On August 20, an attacker drained 720,923,967.99 MANTRA — worth roughly $3.6 million at the pre-incident spot price of $0.005 — from two MANTRA-managed wallets. Mantra's own postmortem, published August 28, confirms the root cause: a chain of two vulnerabilities in the balance-accounting layer of the shared Cosmos EVM module.

The incident is less a story about a novel exploit than about the gap between a patched upstream dependency and a deployed chain — and about what shared infrastructure means when a vulnerability ships in every consumer at once.

The Mechanism

According to Mantra's postmortem and the Cosmos Labs security communication, the attack combined two flaws:

First, an unsigned-integer underflow in the EVM state database gave a specially constructed vesting account an artificially inflated EVM-side balance. In plain terms, a subtraction that should have failed instead wrapped around, crediting value that did not exist.

Second, a transfer using that wrapped balance to a victim account — the burn address, in this case, or a genesis multisig — produced an overflow that left the attacker holding what the victim address lost. An attacker contract routed through the staking precompile then debited MANTRA's wallets directly, without the private keys.

On-chain analyst Rarma traced the drain within hours: 600,000,035.55 MANTRA from the null/burn address and 120,923,932.44 MANTRA from a genesis-era multisig, consolidated through a single attacker wallet that fired 24 transactions before going quiet. It took Mantra eight days to publicly confirm the amount and mechanism that public transactions had already shown.

The Timeline That Matters

The disclosed chronology, assembled from Cosmos EVM's public repository and Mantra's postmortem, is the uncomfortable part of this incident:

  • May 13 — Cosmos Labs opens pull request #1176, "fix: harden statedb balance and event amount handling," whose description says it would guard StateDB balance subtraction against underflow.
  • May 15 — The fix merges into the main branch.
  • July 27 — An independent researcher publishes a full write-up of the exploit path, titled "Printing Infinite Money on the Cosmos Blockchain," reportedly after first reporting it through HackerOne.
  • August 13–19 — Backports to the maintained release branches begin and are merged on August 19, the same day Cosmos Labs ships v0.7.2, whose release notes describe "important security fixes" and recommend a coordinated upgrade.
  • August 20 — Mantra is exploited. The corresponding v0.6.2 release had not yet been applied to the network.

The main branch carried the fix for three months while a public write-up of the exploit path existed for nearly a month before the attack. Mantra halted the chain 14 minutes after the second unauthorized transaction and resumed block production 30 hours and 13 minutes later — but 94.7% of the stolen tokens had already reached a single exchange deposit address before the halt froze anything. As of the August 28 postmortem, none of the extracted funds had been recovered.

Not Just Mantra

The vulnerability sat in shared infrastructure. Cosmos Labs' own security advisory names the affected module, and public reports link three more chains — TAC, Kii Chain, and Nesa — to compromises in the same vulnerability cluster during the same week. TechTimes notes the same bug class cost Saga an estimated $7 million in January. Protos has reported criticism of how Cosmos Labs handled the disclosure process across affected chains.

Chains that adopt the Cosmos EVM stack inherit its security posture — including the parts they may not have put through independent, human-reviewed audits themselves. That is the structural lesson here: when the fix ships late to release branches, every consumer of the module shares the same exposure window, and attackers read the same advisories maintainers do.

Mantra's token fell roughly 18% to a record low on the halt, according to CoinDesk — its second major crisis in sixteen months, after the April 2025 collapse attributed to insider selling.

Verification Status

The root cause and amounts are confirmed by Mantra's official postmortem, the Cosmos Labs GitHub advisory and post-mortem document, and independent reporting by CoinDesk and Rekt. The reconstruction of affected third-party chains relies on public posts from the projects and has not been consolidated into a single official list.


TrustGrade tracks dependency exposure and security posture across DeFi and chain infrastructure. Verified, registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.