MANTRA Chain has published a full post-mortem on the August 20-21 exploit that released about 720.9 million MANTRA, valued by the project at roughly $3.6 million before the incident. The team said the attack was driven by an unsigned-integer underflow flaw in the shared cosmos/evm module used to run Ethereum-style contracts on top of the Cosmos SDK.
The report says the tokens were drained from a burn address and a dormant legacy multisig, not from customer accounts, exchange balances or application contracts. MANTRA also said no validator keys, governance controls or multisig signers were compromised, and that no new tokens were minted during the incident.
Bug in shared module enabled the drain
According to MANTRA, the affected cosmos/evm version failed to verify that an account had enough balance before approving deductions tied to a call. Because the code used unsigned integers, balances did not fall below zero when overdrawn. Instead, they wrapped to a very large number, allowing the exploit to proceed.
The team said the weakness was in shared infrastructure rather than in MANTRA-specific code. In its account, the attacker needed no privileged access and was able to carry out the exploit using a permissionlessly deployed contract and a self-funded wallet.
Where the tokens came from
MANTRA said the attacker extracted roughly 600 million MANTRA from the chain’s burn address and another 120.9 million from a dormant genesis-era multisig linked to an older incentive campaign. The total cited in the report was 720,923,967.99 MANTRA.
The project emphasized that the event did not create new tokens. Instead, it said the exploit moved tokens that had been outside circulating supply and treated as economically inert back into circulation. MANTRA added that the transfers appeared to occur in fixed sizes at short intervals, suggesting an automated pattern rather than manual movement.
Detection lag and network halt
The post-mortem says the team did not identify the unauthorized transactions for about four hours. MANTRA attributed that delay to the absence of continuous monitoring on a burn address that had been assumed to be immovable.
Before the issue was caught, the attacker executed two transactions and moved most of the assets off-chain. Validators halted the network at 23:13 UTC, 14 minutes after the second drain. At that point, the attacker wallet still held 37.96 million tokens, according to the report.
Mainnet remained offline for 30 hours and 13 minutes while validators coordinated a restart using the patched v8.4.0 release. Block production resumed at about 05:30 UTC on August 22, with MANTRA saying the network returned without a rollback or state changes.
Recovery remains unresolved
MANTRA did not commit to a specific recovery plan in the August 28 report. It said law enforcement is involved and that further updates on fund recovery efforts are still pending.
The project also said it will revise its circulating supply figures once it has a clearer view of how many tokens remain in wallets linked to the attacker and what portion, if any, can be recovered. For now, the confirmed next step is continued coordination on recovery and follow-up disclosure from the team.
Source: Cryptopolitan