en
Back to the list

MANTRA post-mortem pins $3.6M exploit on a cosmos/evm integer bug

source-logo  cryptopolitan.com 1 h
image

MANTRA Chain stopped short of committing to a fund recovery plan in the full incident post-mortem report it published on August 28. Instead, the publication presented a formal recap of the August 20-21 incident where an attacker drained roughly 720.9 million MANTRA, worth about $3.6 million from the project.

Today’s disclosure formally assigned a dollar value to the one-week-old attack, which the project insists was due to a coding flaw not directly related to its own code.

In the meantime, MANTRA confirmed that law enforcement is now involved and updates are pending fund recovery efforts. It also said that it will update its circulating supply when it has a clearer picture of tokens stuck in hacker wallets and potential recovery.

What caused the MANTRA exploit?

According to the MANTRA Chain post-mortem, the exploit started at the shared cosmos/evm module it uses to run Ethereum-style contracts on top of the Cosmos SDK.

The affected version did not check that an account could cover a call before it approved subtractions from an account’s balance. The subtractions continued to go through because the code used unsigned integers, which cannot go below zero. Instead, it just wrapped around to an enormous number.

MANTRA clarified that none of its validator keys, governance controls or multisig signers were breached. The project also insisted that the code flaw that the attacker exploited did not come from its own end.

MANTRA wrote that “The attacker required no privileged access” as they had enough to get the job done with a permissionlessly deployed contract and self-funded wallet.

How much did MANTRA lose?

Per MANTRA, the attacker extracted about 600 million MANTRA and another 120.9 million tokens from its burn address and a dormant genesis-era multisig tied to an old incentive campaign, respectively.

MANTRA clarified the technicality of the impact of the attack, insisting that no new tokens were minted. What happened, instead was that the exploit unleashed roughly 720.9 million tokens that had been sitting outside the circulating supply and considered economically inert into circulation.

The report also intimated the programmatic cadence of token movement, as transactions appeared to go through at fixed sizes at short intervals rather than being manually processed.

MANTRA missed the transactions in real-time

By its own admission, the MANTRA team said it did not catch any rogue transactions for the first four hours of the breach. MANTRA explained the sloppiness as a lack of round-the-clock monitoring of a burn address meant to hold tokens that were supposed to be immovable.

In the hours before the team caught the red flags, the attacker ran two transactions and moved most of their haul off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second drain.

The attacker’s wallet still contained 37.96 million tokens at the time the chain was halted.

The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22 after validators coordinated a restart on the patched v8.4.0 release.

MANTRA could have done without this latest episode to cap off a dramatic 18 months for a project still trying to rebuild trust. MANTRA’s former OM token collapsed more than 90% in a single April 2025 session, erasing over $5 billion in value, as Cryptopolitan covered at the time.

Even Inveniam Capital Partners, which put $20 million into MANTRA in 2025, acknowledged past issues when it agreed in June to acquire the project.

When the halt first hit, the token sank 18.5% to a record low near $0.004126 before recovering, according to CoinGecko data.

cryptopolitan.com