MANTRA Chain Hack
What happened
On 20 August 2026, an attacker exploited an unsigned-integer underflow in the balance-accounting layer of the upstream cosmos/evm dependency used by MANTRA Chain. MANTRA reports that 720,923,967.99 MANTRA were moved from a burn address and a legacy multisig, valued at about $3.6 million using the pre-incident price.
Unsigned-integer underflow in upstream cosmos/evm balance accounting.
How it happened
The attacker used a permissionlessly deployed contract and self-funded wallet to trigger an unsigned-integer underflow in balance accounting. No validator, administrator, governance, or multisig credential was compromised.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.