August 22, 2026:


The vulnerability that halted MANTRA Chain late Thursday was not new. The Cosmos EVM ICS20 precompile flaw — documented in security advisory ASA-2026-002 and publicly patched in March 2026 — had already cost the Saga EVM network approximately $7 million in January 2026, and MANTRA was among the 15 chains that Cosmos Labs contacted to coordinate remediation — documented in the Cosmos Labs coordinated remediation advisory. What happened Thursday night raises a more troubling question than “how was MANTRA exploited?” — it raises the question of why a chain listed as a remediation participant was still vulnerable five months after the fix shipped.
At approximately 7:13 PM ET on Thursday, August 20, MANTRA Chain recorded its final block and went dark. In the minutes before the halt, the native MANTRA token had already fallen to $0.004126 — a new all-time low, a decline of roughly 18.5% from the session’s earlier level of approximately $0.005060, according to MANTRA token all-time-low price data. By Friday morning, trading volume had surged nearly 650% to approximately $24 million as holders rushed to act on centralized exchanges where spot trading remained available, and CoinGlass MANTRA futures data showed around $10 million in MANTRA futures volume during the same window.
The halt was comprehensive. MANTRA’s official status page listed the incident as affecting public endpoints, the validator set, the “Migrate” bridge, and all MANTRA-managed IBC relays — the pathways that allow the Cosmos-based blockchain to exchange assets with other networks. MEXC suspended MANTRA deposits and withdrawals at the project’s request, and South Korean platforms Upbit and Bithumb halted MANTRA-branded token transfers. Spot trading of the token continued on centralized platforms throughout the outage, which is why the 650% volume spike was possible even as on-chain activity was fully frozen.
What did not halt: the mounting set of questions about how this happened.
MANTRA’s engineering and security teams, working alongside external security partners, traced the incident to the Cosmos EVM module — specifically, its ICS20 precompile component. In a statement posted to X at approximately 5:45 AM ET Friday, MANTRA’s root-cause X statement read: “We have identified the root cause of the incident and contained the immediate threat. The incident was isolated to the Cosmos EVM module of MANTRA Chain and affected two wallet addresses before we achieved containment. No user funds were exploited.”
The ICS20 precompile is the software bridge that allows smart contracts running on the Ethereum Virtual Machine (EVM) side of MANTRA Chain to trigger cross-chain token transfers via the Cosmos network’s IBC (Inter-Blockchain Communication) protocol. The specific vulnerability — documented in ASA-2026-002 technical root cause and published on GitHub in March 2026 — involves incorrect state handling during nested EVM execution. When a smart contract calls the ICS20 precompile and then reverts its own state back to its original value within the same transaction, the EVM’s state-commit mechanism treats the transaction as if no change occurred and skips writing intermediate state to the chain’s key-value store — but the ICS20 token transfer had already executed. The practical result: an attacker can effectively spend the same token balance multiple times within a single transaction.
This is the precise attack vector used against Saga EVM on January 21, 2026. In that incident, as documented in Halborn’s Saga EVM hack analysis, an attacker used forged IBC messages to mint Saga’s dollar-pegged stablecoin without providing collateral, drained approximately $7 million in assets, bridged them to Ethereum, and converted proceeds to ETH. Cosmos Labs was notified on January 21, investigated the vulnerability across the entire Cosmos EVM ecosystem, and coordinated mitigations — then released the permanent fix as v0.6.0 in March 2026. According to the advisory, 15 chains were identified as running affected code. ASA-2026-002’s acknowledgements section explicitly lists MANTRA alongside Saga, B-Harvest, Zellic, and Sherlock as a participant in the investigation and remediation effort.
That makes today’s incident something more than bad luck. It raises a specific question: was the v0.6.0 patch fully applied to MANTRA Chain’s mainnet before Thursday’s exploit occurred? MANTRA has not yet answered this in its public statements, and the post-mortem the team has promised will be the first place to look for the answer.
The August 18 EVM upgrade to the MANTRA Zone platform — noted by Coinpedia’s August 18 upgrade coverage and referenced on MANTRA’s own X account as a “major EVM upgrade” in celebration of the project’s sixth anniversary — appears, based on available reporting, to be an interface and ecosystem upgrade rather than a change to the underlying chain protocol. Whether it altered the chain’s EVM module configuration is an open question the post-mortem should resolve.
The cosmos/evm GitHub repository is a shared, open-source infrastructure component used by several networks including MANTRA, Ondo, Mezo, the XRP sidechain, and the Telegram Application Chain. “EVM precompiles” are special-purpose contracts at fixed addresses that execute native code rather than EVM bytecode — they let Ethereum-style smart contracts access Cosmos features like IBC transfers directly, without bridging in the traditional sense. The ICS20 precompile specifically handles cross-chain token movements between the EVM environment and the Cosmos IBC ecosystem.
The elegance of the design is also its risk surface: a vulnerability in a shared precompile is a vulnerability in every chain that runs it and has it enabled. The Cosmos EVM v0.6.0 patch notes addressed state synchronization between the EVM’s stateDB and the Cosmos SDK’s key-value store — ensuring that when a nested execution path reverts, the precompile’s effects revert with it. MANTRA’s v8.4.0 patch, currently being tested on its DuKong testnet, is expected to bring its mainnet in line with the corrected behavior; validators are instructed to remain offline until the coordinated upgrade is officially signaled.
The market registered the halt before an official explanation existed. MANTRA’s token was already falling toward its all-time low when the chain recorded its last block. The approximately 18.5% decline — from roughly $0.005060 to $0.004126 — extended what was already a brutal period. Even before Thursday’s incident, MANTRA had fallen approximately 83% from its MANTRA post-migration price high of $0.02627, set in March 2026 after the project completed its 1:4 token redenomination from OM to MANTRA.
That migration itself followed the most damaging episode in the project’s history: the MANTRA’s April 2025 token collapse of the legacy OM token, which lost more than 90% of its value within hours and erased over $5 billion in market capitalization. CEO John Patrick Mullin attributed that event to Mullin blamed forced exchange liquidations — a characterization that remained contested by portions of the market.
Thursday’s token recovery to approximately $0.0046 by Friday morning suggests the market accepted MANTRA’s “no user funds exploited” claim at some level. But the 650% volume surge — with approximately $10 million in futures activity on top of the spot trading — reflects a meaningful quantity of holders treating this as an exit event rather than a buying opportunity.
As of midday ET Friday, August 21, MANTRA Chain remains fully offline. All endpoints, transactions, transfers, and staking operations are suspended, per MANTRA’s official status page. The patched v8.4.0 build is being tested on the DuKong testnet, and MANTRA indicated it aims to complete a coordinated mainnet upgrade within the day — contingent on testing proceeding without additional complications. A full post-mortem is promised once the network is restored. Validators have been directed to hold their nodes offline until the restart signal is officially announced.
What the post-mortem needs to answer goes beyond “what was exploited.” Given that the specific component identified — the Cosmos EVM ICS20 precompile — was the subject of a critical-severity advisory published five months ago, and given that MANTRA was listed as a participant in that advisory’s coordinated remediation process, the post-mortem must explain the gap between participation in remediation and a fully patched production network.
That gap has consequences for more than just Thursday’s token holders. MANTRA holds a digital-asset license from Dubai’s Virtual Assets Regulatory Authority (VARA), a credential the project has emphasized in positioning itself as a compliance-first RWA platform, as documented on MANTRA’s VARA regulatory license page. Institutional participants considering tokenized real-world assets on MANTRA Chain — whether real estate, private credit, or fund shares — require settlement finality and operational uptime that a full-network halt demonstrably does not provide.
More acutely: Inveniam Capital Partners, which invested $20 million in MANTRA in August 2025 and announced plans to acquire MANTRA and its affiliated entities in a transaction expected to close in Q3 2026 per the Inveniam acquisition press release, has not issued a public statement regarding Thursday’s events. The NVNM Chain — a Layer 2 that Inveniam and MANTRA jointly launched in May 2026, confirmed in the NVNM Chain May 2026 launch announcement, which inherits security from MANTRA Chain through Interchain Security — means MANTRA’s chain downtime has downstream implications for Inveniam’s own infrastructure.
Whether Thursday’s events prompt Inveniam to reassess the timing or terms of the acquisition — or simply wait for the post-mortem — is a question with no public answer yet.
MANTRA’s halt arrived days after Maya Protocol’s $1.7M cross-chain exploit halted its own cross-chain network following a separate exploit, and WEMIX separately suspended bridge and decentralized trading services after WEMIX bridge suspension announcement allowed unauthorized token minting. The H1 2026 crypto security landscape, documented as comprising 212 verified exploits and over $1.1 billion in losses in the first six months of the year, established a record pace that the summer has only continued.
The Cosmos EVM ecosystem specifically represents a documented pattern: shared infrastructure with a documented vulnerability, a coordinated patch, and chains that — for reasons the individual post-mortems will need to explain — remain exposed. MANTRA becomes the second publicly known chain after Saga to be exploited through this vector; the question is whether it becomes the last.
Users should follow only official MANTRA channels for updates at x.com/MANTRA_Chain and the project’s MANTRA’s social engineering warning. Anyone offering to help recover frozen funds through unofficial channels or websites should be treated as a social engineering attempt — this is a documented predatory pattern during high-profile network outages, and MANTRA has explicitly warned users about it.
The Cosmos EVM ICS20 precompile vulnerability was publicly disclosed and patched in March 2026 (advisory ASA-2026-002), and MANTRA was named as one of the 15 chains that participated in the original coordinated remediation. The fact that MANTRA appears to have been exploited through the same vulnerability five months later suggests either that the v0.6.0 fix was not fully applied to the mainnet — possibly during MANTRA’s August 18 EVM upgrade — or that a related execution path in the same component remained unpatched. MANTRA’s forthcoming post-mortem is the only place this question will be definitively answered. Until then, the gap between “named remediation participant” and “exploited through that same vulnerability” is the central accountability question.
MANTRA’s team stated explicitly that “no user funds were exploited” and that the exploit was contained to two wallet addresses before further damage occurred. Token holdings on centralized exchanges (MEXC, Upbit, Bithumb) are subject to those exchanges’ own security and custody practices, which are separate from the MANTRA Chain itself. On-chain funds in MANTRA wallets are currently inaccessible due to the halt — they are frozen, not lost — and access should be restored once the patched network comes back online. However, independent verification of MANTRA’s “no funds lost” claim will only be possible after the full post-mortem is published.
The Cosmos EVM module (github.com/cosmos/evm) is shared infrastructure used by multiple blockchain networks — including MANTRA, Ondo, Mezo, the XRP sidechain, and the Telegram Application Chain — to add Ethereum Virtual Machine compatibility to Cosmos-based chains. The ICS20 precompile is the specific component that allows EVM smart contracts to initiate cross-chain token transfers through the Cosmos IBC protocol. The vulnerability in this precompile is a state-handling bug: under certain nested execution conditions, a token transfer executes but the state record says no tokens moved, allowing the same balance to be spent multiple times. All 15 chains identified in January 2026 as running affected code were notified and asked to apply mitigations. MANTRA’s case demonstrates that notification and participation in remediation did not guarantee a fully patched production environment.
Inveniam Capital Partners announced plans in June 2026 to acquire MANTRA and its affiliated entities, with the deal expected to close in Q3 2026. Inveniam has not issued a public statement about Thursday’s events. The NVNM Chain — a Layer 2 that Inveniam and MANTRA jointly launched in May 2026, which inherits security from MANTRA Chain — was also affected by the underlying MANTRA halt. Whether the acquisition terms or timeline will be revisited depends on the post-mortem findings and Inveniam’s internal assessment of the chain’s security posture. No deal changes have been publicly announced as of Friday afternoon ET.