PublicAML

MANTRA Chain exploited for 720.9 million tokens due to vulnerability

An unsigned integer underflow vulnerability led to the unauthorized transfer of tokens from MANTRA-managed addresses. The incident resulted in a loss of approximately 3.6 million USD.

An attacker exploited an unsigned integer underflow vulnerability in the upstream Cosmos EVM module, which allowed for the unauthorized transfer of approximately 720.9 million MANTRA tokens from two MANTRA-managed addresses, specifically the burn address and a dormant genesis-era multisig. In response to the incident, the chain was halted to contain the threat and later resumed operations after implementing a v8.4.0 patch. It is noted that no validator keys, admin privileges, or user funds were compromised during this incident.

The loss incurred from this incident is approximately 3.6 million USD. The mechanism of the attack involved exploiting a vulnerability in the code, which facilitated the unauthorized transfer of a significant amount of tokens. This incident underscores the potential risks associated with vulnerabilities in smart contract code, particularly in the context of the Cosmos EVM module.

While the specific blockchain is not stated, the incident involved the MANTRA Chain, which indicates that tracing the movement of the tokens may be possible through the relevant blockchain records. However, the details regarding the on-chain record and specific addresses involved in the unauthorized transfer are not provided.

Sources

Share:XTelegramLinkedIn
MANTRA Chain exploited for 720.9 million tokens due to vulnerability | PublicAML