MANTRA Failure Analysis Reveals $3.6 Million Vulnerability in cosmos/evm Integer Key

cryptonews.ru发布于2026-08-28更新于2026-08-28

文章摘要

On August 28, MANTRA Chain published a report on a security breach that occurred on August 20-21, resulting in a loss of approximately 720.9 million MANTRA tokens, valued at around $3.6 million. The company did not promise fund recovery. The attack exploited an integer overflow vulnerability in a common cosmos/evm module used to run Ethereum-style smart contracts over Cosmos SDK. This flaw allowed the attacker to drain funds without privileged access. MANTRA emphasized the bug was not in its proprietary code and that no validator keys or multisig systems were compromised. The stolen tokens came from a burn address and an inactive genesis multisig wallet, and were considered economically inactive prior to the attack. MANTRA's team admitted to failing to detect the fraudulent transactions in real-time due to a lack of 24/7 monitoring. The blockchain was halted 14 minutes after the attacker's second withdrawal, with 37.96 million tokens still in the hacker's wallet. The network remained down for over 30 hours before restarting on a patched version. This incident adds to the project's challenges, following a 90% token crash in April 2025 and a recent acquisition by Inveniam Capital Partners, which acknowledged past issues. The token price dropped roughly 18.5% following the breach announcement.

In a full report released on August 28th, MANTRA Chain did not make specific promises regarding fund recovery. Instead, the publication presented an official overview of the incident that occurred on August 20-21, where an attacker withdrew approximately 720.9 million MANTRA from the project, worth roughly $3.6 million.

Today's announcement officially assessed the monetary equivalent of the attack that happened a week ago, which the project insists was caused by a bug in code not directly related to its own codebase.

Meanwhile, MANTRA confirmed that law enforcement has been engaged in the case, and information will be provided as updates on fund return become available. The company also stated it will update the circulating token count once it has a clearer picture of which tokens are stuck in the hacker's wallets and the possibilities for their recovery.

What Caused the Vulnerability in MANTRA?

According to the vulnerability analysis in MANTRA Chain, it originated from a shared cosmos/evm key used to run Ethereum-style smart contracts on top of the Cosmos SDK.

The affected version did not verify the ability to cover transaction costs before approving contract calls from an account's balance. The calls continued to execute because the code used unsigned integers, which cannot be less than zero. Instead, it wrapped around to an enormous number.

MANTRA clarified that none of its validator keys, governance mechanisms, or multisig devices were compromised. The project also insisted that the code vulnerability exploited by the attacker was not on its own side.

MANTRA wrote that "the attacker did not require privileged access," as they had sufficient resources to perform the task thanks to a permissionlessly deployed contract and their own wallet.

How Much Loss Did MANTRA Incur?

According to MANTRA's data, the attacker drained about 600 million MANTRA and an additional 120.9 million tokens from a burn address and an inactive multisig from the genesis era related to an old incentive campaign, respectively.

MANTRA clarified the technical details of the attack's aftermath, insisting that no new tokens were minted. Instead, the hack resulted in approximately 720.9 million tokens, previously outside the circulating supply and considered economically inactive, being released into circulation.

The report also pointed to a programmatic rhythm in the token movements, as transactions appeared to go through in fixed volumes at short intervals rather than being handled manually.

MANTRA Missed Real-Time Transactions

By its own admission, the MANTRA team stated that it failed to detect a single fraudulent transaction in the first four hours after the exploit. MANTRA explained this oversight by the lack of 24/7 monitoring of the burn address for tokens that were supposed to be non-transferable.

Hours before the team spotted red flags, the attacker conducted two transactions and moved the bulk of the stolen funds off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second withdrawal.

At the time of the blockchain halt, 37.96 million tokens remained in the attacker's wallet.

The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22nd after validators coordinated a restart on the patched version 8.4.0.

MANTRA could have well done without this latest episode in a dramatic 18 months that concluded for a project still trying to regain trust. MANTRA's former OM token crashed over 90% in a single session in April 2025, losing over $5 billion in value, as Cryptopolitan reported at the time.

Even Inveniam Capital Partners, which invested $20 million in MANTRA in 2025, acknowledged past problems, when it agreed to acquire the project in June.

According to CoinGecko data, after the first post-halt trading, the token fell 18.5% to a record low around $0.004126 before recovering.

end-content

热门币种推荐

相关问答

QWhat was the root cause of the $3.6 million vulnerability exploited on the MANTRA Chain?

AThe vulnerability stemmed from a flaw in the common cosmos/evm module, used to run Ethereum-style contracts on Cosmos SDK. The affected version did not check if the caller's balance could cover transaction fees before approving a contract call from an account's balance. It used unsigned integers, which cannot be negative, causing the balance to loop to a huge number instead of failing.

QWhat was the total amount of funds and tokens taken in the attack on MANTRA Chain?

AThe attacker withdrew approximately 720.9 million MANTRA tokens, with an estimated value of $3.6 million. This included about 600 million MANTRA from the main attack and an additional 120.9 million tokens from a burn address and an inactive multi-signature wallet.

QDid the MANTRA team detect the fraudulent transactions in real-time when the attack occurred?

ANo. According to the report, the MANTRA team failed to detect any fraudulent transactions in the first four hours of the attack. They attributed this oversight to not having 24/7 monitoring on the burn address, from which some tokens were moved.

QHow did the attacker manage to execute the exploit without privileged access?

AAccording to MANTRA, the attacker did not require privileged access. They had sufficient resources to execute the attack using a permissionlessly deployed contract and their own wallet. MANTRA confirmed that none of its validator keys, governance mechanisms, or multi-signature devices were compromised.

QHow long was the MANTRA blockchain network halted following the attack, and what was the consequence for its native token price?

AThe network was halted for 30 hours and 13 minutes, from 23:13 UTC on August 21 until 05:26 UTC on August 22. Following the network stop and subsequent restart on a patched version, the MANTRA token price initially dropped by 18.5% to a record low of around $0.004126 before recovering slightly.

你可能也喜欢

交易

现货

热门文章

如何购买MANTRA

欢迎来到HTX.com!我们已经让购买Mantra(MANTRA)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Mantra(MANTRA)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Mantra(MANTRA)购买完您的Mantra(MANTRA)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Mantra(MANTRA)在HTX的现货市场轻松交易Mantra(MANTRA)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

1.3k人学过发布于 2026.03.04更新于 2026.06.02

如何购买MANTRA

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对MANTRA(MANTRA)币价的意见。

活动图片