MANTRA Reveals Root Cause Behind $3.6M Exploit and Security Fixes
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- MANTRA Chain lost 720.9 million tokens through an upstream balance accounting flaw.
- The attacker accessed no validator keys, governance systems, or customer balances.
- The team has added new monitoring rules and patched the exploited vulnerability.
MANTRA has published a post-mortem report detailing the attack, response, and security changes following the 20 August 2026 exploit. The report confirmed that an attacker was able to move 720.9 million MANTRA tokens from two inactive addresses without touching validator keys, governance controls, or multisig systems.
The exploit was a result of an unsigned integer underflow bug in the cosmos/evm balance accounting layer. The vulnerability led to a permissionless contract and funded wallet triggering an unauthorized balance subtraction. Furthermore, the attacker did not require privileged access to complete the operation.
MANTRA Identifies Balance Accounting Bug Behind Exploit
The attacker first transferred 600 million MANTRA from the burn address at around 19:06 UTC. Later, another transfer moved about 120.9 million MANTRA from a legacy genesis-era multisig linked to an incentive campaign. The team halted the network at 23:13 UTC after the second transaction. Meanwhile, validators prepared a patched v8.4.0 release and restarted the chain on 22 August after verification checks passed. The restart preserved confirmed transactions without requiring a rollback.
According to the report, the exploit did not create new tokens. Instead, it changed the movement of previously inactive balances into circulation. The affected transfers represented about $3.6 million based on the pre-incident MANTRA price.
The report also stated that no customer account, exchange-held balance, deposit address, or application contract lost funds. However, users experienced service disruption during the 30-hour and 13-minute network halt.
— MANTRA | The EVM L1 for RWAs (@MANTRA_Chain) August 28, 2026
Security Gaps Led to Delayed Exploit Detection Across Systems
The team identified two monitoring gaps during its review. First, the burn address received no active transaction monitoring because the address appeared unable to authorize transfers under normal rules. Moreover, security systems lacked alerts for impossible debits from accounts without public keys or transaction sequences. Such a rule would have detected the first unauthorized transfer immediately, according to the report.
The vulnerability entered through an upstream cosmos/evm component used for EVM support on Cosmos networks. The affected code allowed an unsigned subtraction to continue when the balance lacked enough funds. Moreover, the team reported the issue to the upstream maintainers after determining the cause. The report called for improved disclosure practices for security fixes that impact multiple networks.
MANTRA Outlines Recovery Steps and Future Protections
The team confirmed that no stolen tokens have returned as of 28 August. Around 37.96 million MANTRA remain restricted inside the attacker’s account after the chain applied account restrictions. Meanwhile, recovery efforts continue through law enforcement cooperation and exchange requests. The team said it will publish updated supply information after determining the treatment of recovered, restricted, or unrecoverable tokens.
The updated security plan introduces new monitoring rules for inactive addresses, signer mismatches, and unusual account activity. Additionally, it will expand security checks using raw blockchain events instead of relying only on standard wallet activity. The team also plans to review addresses previously considered unable to move funds. Moreover, it will push for improved communication around upstream security releases and vulnerability disclosures.
At the time of this publication, MANTRA was trading around $0.004800, up by 16% over the last 24 hours. Its market cap and trading volume stand at $30 million and $80 million, respectively.

Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







