LATEST NEWS
SELECTED FOR YOU

No recovery plan in sight as MANTRA releases exploit post-mortem

ByHannah CollymoreHannah Collymore 3 mins read
No recovery plan in sight as MANTRA releases exploit post-mortem
  • MANTRA Chain’s August 28 post-mortem says an attacker exploited an unsigned-integer underflow bug in the cosmos/evm module.
  • The drain came up to about 720.9 million MANTRA, roughly $3.6 million, from a burn address and a legacy multisig on August 20.
  • No customer funds were debited, and no new tokens were minted.

MANTRA Chain stopped short of committing to a fund recovery plan in the full incident post-mortem report it published on August 28. Instead, the publication presented a formal recap of the August 20-21 incident where an attacker drained roughly 720.9 million MANTRA, worth about $3.6 million from the project.

Today’s disclosure formally assigned a dollar value to the one-week-old attack, which the project insists was due to a coding flaw not directly related to its own code.

In the meantime, MANTRA confirmed that law enforcement is now involved and updates are pending fund recovery efforts. It also said that it will update its circulating supply when it has a clearer picture of tokens stuck in hacker wallets and potential recovery.

What caused the MANTRA exploit?

According to the MANTRA Chain post-mortem, the exploit started at the shared cosmos/evm module it uses to run Ethereum-style contracts on top of the Cosmos SDK.

The affected version did not check that an account could cover a call before it approved subtractions from an account’s balance. The subtractions continued to go through because the code used unsigned integers, which cannot go below zero. Instead, it just wrapped around to an enormous number.

MANTRA clarified that none of its validator keys, governance controls or multisig signers were breached. The project also insisted that the code flaw that the attacker exploited did not come from its own end.

MANTRA wrote that “The attacker required no privileged access” as they had enough to get the job done with a permissionlessly deployed contract and self-funded wallet.

How much did MANTRA lose?

Per MANTRA, the attacker extracted about 600 million MANTRA and another 120.9 million tokens from its burn address and a dormant genesis-era multisig tied to an old incentive campaign, respectively.

MANTRA clarified the technicality of the impact of the attack, insisting that no new tokens were minted. What happened, instead was that the exploit unleashed roughly 720.9 million tokens that had been sitting outside the circulating supply and considered economically inert into circulation.

The report also intimated the programmatic cadence of token movement, as transactions appeared to go through at fixed sizes at short intervals rather than being manually processed.

MANTRA missed the transactions in real-time

By its own admission, the MANTRA team said it did not catch any rogue transactions for the first four hours of the breach. MANTRA explained the sloppiness as a lack of round-the-clock monitoring of a burn address meant to hold tokens that were supposed to be immovable.

In the hours before the team caught the red flags, the attacker ran two transactions and moved most of their haul off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second drain.

The attacker’s wallet still contained 37.96 million tokens at the time the chain was halted.

The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22 after validators coordinated a restart on the patched v8.4.0 release.

MANTRA could have done without this latest episode to cap off a dramatic 18 months for a project still trying to rebuild trust. MANTRA’s former OM token collapsed more than 90% in a single April 2025 session, erasing over $5 billion in value, as Cryptopolitan covered at the time.

Even Inveniam Capital Partners, which put $20 million into MANTRA in 2025, acknowledged past issues when it agreed in June to acquire the project.

When the halt first hit, the token sank 18.5% to a record low near $0.004126 before recovering, according to CoinGecko data.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

FAQs

How much was stolen in the MANTRA exploit?

The attacker moved 720,923,967.99 MANTRA in total, worth about $3.6 million at the pre-incident price of $0.005 per token, taking roughly 600 million from the chain's burn address and 120.9 million from a legacy genesis-era multisig.

Were customer or exchange funds lost?

No. According to MANTRA's post-mortem, no customer account, exchange-held balance, deposit address or application contract was debited, though the network was unavailable for 30 hours and 13 minutes and some exchanges paused deposits and withdrawals for longer.

Is the vulnerability fixed and is the chain back online?

Yes. MANTRA's status page confirms the flaw in the Cosmos-EVM module was remediated in the v8.4.0 release, and mainnet has produced blocks normally since block production resumed at about 05:30 UTC on August 22, 2026, with no rollback or state changes.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore

Hannah Collymore

Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.

MORE … NEWS