MANTRA Chain Restarts After 30-Hour Halt as Cosmos-EVM Vulnerability Raises Security Questions

Daily Feed
MANTRA Chain Restarts After 30-Hour Halt as Cosmos-EVM Vulnerability Raises Security Questions

MANTRA Chain is back online after a roughly 30-hour halt, but getting the network running again is not the same as getting answers. The chain resumed block production on Aug. 22 after a vulnerability in its [Cosmos-EVM stack](https://docs.cosmos.network/evm/latest/documentation/overview) forced developers to stop the chain, patch the software, and restart it through a coordinated validator upgrade.

  • Block production resumed at about 5:30 a.m. UTC on Aug. 22
  • Version 8.4.0 fixed the issue, with no rollback or state rewrite
  • User balances were unchanged, according to MANTRA
  • Two MANTRA-managed wallets were involved before containment
  • The incident raises fresh questions about Cosmos-EVM security and upstream dependencies

MANTRA said the restart followed a coordinated software update involving MANTRA-operated validators and other members of the validator set. The mainnet stopped processing transactions late on Aug. 20 after developers detected an attacker exploiting a vulnerability in an upstream software dependency tied to the [Cosmos-EVM module](https://github.com/cosmos/evm/releases).

That shutdown had real consequences. Transfers stopped. Staking froze. Bridges went dark. MANTRA-managed inter-blockchain communication relays were halted too, and some exchanges paused deposits and withdrawals linked to the network. For a chain built around real-world assets, that is not a small outage. It is the kind of failure that reminds everyone that “financial infrastructure” is still software, and software still breaks in embarrassing ways.

MANTRA’s initial notice said all transactions and network endpoints had been frozen. The chain stayed stuck at block 17, 449, 398 while the team reviewed attack paths and prepared a patch. The last reported block was processed at about 11:13 p.m. UTC on Aug. 20.

The project said the incident affected two wallet addresses before the threat was contained, later identifying them on its status page as MANTRA-managed wallets. MANTRA also said there was no indication that user, exchange, or partner funds had been directly affected.

“No user funds were exploited, ” MANTRA said.

That wording matters. It suggests the team believes the incident hit its own operational wallets rather than customer balances. But the unanswered questions matter more than the reassurance. What activity took place in those two wallets? How much value was involved? Did anything leave the addresses? MANTRA has not disclosed those details yet.

Before the restart, the team took a complete snapshot of the blockchain at the halted state. In plain English, that means it preserved the chain’s condition at a specific moment so validators could resume from the same point rather than unwind history. MANTRA said version 8.4.0 was tested on DuKong testnet and in an internal environment that replicated mainnet state, and that the software update did not require module changes, state migrations, or changes to the blockchain’s stored data.

Just as important, MANTRA said there was no blockchain rollback. That is a clean break from the kind of emergency that rewrites history and usually sparks a week of tribal warfare. Instead, the chain was patched and restarted with balances intact. Token holders were told they did not need to take any action.

The restart was handled carefully. MANTRA-operated validators were upgraded first, then validator partners, followed by ordinary node operators, RPC services, and archive nodes. Public RPC and EVM endpoints later came back online. The project warned that explorers, indexers, and other services could lag behind the chain itself, which is normal after a restart but still annoying if you are trying to verify what actually happened.

DuKong remained offline after mainnet returned. MANTRA did not explain that separately, so the safest reading is that the testnet was simply left down while the team finished operational cleanup. Still, it is a reminder that the network was not flipping back to “business as usual” in one neat motion.

The broader question is whether this was a one-off bug or part of a wider Cosmos-EVM security problem. MANTRA added EVM support in September 2025 alongside CosmWasm. For newer readers: EVM stands for Ethereum Virtual Machine, the execution environment used by Ethereum-compatible smart contracts, while CosmWasm is a smart contract framework used in the Cosmos ecosystem. Put the two together and you gain flexibility, but you also widen the number of places where a bug can hide.

That risk is not abstract. In March 2026, Cosmos Labs disclosed a separate Cosmos EVM vulnerability under advisory ASA-2026-002. The flaw was in the ICS20 precompile, a component that helps enable cross-chain token transfers via IBC, the Inter-Blockchain Communication protocol used across Cosmos chains. Under incorrect state handling during nested EVM execution, the same token balance could be used repeatedly within one transaction. Cosmos Labs said the flaw led to an estimated $7 million loss on Saga EVM in January, identified 15 chains running code that contained the flaw, said six did not have the affected feature enabled, and said one was exploited while the remaining networks applied mitigation before an attack occurred. The permanent repair was included in Cosmos EVM version 0.6.0.

MANTRA has not confirmed that the Aug. 20 incident was caused by that earlier flaw. And that is the honest answer: the connection has not been established. It may turn out to be related. It may turn out to be a different exploit path entirely. For now, anyone claiming certainty is selling more confidence than evidence.

The market reaction was predictably ugly. MANTRA’s token fell from approximately $0.005060 to a record low of $0.004126, a decline of about 18.5%, with CoinGecko data cited in market reports placing the low around 11:10 p.m. UTC on Aug. 20. Trading volume nearly 600% to roughly $24 million. When a chain halts and people do not know whether the problem is contained, the market does not wait around to be reassured.

The token had already had a volatile year. In March, it rose 62% after a rebrand, a network upgrade, and a 1:4 non-dilutive token split, with holders receiving four MANTRA tokens for every former OM token. In June, Inveniam Capital Partners announced an agreement to acquire MANTRA and its affiliated entities. Inveniam had also made a $20 million strategic investment in August 2025, and the two companies worked on NVNM Chain, a Layer 2 network built on MANTRA Chain for private-market asset data.

That context matters because MANTRA is not just another random chain with a loud Telegram group and a prayer. It sits in the real-world-asset lane, where projects like to promise serious infrastructure, institutional-grade tooling, and clean financial rails. That pitch only works if the chain can stay online when something breaks. If one vulnerable component can freeze transfers, staking, bridges, and relays for more than a day, then the “infrastructure” part still has some growing up to do.

To its credit, MANTRA did the part a lot of projects mess up: it halted the chain, preserved the state, patched the software, tested the fix, coordinated validators, and restarted without rewriting balances. That is the responsible move when a core module is compromised. Pretending nothing happened would have been a much worse look, and a much riskier one.

MANTRA said a complete post-incident analysis covering the Cosmos-EVM vulnerability and the network’s response will be released in the coming days. That report needs to answer the questions that actually matter: what code path was hit, what happened in the two managed wallets, whether any assets moved, whether the flaw came from MANTRA’s own stack or an external dependency, and whether any validator missed the patch window.

Key questions and takeaways

  • Did user funds get drained?
    MANTRA says no. The project said user funds were not exploited and that user, exchange, and partner funds were not directly affected. The unresolved issue is what happened inside the two MANTRA-managed wallets.

  • Why did the chain stop for so long?
    MANTRA halted mainnet after detecting an exploit in an upstream software dependency tied to its Cosmos-EVM module. It took coordinated validator upgrades and testing to restart the chain safely without a rollback.

  • Was this the same Cosmos EVM bug disclosed by Cosmos Labs?
    Not confirmed. MANTRA says attribution to that earlier ICS20 precompile flaw has not been established.

  • Why did the token price crash if balances were unchanged?
    Because a halted chain, frozen services, and unresolved wallet activity destroy confidence fast. Even without a confirmed loss of end-user funds, uncertainty is enough to hammer a thinly traded token.

  • What should users do now?
    MANTRA said token holders do not need to take any action. The main thing to watch is the promised post-incident report, which should clarify the exploit path and whether any assets actually moved.

Modular blockchains are powerful, but they are not magic. Every bridge, precompile, relay, and dependency adds capability and adds risk. That tradeoff is the price of building fast. Pretending otherwise is just tech theater.

Further reading

For more context on the outage, the Cosmos-EVM bug, and related RWA and interoperability work, these resources are worth a look:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog