MANTRA Chain is back online, but silent code changes spark developer concerns

요약:MANTRA mainnet is running on v8.4.0, while wallet addresses, transaction hashes, amounts and the attack path remain undisclosed.

MANTRA Chain restored mainnet block production on v8.4.0 six days after a security incident forced a chainwide halt. The promised technical account remains unpublished, leaving the exploitation of the upstream dependency and the activity inside two project-managed wallets unexplained.

Related Asset MANTRA #557 MANTRA · $0.00414 24-hour change: up 0.47% 24H Up 0.47% 7D Down 7.22% 30D Down 23.97%

The official incident timeline says mainnet resumed at approximately 05:30 UTC on Aug. 22. The chain said there was no rollback or state change between the halt and restart, user balances were not altered, and token holders did not need to take action.

The team behind the chain marked the incident resolved on Aug. 24 but again said a postmortem would arrive in the coming days. Its current status page and official announcement channel contained no link to that report when checked on Aug. 27.

MANTRA said its analysis found that the incident affected two MANTRA-managed wallets and that no user, exchange, or partner funds were affected. The public account stops short of identifying the wallet addresses, transaction hashes, amounts, or technical exploit steps.

When the halt was reported on Aug. 21, patch testing was still underway. The network's return resolves that operational question while leaving the attacker's method and MANTRA's containment assessment unexplained.

A timeline separates verified MANTRA Chain recovery steps from still-undisclosed wallet, transaction, amount, exploit-path, and ICS20-link details.

For node operators, the public code record has an immediate implication: identify which v8.4.0 build is running. The current release page points to full commit 5c08d7bd9e2619952707dae1258d2a30bf024721, while MANTRA warns that the tag was re-pushed during recovery and tells operators to re-pull it.

The release changelog lists an intermediate MANTRA EVM fork bump from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4. The final tagged go.mod replaces the dependency with the chain's v0.6.2-v8-mantra-1 fork.

The final upgrade handler blocklists one address and disables three Cosmos vesting-account creation messages through the circuit breaker. Those changes describe the deployed mitigation while leaving the attack path undisclosed.

Why the March ICS20 flaw remains only a theory for MANTRA users

A March Cosmos Labs advisory described a critical ICS20 precompile flaw, said known affected chains had mitigated or upgraded, and named Mantra among remediation collaborators. Its timeline ends with the March disclosure, leaving the August incident outside its documented scope.

Users can verify the restart, the exact final code, and stated impact. Wallet addresses, transaction hashes, amounts, and a technical explanation remain necessary to trace the disclosed wallet impact from MANTRA's public account and determine whether the incident repeated the earlier ICS20 bug.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

‘트윗’ 가능…$20 트위터 클론 출시, X 소송에도

다음

비트코인이 8만 달러 회복에 실패하면서 공급 흡수가 ‘핵심 질문’으로 부상: 분석