MANTRA Failure Analysis Reveals $3.6 Million Vulnerability in cosmos/evm Integer Key

cryptonews.ruPublicado a 2026-08-28Actualizado a 2026-08-28

Resumen

On August 28, MANTRA Chain published a report on a security breach that occurred on August 20-21, resulting in a loss of approximately 720.9 million MANTRA tokens, valued at around $3.6 million. The company did not promise fund recovery. The attack exploited an integer overflow vulnerability in a common cosmos/evm module used to run Ethereum-style smart contracts over Cosmos SDK. This flaw allowed the attacker to drain funds without privileged access. MANTRA emphasized the bug was not in its proprietary code and that no validator keys or multisig systems were compromised. The stolen tokens came from a burn address and an inactive genesis multisig wallet, and were considered economically inactive prior to the attack. MANTRA's team admitted to failing to detect the fraudulent transactions in real-time due to a lack of 24/7 monitoring. The blockchain was halted 14 minutes after the attacker's second withdrawal, with 37.96 million tokens still in the hacker's wallet. The network remained down for over 30 hours before restarting on a patched version. This incident adds to the project's challenges, following a 90% token crash in April 2025 and a recent acquisition by Inveniam Capital Partners, which acknowledged past issues. The token price dropped roughly 18.5% following the breach announcement.

In a full report released on August 28th, MANTRA Chain did not make specific promises regarding fund recovery. Instead, the publication presented an official overview of the incident that occurred on August 20-21, where an attacker withdrew approximately 720.9 million MANTRA from the project, worth roughly $3.6 million.

Today's announcement officially assessed the monetary equivalent of the attack that happened a week ago, which the project insists was caused by a bug in code not directly related to its own codebase.

Meanwhile, MANTRA confirmed that law enforcement has been engaged in the case, and information will be provided as updates on fund return become available. The company also stated it will update the circulating token count once it has a clearer picture of which tokens are stuck in the hacker's wallets and the possibilities for their recovery.

What Caused the Vulnerability in MANTRA?

According to the vulnerability analysis in MANTRA Chain, it originated from a shared cosmos/evm key used to run Ethereum-style smart contracts on top of the Cosmos SDK.

The affected version did not verify the ability to cover transaction costs before approving contract calls from an account's balance. The calls continued to execute because the code used unsigned integers, which cannot be less than zero. Instead, it wrapped around to an enormous number.

MANTRA clarified that none of its validator keys, governance mechanisms, or multisig devices were compromised. The project also insisted that the code vulnerability exploited by the attacker was not on its own side.

MANTRA wrote that "the attacker did not require privileged access," as they had sufficient resources to perform the task thanks to a permissionlessly deployed contract and their own wallet.

How Much Loss Did MANTRA Incur?

According to MANTRA's data, the attacker drained about 600 million MANTRA and an additional 120.9 million tokens from a burn address and an inactive multisig from the genesis era related to an old incentive campaign, respectively.

MANTRA clarified the technical details of the attack's aftermath, insisting that no new tokens were minted. Instead, the hack resulted in approximately 720.9 million tokens, previously outside the circulating supply and considered economically inactive, being released into circulation.

The report also pointed to a programmatic rhythm in the token movements, as transactions appeared to go through in fixed volumes at short intervals rather than being handled manually.

MANTRA Missed Real-Time Transactions

By its own admission, the MANTRA team stated that it failed to detect a single fraudulent transaction in the first four hours after the exploit. MANTRA explained this oversight by the lack of 24/7 monitoring of the burn address for tokens that were supposed to be non-transferable.

Hours before the team spotted red flags, the attacker conducted two transactions and moved the bulk of the stolen funds off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second withdrawal.

At the time of the blockchain halt, 37.96 million tokens remained in the attacker's wallet.

The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22nd after validators coordinated a restart on the patched version 8.4.0.

MANTRA could have well done without this latest episode in a dramatic 18 months that concluded for a project still trying to regain trust. MANTRA's former OM token crashed over 90% in a single session in April 2025, losing over $5 billion in value, as Cryptopolitan reported at the time.

Even Inveniam Capital Partners, which invested $20 million in MANTRA in 2025, acknowledged past problems, when it agreed to acquire the project in June.

According to CoinGecko data, after the first post-halt trading, the token fell 18.5% to a record low around $0.004126 before recovering.

end-content

Criptos en tendencia

Preguntas relacionadas

QWhat was the root cause of the $3.6 million vulnerability exploited on the MANTRA Chain?

AThe vulnerability stemmed from a flaw in the common cosmos/evm module, used to run Ethereum-style contracts on Cosmos SDK. The affected version did not check if the caller's balance could cover transaction fees before approving a contract call from an account's balance. It used unsigned integers, which cannot be negative, causing the balance to loop to a huge number instead of failing.

QWhat was the total amount of funds and tokens taken in the attack on MANTRA Chain?

AThe attacker withdrew approximately 720.9 million MANTRA tokens, with an estimated value of $3.6 million. This included about 600 million MANTRA from the main attack and an additional 120.9 million tokens from a burn address and an inactive multi-signature wallet.

QDid the MANTRA team detect the fraudulent transactions in real-time when the attack occurred?

ANo. According to the report, the MANTRA team failed to detect any fraudulent transactions in the first four hours of the attack. They attributed this oversight to not having 24/7 monitoring on the burn address, from which some tokens were moved.

QHow did the attacker manage to execute the exploit without privileged access?

AAccording to MANTRA, the attacker did not require privileged access. They had sufficient resources to execute the attack using a permissionlessly deployed contract and their own wallet. MANTRA confirmed that none of its validator keys, governance mechanisms, or multi-signature devices were compromised.

QHow long was the MANTRA blockchain network halted following the attack, and what was the consequence for its native token price?

AThe network was halted for 30 hours and 13 minutes, from 23:13 UTC on August 21 until 05:26 UTC on August 22. Following the network stop and subsequent restart on a patched version, the MANTRA token price initially dropped by 18.5% to a record low of around $0.004126 before recovering slightly.

Lecturas Relacionadas

Trading

Spot

Artículos destacados

Cómo comprar MANTRA

¡Bienvenido a HTX.com! Hemos hecho que comprar Mantra (MANTRA) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Mantra (MANTRA) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Mantra (MANTRA)Después de comprar tu Mantra (MANTRA), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Mantra (MANTRA)Tradear fácilmente con Mantra (MANTRA) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

522 Vistas totalesPublicado en 2026.03.04Actualizado en 2026.06.02

Cómo comprar MANTRA

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de MANTRA (MANTRA).

活动图片