MANTRA Failure Analysis Reveals $3.6 Million Vulnerability in cosmos/evm Integer Key
On August 28, MANTRA Chain published a report on a security breach that occurred on August 20-21, resulting in a loss of approximately 720.9 million MANTRA tokens, valued at around $3.6 million. The company did not promise fund recovery.
The attack exploited an integer overflow vulnerability in a common cosmos/evm module used to run Ethereum-style smart contracts over Cosmos SDK. This flaw allowed the attacker to drain funds without privileged access. MANTRA emphasized the bug was not in its proprietary code and that no validator keys or multisig systems were compromised.
The stolen tokens came from a burn address and an inactive genesis multisig wallet, and were considered economically inactive prior to the attack. MANTRA's team admitted to failing to detect the fraudulent transactions in real-time due to a lack of 24/7 monitoring. The blockchain was halted 14 minutes after the attacker's second withdrawal, with 37.96 million tokens still in the hacker's wallet. The network remained down for over 30 hours before restarting on a patched version.
This incident adds to the project's challenges, following a 90% token crash in April 2025 and a recent acquisition by Inveniam Capital Partners, which acknowledged past issues. The token price dropped roughly 18.5% following the breach announcement.
cryptonews.ru21 小時前