MANTRA Chain lost 720.9 million MANTRA tokens worth $3.6 million in an Aug. 20 exploit from a cosmos/evm integer bug, per its post-mortem.
The report, published Aug. 28, said the affected code in the shared cosmos/evm module failed to verify an account could cover a call before approving balance subtractions. Because the module used unsigned integers, which cannot go below zero, the subtraction wrapped around to an enormous number instead of reverting. The attacker required no privileged access, deploying a permissionless contract and self-funded wallet to execute the drain.
The exploit pulled roughly 600 million MANTRA from the chain's burn address and 120.9 million from a dormant genesis-era multisig tied to an old incentive campaign. MANTRA said no new tokens were minted — the attacker released economically inert tokens into circulation. The team did not detect the rogue transactions for the first four hours, during which the attacker ran two transactions and moved most of the haul off-chain. Validators halted the network at 23:13 UTC on Aug. 20, 14 minutes after the second drain, with 37.96 million tokens still in the attacker's wallet.
Mainnet resumed block production at 05:26 UTC on Aug. 22 after a 30-hour, 13-minute outage, running the patched v8.4.0 release. The upgrade handler blocklists one address and disables three Cosmos vesting-account creation messages through the circuit breaker. MANTRA confirmed no customer, exchange, or partner funds were debited and no validator keys, governance controls, or multisig signers were breached. The release page points to commit 5c08d7bd9e2619952707dae1258d2a30bf024721, with MANTRA warning that the tag was re-pushed during recovery and telling operators to re-pull it.
The project stopped short of committing to a fund recovery plan. MANTRA said law enforcement is now involved and that it will update its circulating supply once it has a clearer picture of tokens stuck in hacker wallets. The token sank 18.5 percent to a record low near $0.004126 when the halt first hit, according to CoinGecko data, before recovering.
The incident follows a turbulent 18 months for MANTRA. The project's former OM token collapsed more than 90 percent in a single April 2025 session, erasing over $5 billion in value. Inveniam Capital Partners, which invested $20 million in MANTRA in 2025, acknowledged past issues when it agreed in June to acquire the project. A March Cosmos Labs advisory described a critical ICS20 precompile flaw and named MANTRA among remediation collaborators, though the advisory's timeline ends with the March disclosure, leaving the August incident outside its documented scope. The lack of a committed recovery plan and the undisclosed wallet addresses, transaction hashes, and technical exploit steps leave the full scope of the incident unresolved for token holders and node operators.
This article is for informational purposes only and does not constitute investment advice.