MANTRA Chain Restarts Mainnet Six Days After Security Halt
MANTRA mainnet resumes after six-day security halt
MANTRA Chain restarted its mainnet on Aug. 22 by moving to version 8.4.0. The restart came six days after a security incident forced the team to stop the chain. Mainnet began running again at about 05:30 UTC.
MANTRA stated that user balances were not changed and that no rollback of the blockchain state occurred. The team marked the incident as resolved on Aug. 24, but a detailed technical report has not yet been published.
What the team says about the breach
MANTRA said the incident affected two wallets managed by the project. The team confirmed that no user funds, exchange deposits, or partner assets were impacted. However, the public announcement did not list the specific wallet addresses, transaction hashes, or the exact amounts involved.
The project has not explained the technical steps the attacker took to exploit the system. A promised postmortem remains unpublished as of Aug. 27.
Missing details leave exploit path unclear
Because the postmortem has not been released, it is currently unconfirmed whether the breach used the same method as a critical flaw reported in March. That earlier issue involved the ICS20 precompile, a component used for transferring tokens between different blockchains. MANTRA was listed as a collaborator in fixing that March vulnerability, but the August incident falls outside the timeframe of the original advisory.
Node operators must update software
The upgrade to v8.4.0 includes immediate actions for node operators. MANTRA warned that the release tag was re-pushed during recovery, so operators are advised to re-pull the latest code. The final build points to a specific full commit hash.
The new version blocks one address and disables three types of messages related to Cosmos vesting accounts through a circuit breaker. This describes the safety measure added to the network, but it does not reveal how the original attack worked.
Why this matters for MANTRA users
The restart allows the network to function normally again, but the lack of a public postmortem creates uncertainty. Users can verify that the chain is running, but they cannot yet trace exactly what happened inside the two affected wallets or determine if the breach reused the earlier ICS20 bug.