MANTRA Chain Resumes After $3.6M Cosmos EVM Exploit, Full Postmortem Still Missing

1 hour ago 2 sources negative

Key takeaways:

  • Clean restart without state changes may limit MANTRA's long-term reputational damage.
  • Delayed postmortem details could sustain a trust discount on OM token.
  • Cosmos EVM flaw highlights shared infrastructure risks affecting multi-chain security confidence.

MANTRA Chain has restored mainnet block production on version 8.4.0, roughly six days after a security incident forced a chainwide halt, while the project has now confirmed a loss of approximately $3.6 million stemming from a Cosmos EVM balance deduction flaw.

The official incident timeline says mainnet resumed at approximately 05:30 UTC on Aug. 22. According to MANTRA, there was no rollback or state change between the halt and restart, user balances were not altered, and token holders did not need to take action. The team marked the incident resolved on Aug. 24, but as of Aug. 27 no full postmortem had been published.

The breach, dated Aug. 20 in MANTRA's disclosure, allowed attackers to exploit a flaw in how balances were deducted in the Cosmos EVM module. This led to an unauthorized outflow of about 721 million MANTRA tokens from an on-chain burn address and a genesis multisig address. A network upgrade subsequently froze 37.96 million MANTRA tokens, while the remaining tokens had already been moved to various exchanges. Authorities are cooperating in the investigation, but no funds have been recovered so far.

MANTRA said its analysis found the incident affected two MANTRA-managed wallets and that no user, exchange, or partner funds were affected. However, the public account stopped short of identifying wallet addresses, transaction hashes, amounts, or technical exploit steps. The chain also warned node operators that the release tag was re-pushed during recovery and told them to re-pull it. The final upgrade handler blocklists one address and disables three Cosmos vesting-account creation messages through the circuit breaker.

The incident remains partly unexplained: a March Cosmos Labs advisory had described a critical ICS20 precompile flaw and named Mantra among remediation collaborators, but its documented scope ends in March, leaving the August exploit outside that timeline. MANTRA has committed to strengthening monitoring of abnormal accounts and enhancing security protocols to prevent similar incidents.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.