MANTRA post-mortem pins $3.6M exploit on a cosmos/evm integer bug

NewsFri, 28 Aug 2026 14:46:29 UTC3 hours ago
MANTRA post-mortem pins $3.6M exploit on a cosmos/evm integer bug

MANTRA Chain stopped short of committing to a fund recovery plan in the full incident post-mortem report it published on August 28. Instead, the publication presented a formal recap of the August 20-21 incident where an attacker drained roughly 720.9 million MANTRA, worth about $3.6 million from the project.

Today’s disclosure formally assigned a dollar value to the one-week-old attack, which the project insists was due to a coding flaw not directly related to its own code.

In the meantime, MANTRA confirmed that law enforcement is now involved and updates are pending fund recovery efforts. It also said that it will update its circulating supply when it has a clearer picture of tokens stuck in hacker wallets and potential recovery.

What caused the MANTRA exploit?

According to the MANTRA Chain post-mortem, the exploit started at the shared cosmos/evm module it uses to run Ethereum-style contracts on top of the Cosmos SDK.

The affected version did not check that an account could cover a call before it approved subtractions from an account’s balance. The subtractions continued to go through because the code used unsigned integers, which cannot go below zero. Instead, it just wrapped around to an enormous number.

… Continue reading the full article at the original source below.

Read from Source · cryptopolitan.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptopolitan.com).

Related