MANTRA Reports $3.6M in MANTRA Stolen Due to Cosmos EVM Vulnerability Attack

iconChainthink
Share
AI summary iconSummary
On August 20, MANTRA reported a security incident in which an attacker exploited an unsigned integer underflow in the Cosmos EVM upstream module, resulting in the theft of approximately 720 million MANTRA tokens (USD 3.6 million) from two unauthorized addresses. The vulnerability was patched in the development branch on May 15 but was only merged into the release branch on August 19. The chain was halted on August 21 and resumed 30 hours later. Approximately 94.7% of the stolen funds were transferred to an exchange, while 5.27% remain frozen. On-chain analysis indicates no impact on customer accounts or smart contracts.

ChainThink reports that, according to the official MANTRA report, on August 20, an attacker exploited an unsigned integer underflow vulnerability in the upstream module of Cosmos EVM, transferring 720,923,967.99 MANTRA tokens from two unauthorized addresses—equivalent to approximately $3.6 million at the rate of about $0.005 per token on the day of the incident.

Of these, 600 million tokens originated from a burn address, and 121 million tokens came from a genesis multisig address associated with incentives. The attack did not involve validator keys, admin keys, governance permissions, or multisig signers; the attacker did not gain privileged access.

MANTRA stated that the vulnerability was fixed on the Cosmos EVM development branch on May 15, but was not backported to the release branch until August 19, leaving downstream chains with only about 20 hours between the initial attack and the patch—insufficient time to respond adequately.

The first on-chain anomalous transfer occurred on August 21 at 3:06. It was detected nearly four hours later because the burn address had previously been considered non-transferable and was not covered by monitoring.

The MANTRA Chain halted at 7:13 and was restarted after 30 hours and 13 minutes by 38 independent validators coordinating on the patched version v8.4.0, without any rollback or state rewrite.

The report states that approximately 94.7% (683 million) of the stolen funds were transferred via 15 transactions to deposit addresses at a cryptocurrency exchange, while the remaining 37.96 million (5.27%) are still held in the attacker’s accounts and have been frozen; however, it emphasized that “freezing does not equate to recovery,” and the recovery of funds has entered the law enforcement investigation phase.

MANTRA states that no customer accounts, exchange custody balances, or application contracts have been debited; however, the network outage has had a substantial impact on the ecosystem, and new monitoring rules have been implemented to detect anomalies such as discrepancies between transaction account sources and signers.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.