CryptoReal
CASE FILE — Aug 31, 2026

MANTRA Exploit Highlights Critical Cosmos EVM Underflow Bug and Delayed Response

On August 20, over 720 million MANTRA tokens, valued at approximately $3.6 million prior to the incident, were withdrawn from two wallets controlled by MANTRA. Nearly all of these assets—94.7%—were transferred to a single exchange deposit address before MANTRA initiated a chain halt, which only managed to lock the residual balance. (source)

MANTRA's postmortem, made public on August 28, identifies the root issue (source): two interrelated vulnerabilities in the balance-accounting layer of the shared Cosmos EVM module, an open-source framework also utilized by multiple other blockchains. Not all users of this stack may have independently reviewed its security.

A flaw—a classic unsigned-integer underflow—inflated the EVM-side balance of a vesting account artificially. The attacker then exploited this by transferring the manipulated balance to either a victim account, a burn address, or a genesis multisig, resulting in an overflow that shifted the victim’s holdings to the attacker. The exploit was executed through a contract that leveraged the staking precompile, enabling unauthorized debits from MANTRA's wallets without access to private keys—a gap the software failed to prevent.

This marks MANTRA’s second major setback in just over a year. The incident follows the April 2025 internal sell-off that eliminated about $5 billion from the ecosystem, as previously detailed in earlier coverage.

The response this time was swifter: Fourteen minutes after a second unauthorized transfer, MANTRA halted its chain, then released a patch and resumed operations after 30 hours and 13 minutes (source). During the same week, three additional blockchains suffered similar attacks linked to the Cosmos EVM cluster (source).

As of the August 28 postmortem, no stolen funds had been recovered.

While the vulnerability is now confirmed and the halt did contain part of the loss, most of the tokens were unrecoverable, having already been sent to an exchange address.

01Timeline and Initial Disclosure

MANTRA reported the incident on August 20, stating only that it was "aware of an incident," had paused the chain as a precaution, and lacked both a root cause and timeline for resolution (source). No transaction or token amounts were initially provided. Nine hours later, a follow-up confirmed the issue was isolated to the Cosmos EVM module, affected two MANTRA-controlled wallets, and did not involve user funds—but still omitted any figures (source).

External blockchain analysts first pieced together the details. Rarma identified that 600,000,035.55 MANTRA were withdrawn from the burn address and 120,923,932.44 MANTRA from a genesis multisig. The stolen tokens moved through a single wallet, which executed 24 transactions before becoming inactive. Initially, it was believed that none of the stolen funds had left the chain to be liquidated.

MANTRA’s postmortem eventually quantified the loss at roughly $3.6 million, referencing a pre-incident spot price of $0.005 per token (source). It took MANTRA eight days to confirm the details that blockchain analysts had already uncovered within hours.

02Timeline of the Vulnerability and Patch

The vulnerability’s roots trace back to May. On May 13, Cosmos Labs opened a pull request to “harden statedb balance and event amount handling,” intending to prevent underflows and improve denomination awareness (source). The fix was merged into the main branch two days later, on May 15. A detailed write-up on the exploit’s mechanics was published by an independent researcher on July 27 (source).

Backporting the fix to release branches began only on August 13 (source), and both PR #1253 and #1254 were merged on August 19. On that day, Cosmos Labs released v0.7.2, labeling it as containing “important security fixes” and urging a coordinated upgrade (source). MANTRA’s relevant version, v0.6.2, was published about 20 hours before the attack. However, neither release specifically mentioned the underflow bug or its risks.

At 07:16 UTC on August 20, a public pull request on Push Chain’s fork explicitly described the vulnerability and its exploitation (source), about 12 hours before MANTRA’s attack and 16 hours before the chain halt.

Sums referenced in this case file

Both MANTRA’s and Cosmos Labs’ postmortems (source, source) confirm the exploit: an underflow in the balance-accounting layer, triggered by a crafted vesting account and transaction via the staking precompile. This flaw allowed an attacker to manipulate spendable balances, withdraw from burn or multisig addresses, and redirect the balance to themselves in a supply-neutral transaction.

Attack steps as reconstructed:

  • At block 17,444,907 (19:04:50 UTC, Aug. 20), an attacker-controlled address submitted a CreateVestingAccount message (tx)
  • Seventy seconds later, block 17,444,928, 600,000,035.56 MANTRA was transferred from the burn address to the attacker (address)
  • At 22:58:47 UTC, a nearly identical procedure drained 120,923,932.44 MANTRA from the genesis multisig (tx, address). Cosmos Labs independently verified both as part of the MANTRA exploit series.

Although protections against this bug were available months prior, they were not applied to the affected release or chain in time.

03Incident Execution and Immediate Aftermath

Within minutes of each drain, the attacker dispatched 24 transactions, quickly moving nearly all extracted tokens in batches to a single exchange deposit address (source). MANTRA halted the chain at 23:13 UTC, fourteen minutes after the second major transaction. At that moment, 682,966,951.64 MANTRA—equivalent to 94.7% of the stolen funds—had already reached the exchange, while about 5.27% (38 million MANTRA) remained in the attacker’s wallet (address).

The market reacted sharply: MANTRA's price dropped 18.5% to a record low, and trading volumes increased almost sixfold (source).

A hotfix (v0.6.0-v8-mantra-6) was released at 02:28:46 UTC on August 21 (source), and the patched network (v8.4.0) resumed block production at 05:26 UTC on August 22 (source). Cosmos Labs’ postmortem gives a slightly different restart time (03:38:07 UTC), which remains unresolved. There was no rollback of the chain or user balances; the only change was to restrict the attacker’s address. As of August 28, all remaining stolen funds, including those frozen, had not been recovered (source).

No stolen tokens were bridged to other blockchains; almost all ended up at an exchange on MANTRA Chain before the halt.

04Impact on Other Chains and Broader Disclosure Issues

MANTRA’s swift halt limited losses, but other Cosmos EVM-based chains were less fortunate. On August 22, TAC and KiiChain also suffered major attacks (sources, [https://x.com/KiiChainio/article/2091721027583709214]), with 2.98 billion TAC and 148.3 million KII drained, respectively. TAC’s attacker bridged tokens to BNB Chain within 95 seconds, well before the project’s own halt was initiated. KiiChain managed to freeze 54.4% of its stolen funds on-chain, but most of the rest was bridged out and sold. Nesa, another project, also responded to related malicious activity soon afterward (source).

Cosmos Labs released v0.7.2 with the underflow fix on August 19, but it wasn’t until August 25 that affected chains were advised to halt and upgrade (source). Cosmos Labs acknowledged the ongoing security incident on August 24 (source), after MANTRA had already halted and TAC and KiiChain faced attacks.

KiiChain’s postmortem (source) criticized Cosmos Labs for disclosing the patch publicly before privately warning affected chains, arguing that this handed the exploit details to potential attackers. Other developers echoed this sentiment, calling the disclosure “negligent AF” (source).

MANTRA’s own account adds that its engineers reported both the bug and the ongoing exploit to Cosmos Labs, which then alerted other chains privately—yet the advisory still recommended only upgrading, not halting, until after TAC was compromised (source). Thus, MANTRA’s incident prompted a broader response, but it was not quick enough to protect the other chains.

These events occurred as MANTRA was still dealing with the aftermath of its April 2025 collapse and during acquisition talks with Inveniam Capital Partners (source).

In summary, the same underflow vulnerability was exploited across four blockchains in five days, despite a fix existing months prior. The communications and upgrade process failed to prevent widespread losses. By the time emergency halts were implemented, assets from TAC and KiiChain had already been bridged out and sold.

Final numbers: 720,923,967.99 MANTRA (about $3.6 million) was extracted from two wallets, with MANTRA reporting no end-user funds were affected. Almost all tokens reached an exchange deposit address before the halt. As of the postmortem, no recovery had occurred.

While the technical root cause is now public and confirmed, and the network was restored within 30 hours, the absence of fund recovery and delays in transparent disclosure raise questions about the effectiveness of incident response processes in decentralized infrastructure. In this case, a prompt halt contained only a small fraction of the loss, and “contained” recovery remains elusive.

References: Rarma, MANTRA, Grey Ledger, Cosmos Labs, TechTimes, CoinDesk, TAC, KiiChain, Nesa, De, Protos, The Coin Republic

CosmosMantra
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.