Foresight News
Foresight News|Aug 28, 2026 10:45
**[MANTRA Releases Cosmos EVM Vulnerability Incident Report, Attacker Transfers Approximately $3.6 Million in MANTRA]** Foresight News reports that MANTRA has published a comprehensive post-incident report on the security event that occurred on August 20. According to the report, the attacker exploited an unsigned integer underflow vulnerability in the upstream module Cosmos EVM, which MANTRA Chain relies on, to transfer a total of 720,923,967.99 MANTRA tokens from two unauthorized addresses (valued at approximately $3.6 million based on the spot price of $0.005 on the day of the incident). Of these, 600 million tokens were taken from a burn address, and 121 million tokens were taken from a genesis multisig address associated with incentive activities. The attack did not involve validator keys, admin keys, governance permissions, or multisig signers being compromised, nor did the attacker gain any privileged access. MANTRA stated that the vulnerability had been fixed in the Cosmos EVM development branch as early as May 15, but it was not backported and merged into the release branch until August 19—approximately 20 hours before the first attack—leaving insufficient response time for downstream chains. The first abnormal transaction on-chain occurred at 3:06 AM on August 21. Since the burn address was previously considered non-transferable and was not monitored, the issue was only discovered nearly four hours later, during which the attacker had completed a second transfer and moved most of the funds. MANTRA Chain was halted at 7:13 AM and restarted 30 hours and 13 minutes later, on August 22, under the patched version v8.4.0, coordinated by 38 independent validators. No rollback or state rewrite occurred. The report states that approximately 94.7% of the stolen funds (683 million tokens) have been transferred to a deposit address at an exchange through 15 transactions, while the remaining 37.96 million tokens (5.27%) are still held in the attacker’s account and have been frozen. However, it emphasized that "freezing does not equate to recovery," and the process of recovering the funds has entered the law enforcement investigation stage. MANTRA confirmed that no customer accounts, exchange custody balances, or application contracts were deducted, but the network interruption did have a tangible impact on the ecosystem. New monitoring rules have been established for abnormal behaviors such as discrepancies between transaction account sources and signers.
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads