In a full report released on August 28th, MANTRA Chain did not make specific promises regarding fund recovery. Instead, the publication presented an official overview of the incident that occurred on August 20-21, where an attacker withdrew approximately 720.9 million MANTRA from the project, worth roughly $3.6 million.
Today's announcement officially assessed the monetary equivalent of the attack that happened a week ago, which the project insists was caused by a bug in code not directly related to its own codebase.
Meanwhile, MANTRA confirmed that law enforcement has been engaged in the case, and information will be provided as updates on fund return become available. The company also stated it will update the circulating token count once it has a clearer picture of which tokens are stuck in the hacker's wallets and the possibilities for their recovery.
What Caused the Vulnerability in MANTRA?
According to the vulnerability analysis in MANTRA Chain, it originated from a shared cosmos/evm key used to run Ethereum-style smart contracts on top of the Cosmos SDK.
The affected version did not verify the ability to cover transaction costs before approving contract calls from an account's balance. The calls continued to execute because the code used unsigned integers, which cannot be less than zero. Instead, it wrapped around to an enormous number.
MANTRA clarified that none of its validator keys, governance mechanisms, or multisig devices were compromised. The project also insisted that the code vulnerability exploited by the attacker was not on its own side.
MANTRA wrote that "the attacker did not require privileged access," as they had sufficient resources to perform the task thanks to a permissionlessly deployed contract and their own wallet.
How Much Loss Did MANTRA Incur?
According to MANTRA's data, the attacker drained about 600 million MANTRA and an additional 120.9 million tokens from a burn address and an inactive multisig from the genesis era related to an old incentive campaign, respectively.
MANTRA clarified the technical details of the attack's aftermath, insisting that no new tokens were minted. Instead, the hack resulted in approximately 720.9 million tokens, previously outside the circulating supply and considered economically inactive, being released into circulation.
The report also pointed to a programmatic rhythm in the token movements, as transactions appeared to go through in fixed volumes at short intervals rather than being handled manually.
MANTRA Missed Real-Time Transactions
By its own admission, the MANTRA team stated that it failed to detect a single fraudulent transaction in the first four hours after the exploit. MANTRA explained this oversight by the lack of 24/7 monitoring of the burn address for tokens that were supposed to be non-transferable.
Hours before the team spotted red flags, the attacker conducted two transactions and moved the bulk of the stolen funds off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second withdrawal.
At the time of the blockchain halt, 37.96 million tokens remained in the attacker's wallet.
The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22nd after validators coordinated a restart on the patched version 8.4.0.
MANTRA could have well done without this latest episode in a dramatic 18 months that concluded for a project still trying to regain trust. MANTRA's former OM token crashed over 90% in a single session in April 2025, losing over $5 billion in value, as Cryptopolitan reported at the time.
Even Inveniam Capital Partners, which invested $20 million in MANTRA in 2025, acknowledged past problems, when it agreed to acquire the project in June.
According to CoinGecko data, after the first post-halt trading, the token fell 18.5% to a record low around $0.004126 before recovering.
end-content





