MANTRA Chain has resumed producing blocks after developers released a software update to address a vulnerability in its Cosmos-EVM module, ending a mainnet shutdown that left the network unable to process transactions for about 30 hours.
The project said in an Aug. 22 post that block production had restarted following the deployment of version 8.4.0. Its incident status page recorded the return of the mainnet at about 05:30 UTC on 22 August.
The recovery followed a coordinated upgrade involving validators operated by MANTRA and other members of the network’s validator set. The project said user balances were unchanged and that the restart did not involve a blockchain rollback or any alteration to the network’s state. Token holders were told they did not need to take action.
The disruption began late on 20 August, when MANTRA identified an attacker exploiting a vulnerability in an upstream software dependency used by the blockchain. The company halted the mainnet while security teams examined the activity, preventing transactions from being processed.
MANTRA’s first notice said all transactions and network endpoints had been frozen. Transfers, staking operations, bridges and MANTRA-managed inter-blockchain communication relays were also stopped. Some exchanges paused deposits and withdrawals linked to the network.
The halt took validators, public endpoints and bridge services offline, leaving assets temporarily unable to move on the RWA-focused Layer 1.
As the investigation progressed, MANTRA traced the vulnerability to its Cosmos-EVM module. It said activity had affected two wallet addresses before the threat was contained. The incident page later identified the addresses as wallets managed by MANTRA and said there was no indication that user, exchange or partner funds had been directly affected.
“No user funds were exploited,” the project said in an update after identifying the source of the incident.
MANTRA has not explained what happened in the two managed wallets, how much value was involved or whether any assets were transferred out. It has also not published the attack path or identified the specific upstream software component responsible for the vulnerability.
Before preparing the network for a restart, the team took a complete snapshot of the blockchain in its halted state. The mainnet remained stopped at block 17,449,398 while developers assessed known attack paths and prepared a repair.
Developers produced version 8.4.0 to fix the EVM-module vulnerability and introduce additional security protections. The release was first tested on MANTRA’s DuKong testnet and then checked in an internal environment designed to replicate the mainnet state.
Several upgrade rehearsals were carried out before validators were instructed to restart. According to MANTRA’s incident page, the update required no module changes, state migrations or alterations to the blockchain’s stored data.
Validators operated by MANTRA were upgraded first. Validator partners, standard node operators, RPC services and archive nodes followed. MANTRA said a coordinated restart was chosen because restoring only part of the validator set could have caused operational problems.
Block production returned roughly 30 hours after the last reported block, which was processed at about 23:13 UTC on 20 August. Public RPC and EVM endpoints later came back online, although MANTRA warned that explorers, indexers and other services could take longer to catch up with data generated after the restart.
DuKong remained offline after the mainnet resumed. MANTRA said engineers would continue working to restore the public testnet over the following several days while monitoring the stability of the mainnet.
The affected Cosmos-EVM component supports Ethereum-compatible smart contracts on MANTRA’s network. In September 2025, the chain added EVM support alongside CosmWasm, allowing developers to deploy applications using either environment on the RWA-focused platform.
The incident has also prompted attention because of a separate critical vulnerability disclosed by Cosmos Labs in March 2026. Security advisory ASA-2026-002 described an error in the ICS20 precompile, which enables EVM smart contracts to begin cross-chain token transfers using the Inter-Blockchain Communication protocol.
According to the Cosmos EVM advisory, incorrect state handling during nested EVM execution could allow the same token balance to be used repeatedly in a single transaction. The flaw was linked to an estimated $7m loss on Saga EVM in January.
Cosmos Labs said 15 chains were running code containing the vulnerability. Six did not have the affected feature enabled, one was exploited and the other networks introduced a mitigation before an attack took place.
MANTRA was among the teams that helped investigate and respond to that earlier issue. Cosmos Labs said a permanent fix was included in Cosmos EVM version 0.6.0, with known affected chains either upgrading or disabling the vulnerable component.
However, neither MANTRA nor Cosmos Labs has said that the 20 August incident involved the same ICS20 flaw. Until MANTRA releases its technical report, linking the latest exploit to the previously disclosed vulnerability would go beyond the available evidence.
The MANTRA token also fell sharply around the time of the network shutdown. Its price dropped from about $0.005060 to a record low of $0.004126, a decline of approximately 18.5%. CoinGecko data cited in market reports placed the low at roughly 23:10 UTC on 20 August, only minutes before the network’s final reported block.
Trading volume increased by nearly 600% to about $24m during the initial market reaction. MANTRA has not said that the sell-off was connected to the attack, so any relationship between the price movement and the incident remains unconfirmed.
Earlier in March, the token had risen 62% after MANTRA completed a rebrand, a network upgrade and a 1:4 non-dilutive token split. Under the change, holders received four MANTRA tokens for every former OM token, without changing the total value of their holdings at the point of conversion.
For US token holders using MANTRA’s native network, the shutdown prevented the same on-chain transactions, staking activity and transfers that were unavailable in other regions. The project did not report a separate impact on American users, while its confirmation that balances remained unchanged applied generally to all token holders.
MANTRA’s network is focused on tokenised real-world assets and is linked to several institutional projects. In June, Inveniam Capital Partners announced an agreement to acquire MANTRA and its affiliated entities after making a $20m strategic investment in the company in August 2025.
The two companies had also worked on NVNM Chain, a Layer 2 network built on MANTRA Chain for private-market asset data.
MANTRA said it would publish a full post-incident analysis covering the Cosmos-EVM vulnerability and its response in the coming days.
