NewsCryptoMANTRA Chain Restores Operations After 30-Hour Shutdown Triggered by Cosmos-EVM Vulnerability

MANTRA Chain Restores Operations After 30-Hour Shutdown Triggered by Cosmos-EVM Vulnerability

Author: Blockonomi·

Key Takeaways

  • MANTRA Chain restored block production at 5:30 a.m. UTC on August 22, ending a roughly 30-hour outage, after deploying software version 8.4.0 with a fix for the exploited Cosmos-EVM vulnerability.
  • The security flaw sat in an upstream Cosmos-EVM dependency rather than code MANTRA wrote itself, a class of shared-component risk that can expose every project built on the same software.
  • Suspicious activity was limited to two wallet addresses, both belonging to MANTRA's internal wallet infrastructure, and the project confirmed that no user, exchange partner, or ecosystem funds were compromised.
  • The chain resumed from a complete snapshot taken at block height 17,449,398 without requiring a state rollback, and all user account balances remained intact.
  • During the outage the OM token declined about 18.5% to an all-time low of roughly $0.004126 as trading volume jumped approximately 600% to about $24 million, while the DuKong testnet remains offline and a detailed post-mortem report is still pending.
MANTRA Chain Restores Operations After 30-Hour Shutdown Triggered by Cosmos-EVM Vulnerability

MANTRA Chain has restored network operations after deploying a comprehensive security patch that resolved a critical vulnerability in its Cosmos-EVM module — a flaw exploited by an attacker that forced the blockchain offline for approximately 30 hours and disabled core network functions. MANTRA Chain is a layer-1 blockchain that presents itself as "The EVM L1 for RWAs," a network built to support real-world asset tokenization. The Cosmos-EVM module at the center of the incident is upstream software that adds Ethereum Virtual Machine compatibility to chains built on the Cosmos SDK, letting Ethereum-style contracts and tooling run alongside Cosmos-native functions such as staking and inter-blockchain communication. The RWA segment MANTRA is courting has also become one of crypto's most competitive institutional markets — tokenized funds from major traditional asset managers already operate on public chains — and institutional participants generally require demonstrable uptime and transparent incident handling from infrastructure they adopt.

Block production resumed at 5:30 a.m. UTC on August 22, following the implementation of software version 8.4.0, which contained both the critical security fix and additional protective measures. The project confirmed the recovery in a post on X:

MANTRA Chain is producing blocks again. The vulnerability in the Cosmos-EVM module has been fixed, the network has resumed, and no user funds were affected. Thank you to everyone for your patience throughout the incident. Review the full history of incident status updates… pic.twitter.com/IDVpw7H7Tp

— MANTRA | The EVM L1 for RWAs (@MANTRA_Chain), August 22, 2026

How the Incident Unfolded

The crisis originated during the late hours of August 20, when MANTRA's security team identified malicious activity targeting a weakness in an upstream software dependency. In response, developers made the decision to completely halt mainnet operations. Emergency halts are a drastic but established response among layer-1 networks — Solana, for example, has suspended block production multiple times during past outages — because stopping the chain prevents an attacker from transacting while a patch is developed, at the cost of full downtime for users and dependent services.

The emergency shutdown effectively disabled all blockchain functionality, including transaction processing, staking mechanisms, cross-chain bridges, and inter-blockchain communication protocols. Several cryptocurrency exchanges responded by suspending deposit and withdrawal services for the network, and throughout the downtime period public endpoints, validator infrastructure, and bridge services remained inaccessible.

Details of the Security Incident

MANTRA determined that the security weakness resided within its Cosmos-EVM module. Because the flaw sat in an upstream dependency rather than code MANTRA wrote itself, it belongs to a class of risk that extends beyond any single chain: vulnerabilities in shared libraries and frameworks can simultaneously expose every project built on the same component. Developers confirmed that suspicious activity was limited to two specific wallet addresses before the threat was successfully neutralized.

Subsequent investigation revealed that both compromised addresses belonged to MANTRA's internal wallet infrastructure. The development team emphasized that no assets belonging to users, exchange partners, or ecosystem collaborators were compromised.

"No user funds were exploited," MANTRA confirmed in its post-incident communication.

The project has not yet released specific details regarding the nature of the unauthorized activity within those two addresses, the total value at risk, or whether any digital assets were transferred out. A comprehensive technical analysis is anticipated within the next few days.

Patch Development and Network Reactivation

Prior to network reactivation, the development team created a complete blockchain snapshot at block height 17,449,398, marking the precise point where operations ceased. Engineers then conducted an extensive analysis of potential attack vectors before constructing and validating the security patch.

The 8.4.0 release underwent rigorous testing on MANTRA's DuKong testnet environment, followed by verification in a controlled setting that mirrored mainnet conditions. Developers executed multiple upgrade simulations before authorizing validators to restart operations.

MANTRA's own validator infrastructure received the upgrade first, with partner validators, independent node operators, RPC providers, and archive nodes following in sequence. All user account balances remained intact, and the blockchain did not require a state rollback — meaning it resumed from its exact recorded state rather than rewriting transaction history, an outcome that avoids the consensus and accounting disputes that have historically made rollbacks contentious.

Market Impact and Price Movement

Throughout the security incident, MANTRA's native token experienced significant downward pressure, declining from approximately $0.005060 to an unprecedented low of $0.004126 — an 18.5% decrease that marked an all-time low, according to CoinGecko data. The price floor occurred around 11:10 p.m. UTC on August 20, shortly before the network processed its final block.

Market participants reacted strongly to the news, driving trading volume up by approximately 600% to reach roughly $24 million. MANTRA has not officially attributed the price decline to the security breach. The drawdown extends a difficult period for the token: in April 2025, OM lost roughly 90% of its value within hours amid a wave of forced liquidations that MANTRA's leadership attributed to large over-the-counter positions rather than any protocol failure, an episode that prompted the project to announce token buybacks and expanded transparency measures.

What Comes Next

While mainnet operations have been restored, the DuKong testnet environment remains offline. MANTRA indicated that restoration efforts for the test network will proceed throughout the coming days. A further operational milestone to watch is the reinstatement of deposit and withdrawal support by the exchanges that suspended MANTRA services during the halt.

The team has committed to publishing a detailed post-mortem analysis addressing the Cosmos-EVM vulnerability and outlining the comprehensive response protocol in the near future. The open questions left by the incident — the exact nature of the activity in the two internal wallets, the value exposed, and whether any assets were moved — now rest with that report.