MANTRA Chain Hack

Reported loss $3.6M
Mantra
Unsigned Integer Underflow

What happened

On 20 August 2026, an attacker exploited an unsigned-integer underflow in the balance-accounting layer of the upstream cosmos/evm dependency used by MANTRA Chain. MANTRA reports that 720,923,967.99 MANTRA were moved from a burn address and a legacy multisig, valued at about $3.6 million using the pre-incident price.

Technical root cause

Unsigned-integer underflow in upstream cosmos/evm balance accounting.

How it happened

The attacker used a permissionlessly deployed contract and self-funded wallet to trigger an unsigned-integer underflow in balance accounting. No validator, administrator, governance, or multisig credential was compromised.

Protocol details

Classification Access Control
Protocol Type Chain
Implementation language Go

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.