MANTRA Chain resumed mainnet block production on v8.4.0 at roughly 05:30 UTC on Aug. 22, six days after a security incident forced a chainwide halt. The team marked the incident resolved on Aug. 24 and confirmed no rollback, no state change, and no impact on user balances or token holders. Two project-managed wallets were the only ones touched, per the team's own analysis.
What's missing is the technical account MANTRA has been promising since the halt was reported on Aug. 21. The public incident timeline names no wallet addresses, transaction hashes, amounts, or exploit steps. As of Aug. 27, the status page and official announcement channels carried no link to the promised postmortem.
Why it matters
For node operators, the restart is only half the picture. The release page now points to full commit 5c08d7bd9e2619952707dae1258d2a30bf024721, with MANTRA warning that the tag was re-pushed during recovery and instructing operators to re-pull it. The changelog shows a MANTRA EVM fork bump from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4, and the final go.mod replaces an upstream dependency with the chain's own v0.6.2-v8-mantra-1 fork.
The deployed handler changes are visible: one address blacklisted, three Cosmos vesting-account creation messages disabled through the circuit breaker. That describes the mitigation, not the attack path. Without the postmortem, operators cannot tell whether the fix addresses the root cause or just patches the immediate symptom.
Market impact
The opacity lands in a sector already bruised by earlier Cosmos-chain exploits. A March advisory from Cosmos Labs flagged a critical ICS20 precompile flaw, named Mantra among remediation collaborators, and said known affected chains had patched. The MANTRA timeline ends with that March disclosure, leaving the August incident outside its documented scope. Whether the August event repeated the earlier ICS20 bug or exploited something new is the question users and operators cannot answer from the public record.
The exchange and partner ecosystem is, by MANTRA's own statement, untouched.
Frequently asked questions
-
When did MANTRA Chain resume mainnet after the security halt?
MANTRA restored mainnet block production on v8.4.0 at approximately 05:30 UTC on Aug. 22, six days after the halt began. The team marked the incident resolved on Aug. 24.
-
Were user funds affected by the MANTRA security incident?
Per MANTRA's own analysis, the incident touched only two MANTRA-managed wallets. No user, exchange, or partner funds were affected, and there was no rollback or state change between halt and restart.
-
What code changes did MANTRA deploy in v8.4.0?
The release bumps the MANTRA EVM fork from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4 and replaces an upstream dependency with v0.6.2-v8-mantra-1. The upgrade handler blacklists one address and disables three Cosmos vesting-account creation messages.
-
Has MANTRA published a technical postmortem?
No. The team promised a postmortem in the days after the Aug. 24 resolution. As of Aug. 27, the status page and official channels carried no link to the report, leaving wallet addresses, transaction hashes, and exploit steps undisclosed.
-
Could this incident be related to the March Cosmos ICS20 flaw?
A March Cosmos Labs advisory flagged a critical ICS20 precompile bug and named Mantra among remediation collaborators. The August incident falls outside that advisory's documented scope, so whether it repeated the ICS20 bug or hit a new vector is undetermined.
CryptoSlate