TL;DR
- MANTRA Chain has disclosed new details about its August exploit, which moved 720.9 million MANTRA worth about $3.6 million.
- The attack exploited an upstream Cosmos-EVM vulnerability without compromising validator keys or customer balances.
- The chain has since been patched and restored, but MANTRA has not committed to a definitive recovery plan.
MANTRA Chain has released a detailed post-mortem of its August 20 security incident, confirming that an attacker transferred approximately 720.9 million MANTRA, valued at about $3.6 million. The report attributes the breach to an unsigned-integer underflow in the upstream cosmos/evm module rather than code written directly by MANTRA.
The incident did not involve compromised validator keys, governance controls, administrator credentials or multisig signers. MANTRA confirmed that no customer funds were directly debited. However, the event increased circulating supply because the attacker moved tokens previously considered economically inactive.
MANTRA Chain Identifies The Technical Failure
The vulnerability allowed a balance subtraction to proceed without verifying whether an account held enough funds. Because unsigned integers cannot represent negative values, the faulty calculation could wrap around into an extremely large number.
The attacker used a permissionlessly deployed contract and a self-funded wallet, meaning privileged access was not required. Around 600 million MANTRA came from the burn address, while another 120.9 million came from a dormant genesis-era multisig linked to an earlier incentive campaign. No new MANTRA was minted.
MANTRA also acknowledged that its monitoring systems failed to flag the first unauthorized transaction. The burn address had been treated as inert because it was not expected to move funds. The attacker remained undetected for nearly four hours before the second transfer triggered a response.

Patch Restores Network As Recovery Remains Open
Validators halted the network at 23:13 UTC on August 20, shortly after the second unauthorized transaction. The chain remained offline for 30 hours and 13 minutes before validators coordinated a restart using the patched v8.4.0 release. The restart occurred without a rollback or state rewrite.
The post-mortem says approximately 37.96 million MANTRA remained in the attacker’s wallet when the chain was stopped. Those tokens were immobilized, while the remaining funds moved through external routes and became part of recovery efforts involving law enforcement.
The vulnerability had been fixed upstream before the incident, but the relevant fix reached release branches only shortly before the exploit. The episode highlights the security challenges facing chains that depend on shared open-source infrastructure, where a flaw can affect multiple networks.
Â



