A chain paused itself after an exploit — what 'user funds are unaffected' actually covers
MANTRA Chain was still halted on Aug. 21, after the team said an attacker exploited a vulnerability in an upstream depen…
MANTRA Chain was still halted on Aug. 21, after the team said an attacker exploited a vulnerability in an upstream dependency. With the mainnet paused, transactions, transfers, and staking are all unavailable, and deposits and withdrawals for the token had been paused on affected venues according to earlier incident updates. MANTRA said users did not need to take any action while the chain remained offline.
A halt like this is a deliberate move, not a crash. MANTRA first froze endpoints and transactions while reviewing the root cause and impact, then attributed the precautionary halt to an attacker exploiting the upstream dependency. The team has identified the vulnerable software only as an upstream dependency, meaning code the chain relies on rather than code it wrote itself. It said it was tracing fund movements, working with exchange partners, and continuing to assess the complete scope.
The fix is a patched release, v8.4.0, which MANTRA said addresses the underlying vulnerability. The project's GitHub release confirms the version and includes a mainnet upgrade handler. Before that software reaches mainnet it is being tested on the DuKong testnet, and that testing is the gate. MANTRA was targeting a restart later on Aug. 21, subject to testing completing cleanly.
Restarting is not something a single operator can do alone. MANTRA instructed validators to keep their mainnet nodes offline until it announces a coordinated restart, so the patched network returns through the wider validator set together. That coordination requirement is the point: a chain brought back piecemeal, with some nodes on old software and some on new, would not agree on a single history.
MANTRA said user funds were unaffected by the halt itself, and that a full network state snapshot was taken before the restart process began. That sentence rewards careful reading. The assurance is about the pause, which simply prevents transactions from being processed. The asset impact of the attacker's activity is a separate question, and it remains unconfirmed.
Two habits are worth taking from this. First, the chain is paused and nothing was lost are different claims; a project can honestly say the first while the second is still being investigated. Second, an outage is exactly the moment scammers wait for. Restart news, snapshot instructions, and any statement about compensation come from a project's official channels and its validators. A link that shows up in your replies or direct messages during an outage, asking you to connect a wallet, verify a balance, or sign something, is how funds actually get taken.