MANTRA Chain is back online, but silent code changes spark developer concerns

MANTRA Chain is back online, but silent code changes spark developer concerns


MANTRA Chain restored mainnet block production on v8.4.0 six days after a security incident forced a chainwide halt. The promised technical account remains unpublished, leaving the exploitation of the upstream dependency and the activity inside two project-managed wallets unexplained.

The official incident timeline says mainnet resumed at approximately 05:30 UTC on Aug. 22. The chain said there was no rollback or state change between the halt and restart, user balances were not altered, and token holders did not need to take action.

The team behind the chain marked the incident resolved on Aug. 24 but again said a postmortem would arrive in the coming days. Its current status page and official announcement channel contained no link to that report when checked on Aug. 27.

MANTRA said its analysis found that the incident affected two MANTRA-managed wallets and that no user, exchange, or partner funds were affected. The public account stops short of identifying the wallet addresses, transaction hashes, amounts, or technical exploit steps.

Betfury

When the halt was reported on Aug. 21, patch testing was still underway. The network’s return resolves that operational question while leaving the attacker’s method and MANTRA’s containment assessment unexplained.

The Daily Brief

The signal, before the noise.

Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

One email. Everything that matters.

Free to join. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re on the list. Your next Daily Brief is on its way.

Related Reading

Mantra, market makers allegedly exploited validation gaps to inflate OM token liquidity

MANTRA Chain recovery timeline and comparison of verified public records with still-undisclosed exploit details
A timeline separates verified MANTRA Chain recovery steps from still-undisclosed wallet, transaction, amount, exploit-path, and ICS20-link details.

For node operators, the public code record has an immediate implication: identify which v8.4.0 build is running. The current release page points to full commit 5c08d7bd9e2619952707dae1258d2a30bf024721, while MANTRA warns that the tag was re-pushed during recovery and tells operators to re-pull it.

The release changelog lists an intermediate MANTRA EVM fork bump from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4. The final tagged go.mod replaces the dependency with the chain’s v0.6.2-v8-mantra-1 fork.

The final upgrade handler blocklists one address and disables three Cosmos vesting-account creation messages through the circuit breaker. Those changes describe the deployed mitigation while leaving the attack path undisclosed.

Why the March ICS20 flaw remains only a theory for MANTRA users

A March Cosmos Labs advisory described a critical ICS20 precompile flaw, said known affected chains had mitigated or upgraded, and named Mantra among remediation collaborators. Its timeline ends with the March disclosure, leaving the August incident outside its documented scope.

Users can verify the restart, the exact final code, and stated impact. Wallet addresses, transaction hashes, amounts, and a technical explanation remain necessary to trace the disclosed wallet impact from MANTRA’s public account and determine whether the incident repeated the earlier ICS20 bug.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest