NewsCryptoMANTRA Chain Returns Online as Developers Seek Answers on Silent Code Changes

MANTRA Chain Returns Online as Developers Seek Answers on Silent Code Changes

Author: CryptoNewsNet·

Key Takeaways

  • Mainnet block production on MANTRA Chain restarted on v8.4.0 about 05:30 UTC on Aug. 22 after a six-day outage.
  • MANTRA said there was no rollback or state change during the halt, and user balances were not altered.
  • The company said two MANTRA-managed wallets were affected, while user, exchange, and partner funds were not affected.
  • MANTRA had not published the promised postmortem by Aug. 27, so the exploit method and technical details remained undisclosed.
  • The release record shows a re-pushed v8.4.0 tag and a final upgrade that blocklists one address and disables three Cosmos vesting-account creation messages.
MANTRA Chain Returns Online as Developers Seek Answers on Silent Code Changes

MANTRA Chain Returns Online as Developers Seek Answers on Silent Code Changes

MANTRA Chain has restored mainnet block production on v8.4.0, six days after a security incident forced a chainwide halt. The promised technical account has not yet been published, leaving unexplained the exploitation of the upstream dependency and the activity inside two project-managed wallets.

According to the official incident timeline, mainnet resumed at approximately 05:30 UTC on Aug. 22. The chain said there was no rollback or state change between the halt and the restart, user balances were not altered, and token holders did not need to take any action.

The team marked the incident resolved on Aug. 24, but again said a postmortem would be published in the coming days. When checked on Aug. 27, neither the current status page nor the official announcement channel contained a link to that report.

MANTRA said its analysis found that the incident affected two MANTRA-managed wallets and that no user, exchange, or partner funds were affected. However, the public account does not identify the wallet addresses, transaction hashes, amounts, or the technical steps used in the exploit.

When the halt was first reported on Aug. 21, patch testing was still underway. The network’s return resolves the operational interruption, but the attacker’s method and MANTRA’s containment assessment remain undisclosed.

For node operators, the public code record carries an immediate practical question: which v8.4.0 build is running. The current release page points to full commit 5c08d7bd9e2619952707dae1258d2a30bf024721, while MANTRA warns that the tag was re-pushed during recovery and tells operators to re-pull it.

That kind of version-level clarity matters in post-incident recoveries, because validators and infrastructure teams typically rely on release tags and changelogs to confirm they are on the intended build after an emergency restart. Here, the release trail is public, but the rationale for the code changes is not fully documented.

The release changelog lists an intermediate MANTRA EVM fork bump from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4. The final tagged go.mod replaces the dependency with the chain’s v0.6.2-v8-mantra-1 fork.

The final upgrade handler blocklists one address and disables three Cosmos vesting-account creation messages through the circuit breaker. Those changes describe the deployed mitigation, while the attack path itself remains undisclosed.

Why the March ICS20 flaw remains only a theory for MANTRA users

A March Cosmos Labs advisory described a critical ICS20 precompile flaw, said known affected chains had mitigated or upgraded, and named Mantra among remediation collaborators. Its timeline ends with the March disclosure, leaving the August incident outside its documented scope.

That makes the missing postmortem especially important for readers trying to separate confirmed facts from older vulnerability references: the public record shows a restart, a tagged build, and a limited mitigation set, but not the chain of events that led to the halt. Until MANTRA publishes the promised technical account, users can verify the restart, the exact final code, and the stated impact, but not the wallet addresses, transaction hashes, amounts, or technical explanation needed to connect this incident to any earlier bug.

Source | Related coverage