MANTRA 发布 Cosmos EVM 漏洞事件报告,攻击者共转移约 360 万美元 MANTRA

MANTRA 发布 Cosmos EVM 漏洞事件报告,攻击者共转移约 360 万美元 MANTRA

2026-08-28 18:45

ChainThink 消息,8 月 28 日,据 MANTRA 官方报告,8 月 20 日安全事件系攻击者利用 Cosmos EVM 上游模块的无符号整数下溢漏洞,从两个未经授权地址转移 720,923,967.99 枚 MANTRA(按事发当日约 0.005 美元计算,约合 360 万美元)。

其中 6 亿枚来自销毁地址,1.21 亿枚来自一个与激励相关的创世多签地址。攻击未涉及验证人密钥、管理员密钥、治理权限或多签签名人,攻击者未获得特权访问。

MANTRA 表示,该漏洞于 5 月 15 日在 Cosmos EVM 开发分支修复,但直至 8 月 19 日才被回溯合并进发布分支,距首次攻击仅约 20 小时,未给下游链留出充足响应窗口。

链上首笔异常转账发生于 8 月 21 日 3:06,因销毁地址此前被视为不可转移且未被监控覆盖,近 4 小时后才被发现。

MANTRA Chain 于 7:13 停链,历时 30 小时 13 分钟后,在修复版本 v8.4.0 下由 38 个独立验证人协调重启,未发生回滚或状态重写。

报告称,被盗资金中约 94.7%(6.83 亿枚)已通过 15 笔转账流向某交易所充值地址,剩余约 3796 万枚(占比 5.27%)仍滞留于攻击者账户并已被冻结,但强调“冻结不等于已找回”,资金追回已进入执法调查阶段。

MANTRA 表示未有任何客户账户、交易所托管余额或应用合约被扣款,但网络中断对生态造成实质影响,已针对交易账户来源与签名者不一致等异常行为建立新的监控规则。

Disclaimer: Contains third-party opinions, does not constitute financial advice

Recommended Reading

NVIDIA attracts $85 billion in investor demand during massive bond issuance

06-16
NVIDIA attracts $85 billion in investor demand during massive bond issuance

Ethereum surges over 10% in 24 hours, currently priced at $1,841.31

06-16
Ethereum surges over 10% in 24 hours, currently priced at $1,841.31

Amazon announces a multi-billion dollar investment in Missouri to build a data center campus, expected to create over 400 long-term positions

06-16
Amazon announces a multi-billion dollar investment in Missouri to build a data center campus, expected to create over 400 long-term positions

Binance Platform's SpaceX Perpetual Contract Trading Volume Surpasses $9 Billion, Capturing Over 60% Market Share

06-16
Binance Platform's SpaceX Perpetual Contract Trading Volume Surpasses $9 Billion, Capturing Over 60% Market Share

Binance platform XLM/USDT short-term spike down to $0.17, now recovered to $0.225

06-16
Binance platform XLM/USDT short-term spike down to $0.17, now recovered to $0.225

Trump: The Strait of Hormuz has been fully reopened as of Friday, and all agreements have been signed

06-16
Trump: The Strait of Hormuz has been fully reopened as of Friday, and all agreements have been signed

SlowMist: Aztec Connect Contract Hacked for $2.19 Million Due to ZK-Rollup L1/L2 State Boundary Vulnerability

06-15
SlowMist: Aztec Connect Contract Hacked for $2.19 Million Due to ZK-Rollup L1/L2 State Boundary Vulnerability