Loading...
MANTRA released a security incident report on August 20th, stating that attackers exploited the Cosmos EVM integer overflow vulnerability to transfer 720.924 million MANTRAs from two addresses, which amounts to approximately 3.6 million US dollars at a unit price of 0.005 US dollars. Among them, 600 million pieces come from the destruction address, and 121 million pieces come from the Genesis multi signature address. The attack did not involve validator or administrator keys. The vulnerability was fixed in the development branch on May 15th and merged into the release branch on August 19th. On August 21st at 11:06 (UTC+8), the first abnormal transfer occurred, and MANTRA Chain stopped at 15:13 (UTC+8). On August 22nd, it was restarted under version v8.4.0. Of the stolen funds, 683 million have been deposited into exchange recharge addresses, while the remaining 37.96 million have been frozen. The recovery of funds has entered the stage of law enforcement investigation.