|

MANTRA Chain is back online, but silent code changes spark developer concerns

MANTRA Chain recovery timeline and comparison of verified public records with still-undisclosed exploit details

MANTRA Chain restored mainnet block manufacturing on v8.4.0 six days after a safety incident compelled a chainwide halt. The promised technical account stays unpublished, leaving the exploitation of the upstream dependency and the exercise inside two project-managed wallets unexplained.

The official incident timeline says mainnet resumed at roughly 05:30 UTC on Aug. 22. The chain mentioned there was no rollback or state change between the halt and restart, person balances weren’t altered, and token holders didn’t have to take motion.

The workforce behind the chain marked the incident resolved on Aug. 24 but once more mentioned a postmortem would arrive within the coming days. Its present status page and official announcement channel contained no hyperlink to that report when checked on Aug. 27.

MANTRA mentioned its evaluation discovered that the incident affected two MANTRA-managed wallets and that no person, change, or associate funds had been affected. The public account stops in need of figuring out the pockets addresses, transaction hashes, quantities, or technical exploit steps.

When the halt was reported on Aug. 21, patch testing was nonetheless underway. The community’s return resolves that operational query whereas leaving the attacker’s technique and MANTRA’s containment evaluation unexplained.

Related Reading

Mantra, market makers allegedly exploited validation gaps to inflate OM token liquidity


MANTRA Chain recovery timeline and comparison of verified public records with still-undisclosed exploit details
A timeline separates verified MANTRA Chain restoration steps from still-undisclosed pockets, transaction, quantity, exploit-path, and ICS20-link particulars.

For node operators, the general public code report has an instantaneous implication: determine which v8.4.0 construct is operating. The present release page factors to full commit 5c08d7bd9e2619952707dae1258d2a30bf024721, whereas MANTRA warns that the tag was re-pushed throughout restoration and tells operators to re-pull it.

The launch changelog lists an intermediate MANTRA EVM fork bump from v0.6.0-v8-mantra-3 to v0.6.0-v8-mantra-4. The last tagged go.mod replaces the dependency with the chain’s v0.6.2-v8-mantra-1 fork.

The last upgrade handler blocklists one tackle and disables three Cosmos vesting-account creation messages by means of the circuit breaker. Those changes describe the deployed mitigation whereas leaving the assault path undisclosed.

Why the March ICS20 flaw stays solely a principle for MANTRA customers

A March Cosmos Labs advisory described a vital ICS20 precompile flaw, mentioned identified affected chains had mitigated or upgraded, and named Mantra amongst remediation collaborators. Its timeline ends with the March disclosure, leaving the August incident exterior its documented scope.

Users can confirm the restart, the precise last code, and said impression. Wallet addresses, transaction hashes, quantities, and a technical rationalization stay essential to hint the disclosed pockets impression from MANTRA’s public account and decide whether or not the incident repeated the sooner ICS20 bug.

The submit MANTRA Chain is back online, but silent code changes spark developer concerns appeared first on CryptoSlate.

Similar Posts