BTC $78,406.22 +0.49%
ETH $2,446.04 -0.33%
BNB $685.95 -0.85%
XRP $1.37 -1.15%
SOL $102.87 -1.71%
TRX $0.3350 -1.60%
DOGE $0.0826 -2.31%
ADA $0.1960 -2.21%
BCH $247.00 +0.73%
LINK $11.27 -0.73%
HYPE $81.29 -2.55%
AAVE $123.34 -0.67%
SUI $0.7215 -2.22%
XLM $0.1762 -1.43%
ZEC $825.17 -1.46%
BTC $78,406.22 +0.49%
ETH $2,446.04 -0.33%
BNB $685.95 -0.85%
XRP $1.37 -1.15%
SOL $102.87 -1.71%
TRX $0.3350 -1.60%
DOGE $0.0826 -2.31%
ADA $0.1960 -2.21%
BCH $247.00 +0.73%
LINK $11.27 -0.73%
HYPE $81.29 -2.55%
AAVE $123.34 -0.67%
SUI $0.7215 -2.22%
XLM $0.1762 -1.43%
ZEC $825.17 -1.46%

dent

All
Article
Flash

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

first_img The president of the Polish Olympic Committee was arrested on suspicion of cryptocurrency bribery

Polish Olympic Committee President Radosław Piszczek was arrested on Thursday, suspected of receiving kickbacks from the cryptocurrency platform Zondacrypto during the signing of a sponsorship agreement. Polish Sports Minister Jakub Rudnicki confirmed the arrest on the X platform, stating, "Such a person should not hold the position of President of the Polish Olympic Committee; Piszczek has brought shame to Polish sports." Interior Minister Marcin Kwiatkowski referred to him as "a symbol of extreme corruption plaguing the Olympic movement."According to the investigation, Piszczek facilitated the sponsorship agreement between the Polish Olympic Committee and Zondacrypto in October 2025, which promised cryptocurrency rewards to medalists of the 2026 Milan-Cortina Winter Olympics. The Polish government accused Zondacrypto of having ties to nationalist opposition groups, organized crime, and Russian intelligence agencies, estimating that the platform's collapse caused losses of about 350 million zlotys (approximately 80 million euros), affecting around 30,000 people. The Interior Minister described Zondacrypto as "essentially a Ponzi scheme."Media investigations also revealed that Piszczek received a Patek Philippe watch worth approximately 40,000 euros from Zondacrypto CEO Przemysław Kral, who claimed the watch was purchased out of his own pocket. Kral is currently cooperating with prosecutors in hopes of a reduced sentence. Zondacrypto was founded by Sylwester Sucheck in 2014, who went missing in 2022, with Kral taking over his position. The Polish prosecutors launched an investigation in April of this year, and most Polish sports federations subsequently called for Piszczek's resignation.
app_icon
ChainCatcher Building the Web3 world with innovations.