Skip to main content
AVOID.NET

Audit log

Every state-changing event for MANTRA Chain (August 2026 Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-12 17:16:22Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,484,140
    sig
    2uomzC5cEei2…rmyU5YgCexplorer ↗
    hash
    3FeKBL9FBCcc…TwdD8Ztjsha256 → base58
    verifying row…full verify ↗
    canonical bytes (20516 B) ▸
    {"actor":"system:backfill","investigation_id":"1f2d27ff-9310-48ac-baba-3258b6f11114","kind":"publish","page_slug":"mantra-chain-august-2026-exploit","published_at":"2026-09-12T17:16:22.106Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"MANTRA Chain (August 2026 Exploit)","sections":[{"content":"At approximately 11:13 PM UTC on August 20, 2026, MANTRA Chain halted block production at block 17,449,398 after detecting an active exploit. The team confirmed that an attacker had exploited a vulnerability in the Cosmos EVM module — an upstream dependency used by the chain, not code developed by MANTRA itself. According to MANTRA, the incident affected two wallet addresses before containment was achieved. All network endpoints, validators, bridge infrastructure, and inter-chain relays were frozen for approximately 30 hours. The network resumed block production at approximately 05:30 UTC on August 22, 2026, after validators coordinated a restart on patched software version 8.4.0. MANTRA stated that user balances were not altered and there was no rollback between the halt and the resumption. The team emphasized that no user funds were exploited, though it acknowledged ongoing assessment of the full impact scope at the time of restart. Upbit, a South Korean exchange, paused MANTRA deposits and withdrawals during the halt citing the Virtual Asset User Protection Act, while spot trading on exchanges continued uninterrupted.","heading":"The Exploit and Network Halt","severity":"critical","sources":[{"credibility":1,"name":"MANTRA token plunges 18% to record low as blockchain halts after exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit"},{"credibility":2,"name":"MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability — cryip.co","type":"news_article","url":"https://cryip.co/mantra-chain-halt-attacker-exploit-vulnerability/"},{"credibility":2,"name":"Cosmos Labs urges Cosmos EVM chains to halt amid security incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/25/cosmos-labs-urges-evm-chains-to-halt-amid-security-incident/"},{"credibility":2,"name":"MANTRA Freezes Its Chain and Falls to a Record Low After Exploit — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/mantra-freezes-chain-falls-record-low-exploit/"}]},{"content":"The exploit was rooted in a critical vulnerability in the Cosmos EVM module, formally identified as GHSA-7g4w-cg88-2cq2. The flaw combined two chained weaknesses in Cosmos EVM's balance reconciliation between EVM state and the Cosmos SDK's x/bank module. First, when vesting accounts delegated locked token balances exceeding their spendable balances through the staking precompile, the StateDB SubBalance function underflowed, wrapping the attacker's balance to approximately 2^256 (the maximum possible unsigned integer value). Second, the attacker used this artificially inflated balance against a high-value target account — such as the zero address or a multisig wallet — causing an overflow that transferred the target's entire token balance to the attacker. Cosmos Labs confirmed that total token supply remained effectively unchanged by the attacks, with MANTRA's supply altered by only one base unit. The flaw was first reported through the Cosmos Bug Bounty Program on HackerOne on April 25, 2026. Initial testing by Cosmos Labs on 18-decimal configurations — the standard for production chains — incorrectly suggested no fund loss risk on live networks, leading to an initial assessment that production chains were not affected. A fix was merged silently to the main branch on May 15, 2026, without disclosing which vulnerability it addressed. Patched release versions (below v0.6.2 or v0.7.2 were vulnerable) were released on August 19, 2026, with vague security notes that did not indicate urgency or severity. Critically, the patch was released only approximately 20 hours before the first known attack on MANTRA began. MANTRA later stated that 'twenty hours was not a realistic window in which to assess, build, test and coordinate' an upgrade across its 38 independent validators. A further disclosure failure preceded the attacks: on August 20, 2026 at 07:16 UTC — hours before the first exploit — Push Chain publicly posted detailed exploit methodology on GitHub (repository pushchain/push-chain-evm#40), attributed to a Hacken audit, and identified vulnerable release tags. The Cosmos EVM post-mortem noted that this public publication of a vulnerability and exploit path by a downstream developer 'is highly unusual and can increase the risk of an exploit.'","heading":"Vulnerability: Cosmos EVM Integer Underflow (GHSA-7g4w-cg88-2cq2)","severity":"critical","sources":[{"credibility":1,"name":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"}]},{"content":"MANTRA Chain suffered the loss of approximately 720.9 million OM tokens, valued at roughly $3.6 million at the time of the attack. The OM token fell approximately 18% from a pre-halt price of around $0.005060 to an all-time low of $0.004126. Trading volume surged approximately 600% to approximately $24 million in the 24-hour period following the halt. By the following Friday, the token had partially recovered to near $0.005, though it remained approximately 80% below its March 2026 high of $0.0219. MANTRA's losses were part of a broader cross-chain attack that affected six Cosmos EVM networks in total. Across all six chains, attackers converted stolen tokens into approximately $5.72 million in other assets: an estimated $2.87 million exchanged on decentralized exchanges and approximately $2.85 million processed through centralized exchange accounts (which were subsequently frozen pending investigation). Specific assets drained across the ecosystem included 2,613,674.48 USDT, 114.129045 ETH, 93.78 TON, 1.393618 USDC, and 98.87 OSMO.","heading":"Financial Impact","severity":"high","sources":[{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"credibility":1,"name":"MANTRA token plunges 18% to record low as blockchain halts after exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit"},{"credibility":2,"name":"MANTRA Price Crashes 18% as Exploit Forces Full Blockchain Halt — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/64dce-mantra-price-crashes-18-as-exploit-forces-full-blockchain-halt"},{"credibility":1,"name":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"}]},{"content":"The MANTRA exploit was the first in a series of attacks that ultimately affected six Cosmos EVM chains between August 20 and August 25, 2026. TAC was exploited on August 22, 2026 at approximately 19:46 UTC, halting at block 24,671,475. KiiChain was attacked on August 22 beginning around 21:00 UTC, with attackers using identical techniques 18 separate times to drain 148,326,583.15 KII tokens before validators halted the network at block 9,355,723. Three additional networks were also exploited; one further chain reportedly halted before funds could be withdrawn. On August 24, 2026, Cosmos Labs issued a public advisory urging all Cosmos EVM chains to request that validators halt their chains, citing an 'ongoing security incident.' Cosmos Labs declined at that time to name the vulnerability, identify affected chains by name, or disclose loss amounts, stating it would publish a full incident report later. Cosmos Labs coordinated with approximately 40 Cosmos chains to assess exposure and distribute mitigation guidance through secure private channels.","heading":"Broader Cosmos EVM Attack Pattern","severity":"high","sources":[{"credibility":2,"name":"Cosmos Labs urges Cosmos EVM chains to halt amid security incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/25/cosmos-labs-urges-evm-chains-to-halt-amid-security-incident/"},{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"credibility":2,"name":"Cosmos EVM chains told to halt after security incident — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-incident/"},{"credibility":1,"name":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"}]},{"content":"The August 2026 exploit is the latest in a series of major adverse events affecting MANTRA Chain. The project suffered a widely covered token collapse of approximately 90% in April 2025, which attracted significant scrutiny over token distribution and insider selling allegations (documented separately under the 'mantra-chain' entry). The project subsequently underwent rebranding and a token redenomination in March 2026. As of the August 2026 incident, MANTRA was also in the process of a pending acquisition by Inveniam Capital Partners, expected to close in Q3 2026. The cumulative effect of these events has left OM approximately 80% below its March 2026 redenomination high. The August 2026 incident is characterized as a security exploit of an upstream dependency rather than a flaw in MANTRA's own code; MANTRA was a victim of the vulnerability, not its origin. This distinction is material to any assessment of team competence versus systemic infrastructure risk.","heading":"MANTRA's Prior History and Compounding Risk","severity":"medium","sources":[{"credibility":2,"name":"MANTRA Freezes Its Chain and Falls to a Record Low After Exploit — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/mantra-freezes-chain-falls-record-low-exploit/"},{"credibility":2,"name":"MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability — cryip.co","type":"news_article","url":"https://cryip.co/mantra-chain-halt-attacker-exploit-vulnerability/"},{"credibility":2,"name":"August 2026 Among Worst Months for DeFi Hacks — EtherWorld","type":"news_article","url":"https://etherworld.co/august-2026-among-worst-months-for-defi-hacks/"}]},{"content":"The post-mortem published by Cosmos Labs identified significant failures in the vulnerability disclosure and patch coordination process. The bug was first reported on April 25, 2026, but was initially assessed as not affecting production chains — an assessment that subsequently proved incorrect. A silent fix was merged to the main branch on May 15, 2026, without public disclosure of which vulnerability it addressed. When patched release versions were made available on August 19, 2026, the release notes mentioned security improvements without indicating urgency or severity, leaving downstream chains without the context needed to treat the upgrade as emergency-critical. The patch was available for only approximately 20 hours before the first known attack began. A public GitHub post by Push Chain on the morning of August 20, 2026, which included detailed exploit methodology and identified vulnerable release tags, is assessed by the post-mortem as likely having accelerated attacker awareness and action. These disclosure failures are attributed to the Cosmos EVM upstream maintainers and to Push Chain's inadvertent public disclosure, not to MANTRA Chain itself.","heading":"Disclosure and Patch Coordination Failures","severity":"high","sources":[{"credibility":1,"name":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"}]}],"sources_used":[{"credibility":1,"name":"MANTRA token plunges 18% to record low as blockchain halts after exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit"},{"credibility":1,"name":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"credibility":2,"name":"MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability — cryip.co","type":"news_article","url":"https://cryip.co/mantra-chain-halt-attacker-exploit-vulnerability/"},{"credibility":2,"name":"MANTRA Freezes Its Chain and Falls to a Record Low After Exploit — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/mantra-freezes-chain-falls-record-low-exploit/"},{"credibility":2,"name":"Cosmos Labs urges Cosmos EVM chains to halt amid security incident — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/25/cosmos-labs-urges-evm-chains-to-halt-amid-security-incident/"},{"credibility":2,"name":"MANTRA Price Crashes 18% as Exploit Forces Full Blockchain Halt — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/64dce-mantra-price-crashes-18-as-exploit-forces-full-blockchain-halt"},{"credibility":2,"name":"Cosmos EVM chains told to halt after security incident — crypto.news","type":"news_article","url":"https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-incident/"},{"credibility":2,"name":"August 2026 Among Worst Months for DeFi Hacks — EtherWorld","type":"news_article","url":"https://etherworld.co/august-2026-among-worst-months-for-defi-hacks/"},{"credibility":2,"name":"Cosmos EVM Vulnerability Drains MANTRA, TAC and KiiChain — Ground News / crypto.news aggregate","type":"news_article","url":"https://ground.news/article/cosmos-had-known-the-bug-since-april-a-valuation-error-leads-to-a-57-million-out-of-six-blockchain-exploit"}],"summary":"On August 20, 2026, MANTRA Chain — an RWA-focused Cosmos-based Layer 1 — suffered an exploit of a critical vulnerability in its upstream Cosmos EVM module, forcing a full network halt of approximately 30 hours and causing its OM token to drop 18% to a record low of $0.004126. Approximately 720.9 million OM tokens worth roughly $3.6 million were drained across the incident, part of a coordinated attack pattern that ultimately affected six Cosmos EVM chains and converted approximately $5.72 million in stolen assets across the ecosystem. This page covers the August 2026 security incident; the April 2025 token price collapse is documented separately under the 'mantra-chain' entry.","timeline":[{"date":"2026-04-25","event":"Cosmos EVM vulnerability (GHSA-7g4w-cg88-2cq2) first reported through the Cosmos Bug Bounty Program on HackerOne. Initial Cosmos Labs assessment incorrectly concluded no production chain was at risk.","source":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-05-15","event":"Silent fix for the Cosmos EVM vulnerability merged to the main branch without public disclosure identifying the vulnerability addressed.","source":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-19","event":"Patched Cosmos EVM releases (v0.6.2 and v0.7.2) made available with vague security notes, approximately 20 hours before the first known attack.","source":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain — crypto.news","source_url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"date":"2026-08-20","event":"At 07:16 UTC, Push Chain publicly posted detailed exploit methodology and vulnerable release tags on GitHub (pushchain/push-chain-evm#40), hours before the first attack.","source":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-20","event":"First known attack on MANTRA Chain began at approximately 19:06 UTC (3:06 PM ET).","source":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-20","event":"MANTRA Chain halted block production at block 17,449,398 at approximately 23:13 UTC. All transactions, deposits, and withdrawals frozen. OM token fell 18% to a record low of $0.004126.","source":"MANTRA token plunges 18% to record low as blockchain halts after exploit — CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit"},{"date":"2026-08-22","event":"MANTRA Chain resumed block production at approximately 05:30 UTC on patched software version 8.4.0 after approximately 30 hours offline. No rollback; user balances confirmed unaltered.","source":"MANTRA Freezes Its Chain and Falls to a Record Low After Exploit — CoinPaprika","source_url":"https://coinpaprika.com/news/mantra-freezes-chain-falls-record-low-exploit/"},{"date":"2026-08-22","event":"TAC exploited at approximately 19:46 UTC at block 24,671,475 using the same Cosmos EVM vulnerability. KiiChain subsequently attacked beginning around 21:00 UTC, with 148.3 million KII tokens drained across 18 repeated attacks.","source":"Cosmos Labs urges Cosmos EVM chains to halt amid security incident — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/25/cosmos-labs-urges-evm-chains-to-halt-amid-security-incident/"},{"date":"2026-08-24","event":"Cosmos Labs issued a public advisory urging all Cosmos EVM chains to request that validators halt their chains, confirming an ongoing security incident. Cosmos Labs coordinated with approximately 40 chains.","source":"Cosmos Labs urges Cosmos EVM chains to halt amid security incident — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/25/cosmos-labs-urges-evm-chains-to-halt-amid-security-incident/"},{"date":"2026-08-25","event":"Cosmos Labs closed the active exploit response window at 15:20 UTC. Total cross-chain losses across six networks tracked at approximately $5.72 million converted through decentralized and centralized exchanges.","source":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-28","event":"Cosmos Labs published full post-mortem for GHSA-7g4w-cg88-2cq2, detailing the underflow/overflow exploit chain, the April 2026 disclosure failure, and the Push Chain public posting as a contributing factor.","source":"Cosmos EVM GHSA-7g4w-cg88-2cq2 Post-Mortem — cosmos/security GitHub","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 61e74842-94ab-4ea1-a934-0af407d13981
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.