MANTRA Chain resumes blocks after Cosmos-EVM fix
MANTRA Chain has resumed block production after deploying version 8.4.0 to fix a Cosmos-EVM vulnerability that kept its mainnet unable to process transactions for about 30 hours.
Summary
- MANTRA Chain restarted at approximately 5:30 a.m. UTC on Aug. 22.
- Version 8.4.0 patched a Cosmos-EVM vulnerability and added security protections.
- Two MANTRA-managed wallets were affected, but user balances remained unchanged.
- MANTRA plans to publish a complete post-incident report in the coming days.
MANTRA Chain said in an Aug. 22 post that its mainnet was producing blocks again after developers fixed the vulnerability found in its Cosmos-EVM module.
The restart followed a coordinated software update involving MANTRA-operated validators and other members of the network's validator set. According to the project's incident status page, block production resumed at about 5:30 a.m. UTC on Aug. 22 through the patched v8.4.0 release.
User balances were not changed during the incident, while the restart involved no blockchain rollback or alteration of the network state, the status update said. Token holders were also told that they did not need to take any action.
You might also like: MANTRA price falls 10% as network halts transactions
MANTRA Chain halted after an attacker targeted its EVM module
The incident began late on Aug. 20, when MANTRA detected an attacker exploiting a vulnerability in an upstream software dependency used by the blockchain. Developers responded by halting the mainnet, preventing transactions from being processed while security teams investigated the activity.
MANTRA's initial notice said all transactions and network endpoints had been frozen. The shutdown also stopped transfers, staking operations, bridges and MANTRA-managed inter-blockchain communication relays, while some exchanges paused deposits and withdrawals connected to the network.
As crypto.news reported on Aug. 21, the halt took validators, public endpoints and bridge services offline, leaving assets temporarily unable to move on the RWA-focused Layer 1.
Later in the investigation, MANTRA traced the vulnerability to its Cosmos-EVM module and said the activity affected two wallet addresses before developers contained the threat. Its status page subsequently identified them as MANTRA-managed wallets and said there was no indication that user, exchange, or partner funds had been directly affected.
"No user funds were exploited," the project said in an update after identifying the source of the incident.
MANTRA has not disclosed what activity occurred in the two managed wallets, how much value was involved, or whether any assets left the addresses. The project also has not released the attack path or named the specific upstream software component responsible for the vulnerability.
Before beginning the restart process, the team took a complete snapshot of the blockchain at the halted state. Mainnet remained stopped at block 17,449,398 while developers reviewed known attack paths and prepared the patch.
Version 8.4.0 enabled the coordinated restart
Following the initial investigation, developers built v8.4.0 to repair the vulnerability in the EVM module and add supplementary security protections. MANTRA first tested the release on its DuKong testnet before validating it in an internal environment that replicated the mainnet state.
Repeated upgrade rehearsals were completed before validators received the signal to restart. According to the incident page, the software update did not require module changes, state migrations, or changes to the blockchain's stored data.
MANTRA-operated validators were upgraded first, followed by validator partners, ordinary node operators, RPC services, and archive nodes. The team said it chose a coordinated restart because bringing back only part of the validator set could have created operational problems.
Block production returned roughly 30 hours after the last reported block was processed at about 11:13 p.m. UTC on Aug. 20. Public RPC and EVM endpoints later became operational, although the project warned that explorers, indexers and other services could lag while processing data created after the restart.
DuKong remained offline after the mainnet returned. MANTRA said work to restore the public testnet would continue over the next several days as engineers monitored mainnet stability.
The affected Cosmos-EVM component forms part of MANTRA's system for running Ethereum-compatible smart contracts. In September 2025, the chain added EVM support alongside CosmWasm, allowing developers to deploy applications using either environment on the RWA-focused network.
Earlier Cosmos EVM flaw remains unconfirmed as the cause
The incident has drawn attention to a separate critical vulnerability disclosed by Cosmos Labs in March 2026. Security advisory ASA-2026-002 described an error in the ICS20 precompile, a component that allows EVM smart contracts to initiate cross-chain token transfers through the Inter-Blockchain Communication protocol.
According to the Cosmos EVM advisory, incorrect state handling during nested EVM execution could allow the same token balance to be used repeatedly within one transaction. The flaw led to an estimated $7 million loss on Saga EVM in January.
Cosmos Labs identified 15 chains running code containing the flaw. Six did not have the affected feature enabled, one was exploited, and the remaining networks applied a mitigation before an attack occurred, according to the advisory.
MANTRA was named among the teams that helped investigate and address the earlier issue. Cosmos Labs said the permanent repair was included in Cosmos EVM version 0.6.0 and that known affected chains had either upgraded or disabled the vulnerable component.
Neither MANTRA nor Cosmos Labs has said the Aug. 20 incident used the same ICS20 flaw. Until MANTRA publishes its technical report, attributing the latest exploit to that previously disclosed vulnerability would go beyond the available evidence.
-- Price
MANTRA price hit a record low before the halt
During the hours surrounding the incident, the MANTRA token fell from approximately $0.005060 to a record low of $0.004126, a decline of about 18.5%. CoinGecko data cited in market reports placed the low at roughly 11:10 p.m. UTC on Aug. 20, minutes before the network's last reported block.
Trading volume rose nearly 600% to approximately $24 million during the initial market reaction. MANTRA has not said the token selloff was related to the attack, leaving any link between the price movement and the incident unconfirmed.
Earlier in March, the token had risen 62% after MANTRA completed a rebrand, network upgrade, and 1:4 non-dilutive token split. Under the change, holders received four MANTRA tokens for every former OM token without altering the total value of their holdings at the conversion point, according to March market coverage.
For U.S. token holders using MANTRA's native network, the chain halt prevented the same on-chain transactions, staking, and transfers that were unavailable in other regions. The project did not identify a separate impact on American users, and its confirmation that user balances remained unchanged applied to token holders generally.
MANTRA's network focuses on tokenized real-world assets and is tied to several institutional projects. In June, Inveniam Capital Partners announced an agreement to acquire MANTRA and its affiliated entities after making a $20 million strategic investment in the company in August 2025, as detailed in the acquisition announcement.
The companies had also worked on NVNM Chain, a Layer 2 network built on MANTRA Chain for private-market asset data. MANTRA said a complete post-incident analysis covering the Cosmos-EVM vulnerability and the network's response will be released in the coming days.
Read more: SAND bridge exploit contained after unbacked token mint
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Tether’s USDT0 launches on Stellar with cross-chain liquidity

XRP Ledger tested by BIS researchers for data checks

2026's Most Wild DeFi Yield Strategies: No Betting on Explosive Growth, Just Harvesting On-Chain Speculation Fees

Taiwan's Financial Supervisory Commission to Implement Virtual Asset Regulations by Q1 Next Year

Countdown to Arc Mainnet: Where Will the First Batch of Traffic Flow?

Russian Crypto Trading Awaiting Central Bank Guidelines, Expected to Be Ready by December

Rain contract exploit drains $1.1M from card users

How Uniswap's Fee Switch Redefined Revenue

Arbitrum Nova Migration Window Ends, Transitioning to Minimal Maintenance Mode

Debt Expansion and Currency Shuffle: The Biggest Beta Opportunity in the Crypto Market According to Hayes

Sui Chain DeFi Protocol Full Sail Announces Liquidation: $91,000 Lost Due to Attack on Oracle Switchboard

G20 Supports Regulatory Path for Digital Assets, Strengthens Anti-Money Laundering Enforcement Requirements

Jupiter Launches Universal Deposit, Supporting Multi-Chain Asset Cross-Chain Exchange for USDC
Leverage, Ferraris, and the Law of Attraction: Carl Moon’s "First Life" | WE TALK by WEEX
From a supermarket clerk in Northern Europe to a trader, racer, and musician who dictates his own destiny, Carl Moon’s story isn’t a simple get-rich-quick fantasy. It’s a long-term, self-driven game of goals, discipline, and risk control.

Coldcard Wave 3 Attackers Transfer Stolen Funds for the First Time, Some Assets Converted to ETH

Three Public Chains Halt Operations in Four Days: Who Has the Power to Press the Pause Button?

Kraken IPO delayed until Q2 2027: report

Goldman Sachs, BofA and 19 Other Banks Plan U.S. Dollar Stablecoin Launch

Saudi Arabia Confirms Death of Two Filipino Sailors in Iranian Attack on Oil Tanker

Tracking Cryptocurrency May Be Included in Exporters' Currency Revenue Control

Backpack Adds Micron, SanDisk Shares as Margin Collateral

What is Hedera Hashgraph and how does HBAR work?

Agentic Payment Research Report: From Payment Pathways to Ecological Landscape

What is Chainlink and how does the LINK oracle network work?

Wyoming Adopts Chainlink for FRNT On-Chain Reserve Verification

Crypto Will Eventually Merge with AI Finance

From Glamsterdam to Hegotá: What Will Ethereum Address in Its Next Phase After Scaling?

The Similarities and Differences of Meme from a Long-Cycle Perspective

August Cryptocurrency Security Incident Report: Total Loss of $215 Million, Price Manipulation and Governance Vulnerabilities as Major Attack Methods














