BTC $79,509.22 -0.89%
ETH $2,509.02 -0.36%
BNB $704.41 -0.78%
XRP $1.43 -2.13%
SOL $105.95 -1.14%
TRX $0.3404 +0.80%
DOGE $0.0873 -1.91%
ADA $0.2100 -2.21%
BCH $255.53 -5.51%
LINK $11.82 -0.22%
HYPE $84.74 +0.52%
AAVE $125.40 -2.28%
SUI $0.7708 -1.45%
XLM $0.1825 -2.76%
ZEC $810.65 +2.01%
BTC $79,509.22 -0.89%
ETH $2,509.02 -0.36%
BNB $704.41 -0.78%
XRP $1.43 -2.13%
SOL $105.95 -1.14%
TRX $0.3404 +0.80%
DOGE $0.0873 -1.91%
ADA $0.2100 -2.21%
BCH $255.53 -5.51%
LINK $11.82 -0.22%
HYPE $84.74 +0.52%
AAVE $125.40 -2.28%
SUI $0.7708 -1.45%
XLM $0.1825 -2.76%
ZEC $810.65 +2.01%

transfer

All
Article
Flash

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

first_img The British judge rejected the extradition defense of the former CEO of Saitama, and the case has been transferred to the UK government

According to a report by Reuters, British judge Samuel Goozee dismissed the extradition defense of former Saitama CEO Manpreet Kohli on August 19 and transferred the case to the UK government to make a decision on the US extradition request. Kohli can still appeal, and the extradition has not been finalized; he is currently released on bail set at £200,000 (approximately $272,400).US prosecutors have charged Kohli with wire fraud, market manipulation, and related conspiracy, as well as operating an unlicensed remittance business, involving the Ethereum-based token Saitama, which once had a market value of about $7.5 billion. Kohli defended himself by arguing that the US could not adequately handle his mental health and the risk of suicide during detention, but the judge believed that the transfer and the safeguards of the US prison system could reduce the risk to an acceptable level. Previously, a federal judge in Boston had also dismissed his motion to dismiss the charges.The case stems from the "Operation Token Mirrors" investigation initiated by the US Department of Justice in October 2024, involving fraud and wash trading. Prosecutors allege that 18 individuals, including Kohli, coordinated multiple wallets to purchase tokens and paid ZM Quant and Gotbit to conduct wash trading on several exchanges, with Kohli suspected of profiting about $20 million. Gotbit has admitted to manipulating token prices and trading volumes and was ordered to pay $23 million in June 2025, while its founder Aleksei Andriunin was sentenced to 8 months in prison.

first_img ECB officials say that the digital euro will provide higher privacy protection than bank transfers

European Central Bank (ECB) Executive Board member Piero Cipollone stated in a recent interview that the digital euro will provide stronger privacy protection than regular bank transfers. He pointed out that the euro system is structurally unable to associate specific individuals with their digital euro transactions, whether online or offline.Cipollone stated that offline payments will be conducted entirely directly between individuals, with transaction details visible only to the payer and payee, equivalent to cash transactions; only banks participating in online transactions will be able to identify user identities, and this will only be used for anti-money laundering purposes. He also refuted concerns that the digital euro would replace physical cash, citing the ECB's recent public consultation on the design of the new euro banknotes as an example, stating, "If institutions intend to eliminate cash, it makes no sense to do so."Cipollone's remarks come at a time when public opposition to the digital euro is rising. Civil society groups such as the Austrian digital rights organization Epicenter.works warned in a joint statement earlier this month that the privacy protections of the digital euro "over-rely on institutional commitments rather than technical execution," and that legislative commitments may be weakened in implementation, reinterpreted in court, or even broken. The digital euro regulation was approved by the European Parliament last month, with plans to launch in 2029. ECB President Lagarde previously stated that the digital euro will coexist with physical cash.
app_icon
ChainCatcher Building the Web3 world with innovations.