Invest1 distinct publisher3 min readPublished
MANTRA says the flaw sat in cosmos/evm rather than in its own code, which works as a defence and as a warning to every chain on that module. Validators halted the network only after 94.7% of the 720.9 million tokens were already gone.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The attacker's wallet still contained 37.96 million tokens when validators pulled the network at 23:13 UTC, fourteen minutes after the second drain [8], out of 720,923,967.99 moved in total [3], which is 5.3 percent [1] and leaves 94.7 percent, or roughly 683 million tokens, already off-chain [2]. Marked at the pre-incident five-tenths of a cent, the stranded remainder is about $189,800 [3]. Law enforcement is involved and recovery updates are pending [11], which is roughly what a project says when the arithmetic looks like that.
The mechanism is the plain kind. The affected cosmos/evm version approved subtractions from an account balance without first checking the account could cover the call, and because balances are unsigned integers, a subtraction below zero wrapped upward into an enormous number rather than failing [4]. MANTRA says no validator key or governance control was breached, and that the attacker needed no privileged access at all: a permissionlessly deployed contract and a self-funded wallet were sufficient [5][6]. That is the part that travels. The flaw lived in the shared module MANTRA uses to run Ethereum-style contracts on a Cosmos SDK chain [2], so the live question for any other operator is not whether MANTRA's engineers were sloppy but which version of that module they themselves are running, and the post-mortem, which names v8.4.0 as the patched release validators restarted on after 30 hours and 13 minutes offline [9], supplies no inventory of the other chains sitting on the affected code.
The $3.6 million is a price, and a stale one. It marks 720.9 million tokens at $0.005, where they traded before the incident [3]; during the halt the token printed a record low near $0.004126 [13], which is 17.5 percent below that mark [4], so the 18.5 percent decline CoinGecko recorded was measured against some other reference [13][4]. An attacker liquidating 682.96 million tokens, nominally $3.41 million [5], is selling into a bid the theft itself moved. MANTRA frames the event as 720.9 million economically inert tokens entering circulation, with no tokens minted and no customer balance debited [7], and the circulating supply restatement is deferred until it knows what is stuck in hacker wallets [11].
The counter-read, or rather the more interesting version of it, is that this was an accounting correction: a burn address that nobody watched around the clock [10] was not a burn address but a holding account with a good name, and the honest supply figure was always the larger one. This is probably wrong, but I think the dependency exposure matters more than the $3.6 million, because an unchecked subtraction is bounded only by whatever inert balances a chain has parked where it is not looking, and the split here was 600 million from the burn address plus 120.9 million from a dormant genesis-era multisig tied to an old incentive campaign [12]. What would falsify it: a cosmos/evm disclosure timeline showing the fix was available before August 20, which makes this a patching failure rather than a shared one. For Inveniam Capital Partners, which put $20 million in during 2025 and agreed in June to acquire the project [14], the event is 18 percent of that cheque [6], and set against an April 2025 session that took the old OM token down more than 90 percent and erased over $5 billion [15], it barely registers.
Ranked by verification strength, evidence, and original report placement.
The network remained offline for 30 hours and 13 minutes until 05:26 UTC on August 22, after validators coordinated a restart on the patched v8.4.0 release.
MANTRA Chain published a full incident post-mortem on August 28 covering the August 20-21 incident, and stopped short of committing to a fund recovery plan.
The post-mortem says the exploit started at the shared cosmos/evm module MANTRA uses to run Ethereum-style contracts on top of the Cosmos SDK, and MANTRA insists the code flaw did not come from its own end.
The attacker moved 720,923,967.99 MANTRA in total, worth about $3.6 million at the pre-incident price of $0.005 per token.
The affected cosmos/evm version did not check that an account could cover a call before approving subtractions from the account's balance; because the code used unsigned integers, which cannot go below zero, the subtraction wrapped around to an enormous number.
The attacker ran two transactions and moved most of the haul off-chain before validators halted the network at 23:13 UTC, 14 minutes after the second drain; the attacker's wallet still contained 37.96 million tokens at the halt.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
MANTRA froze its chain and left the order book open: RWA's risk is plumbing, not story1 distinct publisher
invest
Cosmostation shuts every wallet platform on September 1, leaving 18 days and a key export1 distinct publisher
security
Provenance's marker module let anyone with zero tokens claim admin over 82 live financial assets1 distinct publisher
invest
Bitcoin ETFs have bought for eight straight sessions, and each one is smaller1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One document, one outlet
Strip out CoinGecko's price line and every number in this story — the 720,923,967.99 tokens, the 23:13 UTC halt, the four-hour blind spot, the untouched customer balances — comes from a post-mortem written by MANTRA about MANTRA, relayed by a single trade publication. The internal detail is unusually specific, and the admission of missed monitoring cuts against the author's interest, which is why this is not lower. But no auditor, no chain analytics firm and no cosmos/evm maintainer appears anywhere in the reporting.
Patched at home, unmeasured upstream
What is concretely observable is narrow but real: a chain halted, a patched v8.4.0 restart 30 hours later, unnamed exchanges holding deposits shut for longer. What is missing is the number that would matter most — how many other chains import the affected cosmos/evm module and how many are now running fixed code. The story frames the bug as everyone's problem and then measures only MANTRA's yard.
The exoneration outruns the proof
The overstatement here is not the loss — $3.6 million is modestly framed — it is the comfort. 'Not our code,' 'no privileged access,' 'no customer funds debited,' tokens that were 'economically inert': four reassurances, all unverified, all authored by the party under investigation. Against them sit two facts the same document concedes: four hours of no detection, and a halt that landed after roughly 94.7% of the tokens had left. The clean-up reads cleaner than the containment was.
The accused wrote the report
Follow who benefits from each framing. MANTRA is mid-acquisition by an investor already $20 million in, rebuilding after a 90% single-session collapse, and it is the sole author of the account that locates the flaw upstream in a shared module, classifies the drained tokens as inert, and defers both the recovery promise and the circulating supply restatement to an unspecified later date. Every one of those choices reduces the blast radius for the party making it.
Firm timeline, wobbly arithmetic
The sequence — first drain, four-hour gap, second drain, halt 14 minutes later, restart on v8.4.0 — is coherent and specific enough to be checkable, and the derived shares follow directly from it. Confidence drops on the price figures: an 18.5% fall to $0.004126 cannot be measured from the $0.005 used to value the loss, and the same piece places the restart at 05:26 UTC in one place and about 05:30 in another. Small slips, but they are the ones a second outlet would have caught.