MANTRA Chain halted Layer 1 operations late Thursday, August 20, following an exploit in its Cosmos EVM module. The chain recorded its final block at approximately 7:13 PM ET before going dark, with MANTRA officially disclosing the halt at 8:10 PM ET.

The native MANTRA token fell to an all-time low of $0.004126, down 18.5 percent from $0.005060 earlier in the session.

MANTRA's engineering and security teams identified the vulnerability in the Cosmos EVM module's ICS20 precompile—the software bridge that allows smart contracts on the EVM side to initiate cross-chain token transfers via Cosmos' Inter-Blockchain Communication protocol. The flaw involves incorrect state handling during nested EVM execution, triggered when a smart contract calls the ICS20 precompile and subsequently reverts its own state.

This specific vulnerability was detailed in security advisory ASA-2026-002 and patched publicly in March 2026. The same exploit previously hit the Saga EVM network in January 2026, resulting in approximately $7 million in losses. Following that incident, Cosmos Labs contacted 15 chains, including MANTRA, to coordinate remediation. MANTRA remained vulnerable five months after the patch shipped despite being listed as a remediation participant.

Trading activity spiked despite the network freeze. MANTRA token volume on centralized exchanges surged nearly 650 percent to approximately $24 million on Friday, while around $10 million in MANTRA futures volume traded over the same period, according to CoinGlass data.

The halt affected multiple critical components: public endpoints, the validator set, the Migrate bridge, and all MANTRA-managed IBC relays. MEXC suspended MANTRA deposits and withdrawals at the project's request. South Korean exchanges Upbit and Bithumb also halted MANTRA-branded token transfers.

MANTRA's team issued a statement at approximately 5:45 AM ET Friday, confirming the root cause and containment of the immediate threat. The team said the incident was isolated to the Cosmos EVM module and affected two wallet addresses, with no user funds exploited.