← Radar

Incident case file

Sign in to watch

MANTRA Chain Cosmos-EVM Module Exploit — Full Recovery, No User Funds Affected

Incident date 2026-08-20Last updated Aug 26, 2026

3 views

ResolvedMANTRA ChainUpstream dependency vulnerability — Cosmos-EVM stack authorization bypass (bank-layer debit via staking precompile), nCluster: MANTRA-EVM-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

mantra13n9sk3p8x7tpq9adgxvzv9q0qev953mld0hwva — confirmed via the official MANTRA explorer, 24 transactions, all tied to this incident, zero outgoing/off-chain transfers.

Funds moved to

None of the displaced OM left the chain. The network halt froze the attacker's entire on-chain position; per independent verification, total OM supply was unchanged (this was not a mint), and no rollback or state changes occurred between the halt and the coordinated resumption on Aug 22.

Linked

720,923,967.99 OM was displaced from two accounts the attacker held no keys for: 600,000,035.55 OM from the null/burn address and 120,923,932.44 OM from a genesis-era 3-of-5 multisig. Root cause (independent technical analysis): a flaw in the Cosmos-EVM stack itself (cosmos/evm v0.6.0 + x/auth/vesting + the staking precompile) — not MANTRA's own application code — whereby a contract with a victim address baked in could debit that victim via the bank layer without authorization. MANTRA's offi

Chronology

1 beat
  1. Aug 21, 02:44 UTC: MANTRA detects the incident and halts the chain as a precaution; all endpoints and transactions frozen. 03:23 UTC: Freeze confirmed across all endpoints; deposits/withdrawals paused with exchange partners. 05:39 UTC: Team confirms ongoing investigation with external partners, warns users against fake 'recovery' services. 07:57 UTC: Official confirmation that an attacker exploited 'a vulnerability in an upstream dependency used by the chain.' Fund tracing begins in coordination with exchange partners. 10:28 UTC: Independent on-chain analyst Rarma publishes a full technical breakdown identifying the Cosmos-EVM stack as the true root cause (not MANTRA's app logic) and names the attacker address mantra13n9sk3p8x7tpq9adgxvzv9q0qev953mld0hwva, confirming total OM supply is unchanged and that none of the displaced funds left the chain. 11:24 UTC: MANTRA confirms the vulnerability has been identified and a patched release is in preparation; validator coordination required before restart. 12:44 UTC: @MANTRA_Chain publicly states the incident 'was isolated to the Cosmos EVM module of MANTRA Chain and affected two wallet addresses before we achieved containment. No user funds were exploited.' 15:57 UTC: Patch v8.4.0 undergoes testing on the DuKong testnet; team reiterates the incident affected only two MANTRA-managed wallets, with no indication of user, exchange, or partner fund impact. 21:44 UTC: Root cause analysis complete, v8.4.0 validated against an internal environment replicating mainnet state through repeated end-to-end upgrade rehearsals; the store upgrade itself is empty (no module changes, no state migrations), so the upgrade completes in seconds once the validator set is coordinated. Chain remains halted at block 17,449,398 pending full validator coverage — team explicitly prioritizes coordination over speed. Aug 22, 05:30 UTC: MANTRA Chain mainnet resumes producing blocks following the coordinated v8.4.0 restart. Official confirmation: 'User balances were not altered by the incident and no action is required from token holders. There was no rollback or state changes between the halt and chain resumption.' Public RPC/EVM endpoints restored; explorers and downstream services catching up. This is the only incident in the observation window fully resolved — patched and restarted — within 24 hours of window close.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)