CASABLANCA, August 29, 2026
MANTRA Chain said its Aug. 20 exploit resulted in an unauthorised transfer of 720,923,967.99 MANTRA tokens, worth about $3.6 million at the pre-incident spot price, from a burn address and a legacy multisig, a material expansion from its initial notice that two project-managed wallets had been affected.
The Aug. 28 post-mortem gives the first full loss-impact account of the incident. It says no customer account, exchange-held customer balance, deposit address or application contract was debited, but the event increased circulating supply, halted the network for 30 hours and 13 minutes, and left exchange deposits and withdrawals restricted at some venues for longer.
CoinGecko’s MANTRA market page showed the token near $0.004125 when reviewed, up 0.6% over 24 hours. The page listed a roughly $26.2 million market capitalization, about $4.68 million in 24-hour volume and a $0.004004 to $0.004173 daily range, close to the Aug. 26 all-time low of $0.004004.
MANTRA said the attacker “moved 720,923,967.99 MANTRA from two addresses that had not authorised the transactions.” It valued the transfer at approximately $3.6 million using a $0.005 token price at the end of Aug. 20 UTC, a historical valuation rather than a current recovery amount or an estimate of what the attacker realized.
The post-mortem changes the earlier MANTRA Chain halt report, which correctly reflected the company’s then-limited disclosure: two MANTRA-managed wallets, no reported third-party loss and no token amount. The new document names the addresses’ roles, details the transaction sequence and states that 37.96 million tokens remain immobilised.
The distinction is consequential for supply and market structure. The tokens were not newly minted, MANTRA said, but balances previously treated as economically inert became transferable, increasing circulating supply and creating a much more concrete recovery and liquidity question for a chain marketed around tokenized real-world assets.
MANTRA
MANTRAMANTRA Post-Mortem Confirms 720.9M Token Transfer
The dedicated impact check is clear about what the $3.6 million figure does and does not establish. It is MANTRA’s valuation of the 720.9 million-token transfer at the pre-incident price, not a confirmed final economic loss, recovered sum or measure of user funds taken. The project says no customer balances were debited.
The first unauthorised debit occurred at 19:06 UTC on Aug. 20, when the attacker moved 600,000,035.56 MANTRA from the chain’s burn address. At 22:59 UTC, the attacker moved another 120,923,932.44 MANTRA from a legacy genesis-era multisig linked to an incentive campaign.
MANTRA says 15 outbound transfers sent 682,966,951.64 MANTRA, or 94.7% of the extracted amount, to one exchange deposit address. It said the remaining approximately 37.96 million tokens, 5.27% of the total, stayed in the attacker account and were immobilised by the halt and an account restriction in v8.4.0.
No tokens had been recovered as of Aug. 28. MANTRA said recovery requests had been sent through the exchange route and law enforcement was working directly with the platforms involved. Immobilised funds are not recovered funds, and the project has not disclosed the receiving exchange, attacker identity, a return timetable or a final treatment for any restrained amount.
The fuller disclosure also helps separate this incident from other recent security events. Cosmos Labs’ broader post-mortem says the same shared Cosmos EVM defect was exploited across six networks, with an estimated $5.72 million sold through decentralized and centralized exchanges. MANTRA’s document supplies its chain-specific accounting within that wider supply-chain event.
Burn Address and Legacy Multisig Drove the MANTRA Exploit
MANTRA attributes the exploit to an unsigned-integer underflow in the upstream cosmos/evm balance-accounting layer. Native balances are tracked through both the EVM state and Cosmos SDK bank module; the project says the affected code could subtract more than an account’s spendable balance without rejecting the operation, causing the unsigned value to wrap to a very large number.
The attacker paired that defect with a specially constructed account and the staking precompile, according to MANTRA. The result was an unauthorised debit of accounts that had not signed a transaction. MANTRA said no validator keys, administrator keys, governance controls or multisig signers were compromised, and the attack did not require privileged access.
The project’s monitoring did not alert on the first transfer because it treated the burn address as impossible to debit. The address had no associated public key, a sequence number of zero and no history of signing, the report said. That assumption was invalid once the balance-accounting path could be corrupted.
The patch in v8.4.0 adds the underflow guard and blocks permissionless creation of the special account type used as the exploit precondition, MANTRA said. It also restricted the attacker account after the halt. The Cosmos EVM advisory similarly says affected operators need a coordinated upgrade to patched releases rather than a configuration-only mitigation.
Recovery Stays Open After 30-Hour MANTRA Chain Outage
MANTRA halted at 23:13 UTC, 14 minutes after the second unauthorised transaction, and resumed block production at 05:26 UTC on Aug. 22 after validators coordinated the v8.4.0 restart. The team says the chain returned without a rollback, state rewrite or invalidation of legitimate confirmed transactions.
That operational recovery does not settle the supply question. MANTRA says its native total supply, which includes the burn address, did not materially increase, but its circulating supply did because the two affected balances had previously been excluded as economically inert. Some third-party trackers use a different total-supply convention, so moving about 600 million tokens out of the burn address can appear as a reported supply increase even though no new tokens were minted.
For holders, exchange availability still needs separate confirmation. A restarted chain does not itself restore every venue’s deposits, withdrawals or compliance controls, and MANTRA said some platforms kept services suspended longer. The next hard facts to watch are an updated circulating-supply statement, proof of returned or permanently restrained tokens, exchange-service notices and a law-enforcement outcome.
The episode also underscores that an upstream patch can leave a downstream coordination gap. MANTRA says the flaw was not code it authored, but it was code running on its mainnet; its post-mortem says it will press upstream maintainers for clearer severity, affected-version and adoption-window disclosure. That is a different problem from a token-contract exploit, yet it has the same practical demand for timely containment.
Crypto sentiment was still in Greed territory despite the chain-specific security update. Alternative.me’s Crypto Fear and Greed Index read 68 on Aug. 29, down from 73 a day earlier.
Fear & Greed Index
Aug. 29, 2026MANTRA’s post-mortem closes the information gap around the two managed wallets but not the recovery case. Its most important additions are the 720.9 million-token transfer, the historical $3.6 million valuation, the 37.96 million restrained balance and the acknowledgement that a customer-fund finding does not erase the outage, circulating-supply or exchange-access consequences.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | MANTRA Chain: Aug. 20, 2026 full incident post-mortem |
| | Cosmos EVM: GHSA-7g4w-cg88-2cq2 security advisory |
| | Cosmos Labs: Cosmos EVM post-mortem |
| | CoinGecko: MANTRA price and market data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
How many MANTRA tokens were transferred in the August exploit?
MANTRA's Aug. 28 post-mortem puts the unauthorised transfer at 720,923,967.99 MANTRA. The project valued that amount at about $3.6 million using the pre-incident spot price of $0.005 per token at the end of Aug. 20 UTC.
Did the MANTRA exploit take customer funds?
MANTRA says no customer account, exchange-held customer balance, deposit address or application contract was debited. The affected balances were its burn address and a legacy genesis-era multisig tied to an incentive campaign, though the incident still disrupted users through a 30-hour chain outage and later exchange restrictions.
Were any MANTRA tokens recovered after the exploit?
As of Aug. 28, MANTRA said no tokens had been recovered. About 37.96 million MANTRA remained immobilised in the attacker account, while the rest of the proceeds had been traced through a receiving exchange route and referred to law enforcement.
What caused the MANTRA Chain exploit?
MANTRA says the attacker used an unsigned-integer underflow in the upstream cosmos/evm balance-accounting layer. The project says the exploit required no validator, administrator, governance or multisig-key compromise and has been patched in MANTRA Chain v8.4.0.



