MANTRA Chain Exploit Drains $3.6 Million Worth of Tokens
The MANTRA Chain has released its post-mortem report on the August 20-21 exploit that drained roughly $3.6 million worth of tokens from the project. According to the report, an attacker exploited a coding flaw in the shared cosmos/evm module, which allowed them to extract about 600 million MANTRA and another 120.9 million tokens from its burn address and a dormant genesis-era multisig tied to an old incentive campaign.
The attack was not due to a breach of validator keys, governance controls or multisig signers, but rather the attacker's ability to deploy a permissionlessly deployed contract with self-funded wallet.
MANTRA has clarified that no new tokens were minted as a result of the attack. Instead, the exploit unleashed roughly 720.9 million tokens into circulation that had been sitting outside the circulating supply and considered economically inert.