MANTRA Chain resumed producing blocks on Aug. 22 after deploying software update v8.4.0 to patch a vulnerability in its Cosmos-EVM module. The mainnet had gone about 30 hours without processing transactions following an attack that hit two MANTRA-managed wallets, though the project says user balances stayed unchanged and plans a full post-incident report in the coming days.
MANTRA Chain said in an Aug. 22 post that its mainnet was producing blocks again after developers fixed the vulnerability in the network's Cosmos-EVM module. Block production resumed at about 5:30 a.m. UTC on Aug. 22 through the patched v8.4.0 release, according to the project's incident status page.
An attacker targeted MANTRA's EVM module
The trouble started late on Aug. 20, when MANTRA detected an attacker exploiting a vulnerability in an upstream software dependency used by the blockchain. Developers halted the mainnet, freezing transfers, staking, bridges and inter-blockchain communication relays while security teams investigated, and some exchanges paused deposits and withdrawals tied to the network.
Investigators traced the issue to the Cosmos-EVM module, a component that lets developers run Ethereum-compatible smart contracts on the chain, and found it had affected two MANTRA-managed wallets. MANTRA said "No user funds were exploited" after identifying the source of the incident. Mainnet remained stopped at block 17,449,398, roughly 30 hours after the last block was processed at 11:13 p.m. UTC on Aug. 20.
Version 8.4.0 enabled a coordinated restart
Developers built v8.4.0 to repair the vulnerability and add security protections, testing it first on the DuKong testnet before validating it in an internal environment that replicated the mainnet state. The update required no module changes, state migrations, or changes to the blockchain's stored data, according to the incident page.
MANTRA-operated validators upgraded first, followed by validator partners, ordinary node operators, RPC services and archive nodes, since restarting only part of the validator set could have created operational problems. Public RPC and EVM endpoints came back online afterward, though explorers and indexers may lag while processing data created after the restart. DuKong stayed offline, and MANTRA said restoring the testnet would continue over the next several days.
MANTRA token hit a record low before the halt
The MANTRA token fell from approximately $0.005060 to a record low of $0.004126, a decline of about 18.5%, during the hours surrounding the incident. Trading volume rose nearly 600% to approximately $24 million during the initial market reaction, though MANTRA has not said the selloff was related to the attack.
MANTRA has not disclosed what activity occurred in the two managed wallets or released the attack path, and it said a complete post-incident report covering the vulnerability and its response will follow in the coming days.
Source: crypto.news
Trading involves risk.