MANTRA Chain Restarts After Security Halt; Details Unreleased
MANTRA Chain resumed mainnet block production on v8.4.0 six days after an August security halt. The project reports user balances were unaffected but has not released transaction details.
MANTRA Chain resumed mainnet block production on v8.4.0 at about 05:30 UTC on Aug. 22, six days after a chainwide halt that began on Aug. 21. The project reported there was no rollback or state change between the halt and restart and that token holders did not need to take action.
The project’s public status updates say the incident affected two MANTRA-managed wallets. The update does not identify the wallet addresses, provide transaction hashes, list affected amounts, or include a technical postmortem. The project marked the incident resolved on Aug. 24 but had not published the promised technical account as of Aug. 27.
The v8.4.0 release includes specific code changes. The release page points to commit 5c08d7bd9e2619952707dae1258d2a30bf024721 and notes the release tag was re-pushed during recovery. Node operators were instructed to re-pull the tag. The changelog records an intermediate MANTRA EVM fork bump from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4, and the final tagged go.mod replaces an upstream dependency with the chain’s v0.6.2-v8-mantra-1 fork.
Deployed mitigations in the upgrade handler include blocklisting one address and disabling three Cosmos vesting-account creation messages via a circuit breaker. Those measures were applied to limit further risk but the public record does not describe how the attacker accessed funds or whether all vectors were contained.
A March advisory from Cosmos Labs described a critical ICS20 precompile flaw and listed Mantra among collaborators on remediation at that time. The advisory’s timeline ends with the March disclosure. MANTRA’s public updates do not connect the August incident to the earlier ICS20 issue and have not provided the wallet or transaction data that would allow independent verification.
Users and operators can confirm that the chain is producing blocks and inspect the final code release. The absence of wallet addresses, transaction hashes and a technical postmortem prevents independent tracing of the disclosed wallet impact and verification of the exploit path. MANTRA’s public account maintains that user and partner funds were not affected.








