BlockBeats News, August 28th, MANTRA Chain released a full recap report of the security incident on August 20th, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance-keeping layer of the upstream dependency cosmos/evm. The attacker unauthorizedly transferred a total of 720,923,967.99 MANTRA from two addresses, totaling approximately $3.6 million in value based on the pre-attack price.
During the incident, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multisig address related to an early incentive activity. MANTRA stated that this event did not involve validator keys, admin permissions, governance control, or multisig signer leaks. The attacker did not require privileged access and was able to complete the attack solely through unauthorized contract deployment and self-funded wallets.
MANTRA stated that the first unusual transfer occurred on August 20th at 19:06 UTC, where the attacker moved around 6 billion MANTRA from the burn address. Subsequently, at 22:59 UTC, about 120.9 million MANTRA was transferred again. The on-chain operations then halted at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.
This vulnerability was not due to MANTRA's own code but rather originated from the cosmos/evm module, responsible for providing EVM functionality on the Cosmos SDK. The flaw allowed the attacker to perform an unsigned balance deduction without checking if the balance was sufficient, causing a numeric underflow to circumvent normal account authorization logic.
As of August 28th, MANTRA stated that no funds have been recovered. Approximately 37.96 million MANTRA (5.27% of the total transferred amount) is still held in the attacker's addresses, frozen due to the chain halt and v8.4.0 restrictions. The remaining funds have flowed to related exchanges, and the recovery efforts have entered a law enforcement investigation phase. Future steps will involve strengthening monitoring of accounts unable to transfer funds normally, historical "non-transferable" addresses like burn addresses, and driving improvements in the Cosmos ecosystem's security vulnerability disclosure process.

