MANTRA Failure Analysis Reveals $3.6 Million Vulnerability in cosmos/evm Integer Key

cryptonews.ruPublished on 2026-08-28Last updated on 2026-08-28

Abstract

On August 28, MANTRA Chain published a report on a security breach that occurred on August 20-21, resulting in a loss of approximately 720.9 million MANTRA tokens, valued at around $3.6 million. The company did not promise fund recovery. The attack exploited an integer overflow vulnerability in a common cosmos/evm module used to run Ethereum-style smart contracts over Cosmos SDK. This flaw allowed the attacker to drain funds without privileged access. MANTRA emphasized the bug was not in its proprietary code and that no validator keys or multisig systems were compromised. The stolen tokens came from a burn address and an inactive genesis multisig wallet, and were considered economically inactive prior to the attack. MANTRA's team admitted to failing to detect the fraudulent transactions in real-time due to a lack of 24/7 monitoring. The blockchain was halted 14 minutes after the attacker's second withdrawal, with 37.96 million tokens still in the hacker's wallet. The network remained down for over 30 hours before restarting on a patched version. This incident adds to the project's challenges, following a 90% token crash in April 2025 and a recent acquisition by Inveniam Capital Partners, which acknowledged past issues. The token price dropped roughly 18.5% following the breach announcement.

In a full report released on August 28th, MANTRA Chain did not make specific promises regarding fund recovery. Instead, the publication presented an official overview of the incident that occurred on August 20-21, where an attacker withdrew approximately 720.9 million MANTRA from the project, worth roughly $3.6 million.

Today's announcement officially assessed the monetary equivalent of the attack that happened a week ago, which the project insists was caused by a bug in code not directly related to its own codebase.

Meanwhile, MANTRA confirmed that law enforcement has been engaged in the case, and information will be provided as updates on fund return become available. The company also stated it will update the circulating token count once it has a clearer picture of which tokens are stuck in the hacker's wallets and the possibilities for their recovery.

What Caused the Vulnerability in MANTRA?

According to the vulnerability analysis in MANTRA Chain, it originated from a shared cosmos/evm key used to run Ethereum-style smart contracts on top of the Cosmos SDK.

The affected version did not verify the ability to cover transaction costs before approving contract calls from an account's balance. The calls continued to execute because the code used unsigned integers, which cannot be less than zero. Instead, it wrapped around to an enormous number.

MANTRA clarified that none of its validator keys, governance mechanisms, or multisig devices were compromised. The project also insisted that the code vulnerability exploited by the attacker was not on its own side.

MANTRA wrote that "the attacker did not require privileged access," as they had sufficient resources to perform the task thanks to a permissionlessly deployed contract and their own wallet.

How Much Loss Did MANTRA Incur?

According to MANTRA's data, the attacker drained about 600 million MANTRA and an additional 120.9 million tokens from a burn address and an inactive multisig from the genesis era related to an old incentive campaign, respectively.

MANTRA clarified the technical details of the attack's aftermath, insisting that no new tokens were minted. Instead, the hack resulted in approximately 720.9 million tokens, previously outside the circulating supply and considered economically inactive, being released into circulation.

The report also pointed to a programmatic rhythm in the token movements, as transactions appeared to go through in fixed volumes at short intervals rather than being handled manually.

MANTRA Missed Real-Time Transactions

By its own admission, the MANTRA team stated that it failed to detect a single fraudulent transaction in the first four hours after the exploit. MANTRA explained this oversight by the lack of 24/7 monitoring of the burn address for tokens that were supposed to be non-transferable.

Hours before the team spotted red flags, the attacker conducted two transactions and moved the bulk of the stolen funds off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second withdrawal.

At the time of the blockchain halt, 37.96 million tokens remained in the attacker's wallet.

The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22nd after validators coordinated a restart on the patched version 8.4.0.

MANTRA could have well done without this latest episode in a dramatic 18 months that concluded for a project still trying to regain trust. MANTRA's former OM token crashed over 90% in a single session in April 2025, losing over $5 billion in value, as Cryptopolitan reported at the time.

Even Inveniam Capital Partners, which invested $20 million in MANTRA in 2025, acknowledged past problems, when it agreed to acquire the project in June.

According to CoinGecko data, after the first post-halt trading, the token fell 18.5% to a record low around $0.004126 before recovering.

end-content

Trending Cryptos

Related Questions

QWhat was the root cause of the $3.6 million vulnerability exploited on the MANTRA Chain?

AThe vulnerability stemmed from a flaw in the common cosmos/evm module, used to run Ethereum-style contracts on Cosmos SDK. The affected version did not check if the caller's balance could cover transaction fees before approving a contract call from an account's balance. It used unsigned integers, which cannot be negative, causing the balance to loop to a huge number instead of failing.

QWhat was the total amount of funds and tokens taken in the attack on MANTRA Chain?

AThe attacker withdrew approximately 720.9 million MANTRA tokens, with an estimated value of $3.6 million. This included about 600 million MANTRA from the main attack and an additional 120.9 million tokens from a burn address and an inactive multi-signature wallet.

QDid the MANTRA team detect the fraudulent transactions in real-time when the attack occurred?

ANo. According to the report, the MANTRA team failed to detect any fraudulent transactions in the first four hours of the attack. They attributed this oversight to not having 24/7 monitoring on the burn address, from which some tokens were moved.

QHow did the attacker manage to execute the exploit without privileged access?

AAccording to MANTRA, the attacker did not require privileged access. They had sufficient resources to execute the attack using a permissionlessly deployed contract and their own wallet. MANTRA confirmed that none of its validator keys, governance mechanisms, or multi-signature devices were compromised.

QHow long was the MANTRA blockchain network halted following the attack, and what was the consequence for its native token price?

AThe network was halted for 30 hours and 13 minutes, from 23:13 UTC on August 21 until 05:26 UTC on August 22. Following the network stop and subsequent restart on a patched version, the MANTRA token price initially dropped by 18.5% to a record low of around $0.004126 before recovering slightly.

Related Reads

Trading

Spot

Hot Articles

How to Buy MANTRA

Welcome to HTX.com! We've made purchasing Mantra (MANTRA) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Mantra (MANTRA) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Mantra (MANTRA)After purchasing your Mantra (MANTRA), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Mantra (MANTRA)Easily trade Mantra (MANTRA) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

6.0k Total ViewsPublished 2026.03.04Updated 2026.06.02

How to Buy MANTRA

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of MANTRA (MANTRA) are presented below.

活动图片