EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

MANTRA post-mortem analysis: $3.6 million vulnerability attributed to Cosmos/EVM integer flaw

2026-08-29 00:21:15
Bookmark

MANTRA Chain released an incident review report, but did not commit a fund recovery plan.

MANTRA Chain did not make a clear commitment on the fund recovery plan in the complete incident review report released on August 28. The report only provides a formal review of attacks that occurred between August 20 and 21-attackers stole approximately 720.9 million MANTRA tokens, worth approximately $3.6 million, from the project.

The report released today officially marks the dollar value of the week-old attack. The project insisted that the attack originated from a coding flaw that did not originate directly from its own code.

At the same time, MANTRA confirmed that law enforcement agencies have been involved in the investigation and that the latest progress on fund recovery will be announced later. The project party also stated that it will update its circulation supply data after it has a clearer understanding of the number of tokens in the hacker wallet and the potential recovery situation.

Why did the MANTRA attack start?

According to MANTRA Chain's review report, the attack started with its shared cosmos/evm module used to run Ethereum-style contracts on the Cosmos SDK. The affected version did not verify whether the account was able to pay for the corresponding call before approving a deduction from the account balance. Because the code uses unsigned integers (which cannot go below zero), the deduction operation continues, eventually causing the value to wrap around to a huge number.

MANTRA clarified that none of its verifier keys, governance control mechanisms or multi-signature signers were compromised. The project also emphasized that the code flaws exploited by the attacker did not come from itself.

"Attackers do not require any privileged access," MANTRA wrote. They could complete the entire attack with a contract that could be deployed without permission and a self-recharging wallet.

How much did MANTRA lose?

According to MANTRA, the attackers extracted approximately 600 million MANTRA tokens from its destruction address, and an additional 120.9 million tokens were extracted from dormant Genesis multi-signature addresses associated with an old incentive plan.

MANTRA detailed technical details of the attack's impact, insisting that no new tokens were minted. In reality, the attack released some 720.9 million tokens into circulation that were considered economically dormant and were originally out of circulation.

The report also reveals a programmatic rhythm of token transfers-transactions appear to be done in batches at fixed-size intervals rather than manually.

MANTRA fails to catch transactions in real time

The MANTRA team admitted that they failed to detect any unusual transactions in the first four hours after the attack. The team attributed the omission to a failure to monitor the destruction address, which was designed to house the immovable tokens, 24/7.

Within hours before the team detected the abnormal signal, the attacker executed two transactions and transferred most of the stolen money offline. Subsequently, the verifier suspended the network at 23:13 UTC (14 minutes after the second theft occurred).

When the network was suspended, the attacker still held 37.96 million tokens in his wallet. The network was offline for 30 hours and 13 minutes until the validator coordinated the restart of patch version v8.4.0, and resumed operation at 05:26 UTC on August 22.

This incident could have been avoided after the ups and downs of the past 18 months for a project that is still trying to rebuild trust. The OM token, the predecessor of MANTRA, plunged more than 90% in a single trading day in April 2025, and its market value evaporated by more than US$5 billion. Even Inveniam Capital Partners, which invested $20 million in MANTRA in 2025, admitted its past problems when it agreed to buy the project in June.

According to CoinGecko data, the token fell 18.5% to an all-time low of about US$0.004126 after news of the Internet suspension, before recovering.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP