirror image of everything above. Every time an oracle updates a price and that update triggers a liquidation, there is a profit waiting for whoever lands the next transaction. It is called Oracle Extractable Value, or OEV, a close cousin of the MEV that searchers and bots have harvested from block ordering for years. Left alone, OEV leaks out of the protocol to whoever is fastest. The mechanical act, extracting value from the exact moment a price changes, is the same one an oracle manipulator performs. The difference is consent and whose rules you follow.
In 2026 the oracle providers turned that leakage into revenue. Chainlink’s Smart Value Recapture routes updates through a dual-aggregator design and auctions the right to back-run the liquidation, returning the proceeds to the protocol. Chainlink says SVR has already recaptured more than $1.1 million across over $32 million in liquidations and claims close to 99 percent of the young OEV-recapture market. API3 runs a competing OEV network that auctions the same opportunity back to users. The philosophical point is sharper than it looks: OEV recapture and oracle manipulation are the same act, monetizing a price update, separated only by permission. One is a product with a revenue share; the other is an exploit with an indictment. The line between them is drawn by governance, not by physics.
Who Actually Pays for a Manipulated Feed
When the law cannot reach the attacker and the code has already failed, the bill still lands somewhere, and in 2026 it almost always lands on the protocol. The recurring patterns are telling. Sometimes a risk manager reimburses users directly, as Chaos Labs did after the Aave misfire. Sometimes an attacker returns funds voluntarily: a second wallet involved in the Bonzo exploit borrowed roughly $1 million, then identified itself as a white hat and offered to give it back. Sometimes a stablecoin issuer intervenes, as Tether did after the Rhea Finance hack on NEAR in April 2026, when it froze about $3.29 million in USDT tied to the attacker. And sometimes the money simply disappears, as when Edel’s exploiter washed the proceeds through a mixer within hours, a laundering step that also defeats the identity checks we examined in the crypto KYC and deepfake arms race.
For a user on a fully decentralized protocol, formal recourse is close to zero. There is no registered broker to sue, no custodian to hold liable, no CASP with a compliance department, and no SEC-registered intermediary standing between the user and the smart contract. Sergey Nazarov, the Chainlink co-founder, warned about this dynamic long before it became a monthly headline, telling The Defiant back in 2020 that the industry should not wait for a Mt. Gox-level loss before taking oracle risk seriously, arguing the danger stayed underdiscussed only because the losses had not yet reached that scale. Years and hundreds of millions of dollars later, the pattern he described is still running, just spread across many protocols instead of concentrated in one catastrophic failure.
The Defenses That Must Do What the Law Cannot
Because courts are slow, jurisdiction is contested, and attackers can often walk, the real deterrent against oracle manipulation is engineering. The mature defensive menu is well understood. Time-weighted average prices smooth out single-block spikes, though they resist one-block manipulation far better than multi-block attacks. Decentralized push oracles with median aggregation, the Chainlink model, require an attacker to corrupt a majority of independent node operators rather than one thin market. Pull oracles with confidence intervals, the Pyth approach, let first-party publishers post prices alongside a measure of how uncertain they are, so a protocol can refuse to act on a suspiciously wide quote. Caps on derived exchange rates, like Aave’s CAPO when it is configured correctly, blunt donation attacks on vault shares and wrapped tokens. And the hardest-won lesson of the 2025 and 2026 wave is a rule, not a tool: never treat a vault share price or a wrapper ratio as a primary price, because those are accounting numbers that anyone can nudge.
| Provider | Model | Rough value secured | Manipulation defense |
|---|---|---|---|
| Chainlink | Push, decentralized node network, median aggregation | Tens of billions (about 70% of the market) | Needs majority-operator collusion to move a feed |
| Pyth | Pull, first-party publishers | Billions | Prices carry confidence intervals |
| RedStone | Pull, modular, many chains | Billions | On-demand signed data, delivered when used |
| Chronicle | Push, validator-signed feeds | Billions | Signature-verified, transparent signer set |
| API3 | First-party dAPIs plus OEV auctions | Smaller | First-party data, OEV returned to users |
The value-secured figures come from DefiLlama’s oracle rankings, which put Chainlink at the top with tens of billions of dollars secured across hundreds of protocols, roughly 70 percent of the market by value, with Chronicle, RedStone, and Pyth trailing well behind. Concentration is a double-edged defense: a battle-tested market leader is harder to fool, but it also means a single provider’s verifier bug, exactly what sank Bonzo through Supra, can ripple across everything that depends on it.
What the Mango Appeal Means for the Next Drained Protocol
Step back, and oracle manipulation sits in a gap the law was never designed for. Classic market manipulation statutes assume a regulated market with a registered operator and a rulebook. Hacking statutes assume unauthorized access, a lock that was picked. Oracle manipulation fits neither cleanly: the market is permissionless, the access is authorized, and the rulebook, as the Mango judge found, may not exist. The Second Circuit’s answer in the Eisenberg appeal will set the template for years, because it is the first time an appellate court will squarely decide whether draining a rules-free protocol through its own price feed is fraud or just aggressive trading.
If permissionless-means-no-lie survives on appeal, prosecutors will keep struggling and DeFi will keep leaning on civil regulators and, more than anything, on code. Outside the United States the recourse is even thinner: Europe’s MiCA framework largely excludes fully decentralized DeFi from its scope, so a user manipulated on a genuinely permissionless protocol has no CASP to complain to and no national regulator with clear jurisdiction. The through-line, whether you read it as a legal story or a security one, is the same. Until lawmakers pick a lane and courts back them up, the feed is on its own, and the only reliable defense against oracle manipulation is to build systems that cannot be manipulated in the first place.
Frequently Asked Questions
Is oracle manipulation illegal?
It depends on the jurisdiction and on whether the manipulated token counts as a security or a commodity. The Mango Markets case showed that a permissionless protocol with no terms of service can leave prosecutors without a provable lie: a US judge vacated every criminal conviction against the exploiter in 2025, and prosecutors appealed in December 2025. Civil regulators such as the SEC and CFTC can still bring market-manipulation and fraud claims, so the safest reading is that it is legally risky and actively contested, not clearly legal.
What is the difference between oracle manipulation and a flash loan attack?
A flash loan is a funding tool that lets an attacker borrow a large sum with no collateral inside a single transaction. Oracle manipulation is the underlying flaw being exploited, namely a price feed that can be pushed to a wrong value. Many oracle attacks use flash loans to move a thin market, but not all do: the Bonzo Lend exploit relied on a signature-verification bug, not a loan, and plenty of flash loan attacks never touch an oracle at all.
How do protocols prevent oracle manipulation?
Common defenses include decentralized push oracles with median aggregation such as Chainlink, pull oracles with confidence intervals such as Pyth, time-weighted average prices, caps on derived exchange rates such as Aave CAPO, circuit breakers, and multi-oracle sanity checks. The core rule is to never trust a single low-liquidity venue and never treat a vault share price or a wrapped-token ratio as if it were a real market price.
Did Avraham Eisenberg go to prison for the Mango Markets exploit?
No. His Mango Markets convictions were vacated in May 2025 and he was acquitted of wire fraud, on the grounds of improper venue and the absence of any misrepresentation on a protocol with no rules. He is separately serving a four-year sentence for an unrelated conviction. Prosecutors appealed the Mango ruling in December 2025, so the outcome is not final and the verdict could still be reinstated.
What is OEV or Oracle Extractable Value?
OEV is the profit available when an oracle update triggers events such as liquidations, a cousin of MEV. For years it leaked to searchers and bots. In 2026, providers began auctioning it back to protocols: Chainlink Smart Value Recapture and API3’s OEV network return much of that value to the applications that generate it. OEV is essentially the licensed, consent-based flip side of oracle manipulation, the same value capture done with permission.
By Marcus Halloran, security correspondent, HOGE Wire.