MANTRA Chain resumes blocks after Cosmos-EVM fix

Paxful
Bybit


MANTRA Chain has resumed block production after deploying version 8.4.0 to fix a Cosmos-EVM vulnerability that kept its mainnet unable to process transactions for about 30 hours.

Summary

  • MANTRA Chain restarted at approximately 5:30 a.m. UTC on Aug. 22.
  • Version 8.4.0 patched a Cosmos-EVM vulnerability and added security protections.
  • Two MANTRA-managed wallets were affected, but user balances remained unchanged.
  • MANTRA plans to publish a complete post-incident report in the coming days.

MANTRA Chain said in an Aug. 22 post that its mainnet was producing blocks again after developers fixed the vulnerability found in its Cosmos-EVM module.

The restart followed a coordinated software update involving MANTRA-operated validators and other members of the network’s validator set. According to the project’s incident status page, block production resumed at about 5:30 a.m. UTC on Aug. 22 through the patched v8.4.0 release.

okex

User balances were not changed during the incident, while the restart involved no blockchain rollback or alteration of the network state, the status update said. Token holders were also told that they did not need to take any action.

MANTRA Chain halted after an attacker targeted its EVM module

The incident began late on Aug. 20, when MANTRA detected an attacker exploiting a vulnerability in an upstream software dependency used by the blockchain. Developers responded by halting the mainnet, preventing transactions from being processed while security teams investigated the activity.

MANTRA’s initial notice said all transactions and network endpoints had been frozen. The shutdown also stopped transfers, staking operations, bridges and MANTRA-managed inter-blockchain communication relays, while some exchanges paused deposits and withdrawals connected to the network.

As crypto.news reported on Aug. 21, the halt took validators, public endpoints and bridge services offline, leaving assets temporarily unable to move on the RWA-focused Layer 1.

Later in the investigation, MANTRA traced the vulnerability to its Cosmos-EVM module and said the activity affected two wallet addresses before developers contained the threat. Its status page subsequently identified them as MANTRA-managed wallets and said there was no indication that user, exchange, or partner funds had been directly affected.

“No user funds were exploited,” the project said in an update after identifying the source of the incident.

MANTRA has not disclosed what activity occurred in the two managed wallets, how much value was involved, or whether any assets left the addresses. The project also has not released the attack path or named the specific upstream software component responsible for the vulnerability.

Before beginning the restart process, the team took a complete snapshot of the blockchain at the halted state. Mainnet remained stopped at block 17,449,398 while developers reviewed known attack paths and prepared the patch.

Version 8.4.0 enabled the coordinated restart

Following the initial investigation, developers built v8.4.0 to repair the vulnerability in the EVM module and add supplementary security protections. MANTRA first tested the release on its DuKong testnet before validating it in an internal environment that replicated the mainnet state.

Repeated upgrade rehearsals were completed before validators received the signal to restart. According to the incident page, the software update did not require module changes, state migrations, or changes to the blockchain’s stored data.

MANTRA-operated validators were upgraded first, followed by validator partners, ordinary node operators, RPC services, and archive nodes. The team said it chose a coordinated restart because bringing back only part of the validator set could have created operational problems.

Block production returned roughly 30 hours after the last reported block was processed at about 11:13 p.m. UTC on Aug. 20. Public RPC and EVM endpoints later became operational, although the project warned that explorers, indexers and other services could lag while processing data created after the restart.

DuKong remained offline after the mainnet returned. MANTRA said work to restore the public testnet would continue over the next several days as engineers monitored mainnet stability.

The affected Cosmos-EVM component forms part of MANTRA’s system for running Ethereum-compatible smart contracts. In September 2025, the chain added EVM support alongside CosmWasm, allowing developers to deploy applications using either environment on the RWA-focused network.

Earlier Cosmos EVM flaw remains unconfirmed as the cause

The incident has drawn attention to a separate critical vulnerability disclosed by Cosmos Labs in March 2026. Security advisory ASA-2026-002 described an error in the ICS20 precompile, a component that allows EVM smart contracts to initiate cross-chain token transfers through the Inter-Blockchain Communication protocol.

According to the Cosmos EVM advisory, incorrect state handling during nested EVM execution could allow the same token balance to be used repeatedly within one transaction. The flaw led to an estimated $7 million loss on Saga EVM in January.

Cosmos Labs identified 15 chains running code containing the flaw. Six did not have the affected feature enabled, one was exploited, and the remaining networks applied a mitigation before an attack occurred, according to the advisory.

MANTRA was named among the teams that helped investigate and address the earlier issue. Cosmos Labs said the permanent repair was included in Cosmos EVM version 0.6.0 and that known affected chains had either upgraded or disabled the vulnerable component.

Neither MANTRA nor Cosmos Labs has said the Aug. 20 incident used the same ICS20 flaw. Until MANTRA publishes its technical report, attributing the latest exploit to that previously disclosed vulnerability would go beyond the available evidence.

MANTRA price hit a record low before the halt

During the hours surrounding the incident, the MANTRA token fell from approximately $0.005060 to a record low of $0.004126, a decline of about 18.5%. CoinGecko data cited in market reports placed the low at roughly 11:10 p.m. UTC on Aug. 20, minutes before the network’s last reported block.

Trading volume rose nearly 600% to approximately $24 million during the initial market reaction. MANTRA has not said the token selloff was related to the attack, leaving any link between the price movement and the incident unconfirmed.

Earlier in March, the token had risen 62% after MANTRA completed a rebrand, network upgrade, and 1:4 non-dilutive token split. Under the change, holders received four MANTRA tokens for every former OM token without altering the total value of their holdings at the conversion point, according to March market coverage.

For U.S. token holders using MANTRA’s native network, the chain halt prevented the same on-chain transactions, staking, and transfers that were unavailable in other regions. The project did not identify a separate impact on American users, and its confirmation that user balances remained unchanged applied to token holders generally.

MANTRA’s network focuses on tokenized real-world assets and is tied to several institutional projects. In June, Inveniam Capital Partners announced an agreement to acquire MANTRA and its affiliated entities after making a $20 million strategic investment in the company in August 2025, as detailed in the acquisition announcement.

The companies had also worked on NVNM Chain, a Layer 2 network built on MANTRA Chain for private-market asset data. MANTRA said a complete post-incident analysis covering the Cosmos-EVM vulnerability and the network’s response will be released in the coming days.



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*