$MANTRA Another Cosmos-EVM exploit. This time @MANTRA_Chain for ~720m $OM, but $0 in value.
Traced it on-chain, it's not a mint bug, total supply is unchanged.
An attacker drained 720,923,967.99 OM from two accounts they had no keys for:
600,000,035.55 OM from the null/burn address.
120,923,932.44 OM from a genesis-era 3-of-5 multisig.
The flaw is in the Cosmos-EVM stack (cosmos/evm v0.6.0 + x/auth/vesting + the staking precompile), not MANTRA's app logic, a contract with a victim address baked in ends up able to debit that victim via the bank layer.
Attacker: mantra13n9sk3p8x7tpq9adgxvzv9q0qev953mld0hwva, 24 txs, all in this incident.
https://explorer.mantrachain.io/MANTRA/account/mantra13n9sk3p8x7tpq9adgxvzv9q0qev953mld0hwva
None of it left the chain. The halt froze all of it
Traced it on-chain, it's not a mint bug, total supply is unchanged.
An attacker drained 720,923,967.99 OM from two accounts they had no keys for:
600,000,035.55 OM from the null/burn address.
120,923,932.44 OM from a genesis-era 3-of-5 multisig.
The flaw is in the Cosmos-EVM stack (cosmos/evm v0.6.0 + x/auth/vesting + the staking precompile), not MANTRA's app logic, a contract with a victim address baked in ends up able to debit that victim via the bank layer.
Attacker: mantra13n9sk3p8x7tpq9adgxvzv9q0qev953mld0hwva, 24 txs, all in this incident.
https://explorer.mantrachain.io/MANTRA/account/mantra13n9sk3p8x7tpq9adgxvzv9q0qev953mld0hwva
None of it left the chain. The halt froze all of it