MANTRA Exploit Leaves Investors Reeling as $3.6M Worth of Tokens Vanish
MANTRA Chain has released its post-mortem report on the August 20-21 exploit, which saw an attacker drain approximately $3.6 million worth of tokens from the project.
The report reveals that the attack was caused by a coding flaw in the shared cosmos/evm module, which allowed the attacker to extract 720.9 million MANTRA tokens without needing privileged access.
The attacker exploited an unsigned integer issue, which caused the code to wrap around to a large number instead of returning an error.
MANTRA has stated that none of its validator keys, governance controls, or multisig signers were breached during the attack.