BeChain

Market Prices

BTC Bitcoin
$79,949.8 +0.24%
ETH Ethereum
$2,496.06 +0.71%
SOL Solana
$105.72 +2.32%
BNB BNB Chain
$751.2 -2.61%
XRP XRP Ledger
$1.42 +0.13%
DOGE Dogecoin
$0.0900 -0.78%
ADA Cardano
$0.2211 +0.68%
AVAX Avalanche
$7.71 +1.54%
DOT Polkadot
$0.9662 +5.80%
LINK Chainlink
$12.52 +4.27%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,949.8
1
Ethereum ETH
$2,496.06
1
Solana SOL
$105.72
1
BNB Chain BNB
$751.2
1
XRP Ledger XRP
$1.42
1
Dogecoin DOGE
$0.0900
1
Cardano ADA
$0.2211
1
Avalanche AVAX
$7.71
1
Polkadot DOT
$0.9662
1
Chainlink LINK
$12.52

🐋 Whale Tracker

🔴
0x1aad...70da
1d ago
Out
4,139.19 BTC
🔴
0x3b7c...b693
3h ago
Out
166,354 USDC
🔴
0x7d67...5ff0
2m ago
Out
5,689,403 DOGE
Special

When Dead Addresses Wake Up: The Cosmos EVM Accounting Flaw That Turned Burned Tokens Into Loot

CryptoPanda
The clock stopped at 4 AM on August 28. But the chain didn't care. Somewhere between block finality and a monitoring dashboard that was busy assuming the dead stay dead, 720.9 million MANTRA tokens just sprouted legs. Not minted. Not printed. Activated. The burn address—that sacred graveyard where tokens go to die—had become a vault with an open door. And the market didn't crash. It held its breath, then shrugged. That shrug tells you everything about how broken our mental models of chain security really are. Let me rewind to the details, because speed is the only currency that matters here. On April 25, a vulnerability report landed in Cosmos Labs' inbox. The verdict? An unsigned integer underflow paired with an account overflow in the Cosmos EVM module. The initial assessment? Low risk, only exploitable on networks with six decimal places. Classic. The kind of confident misjudgment I've seen a dozen times in my own audits. Fast forward to August. That assumption shatters like a champagne glass on a marble floor. The flaw hits every Cosmos EVM deployment, regardless of decimal config. Forty networks get contacted. Thirteen patch before the attack. Six get exploited. Eleven deployments—eleven—were so invisible that Cosmos Labs didn't even know they existed. Trust no one, verify everything, move fast. They verified slow. Now, the meat. I've spent years staring at accounting logic in DeFi protocols, and this one is a textbook case of cascading failure. The attack path is elegant in its brutality. First, trigger the underflow to create a grotesquely inflated balance. Then, use that poisoned state to overflow another account. Finally, drain the legitimate balance without increasing total supply. No new tokens. No inflation. Just a redistribution of what everyone assumed was permanent dead weight. The burn address—0x000...dead—held about 600 million MANTRA. A genesis-era multisig held another 120.9 million. Both were "dormant balances," the kind of supply that tokenomic models treat as forever excluded. The attacker didn't hack the consensus layer. They hacked the assumption layer. And that's the part nobody prices in. A few numbers to anchor this. Direct losses clock in around $5.72 million—$2.87 million on DEXs, $2.85 million on CEXs. Against Cosmos' $7 billion+ TVL, that's a rounding error: under 0.1%. But the indirect damage? That's where the story bends. The patch was distributed as a "silent public patch." Merge the fix into the public repo, don't shout about it, hope nobody notices. The attacker noticed. They struck within 12 hours of the patch going live. That's not a coincidence. That's someone watching the commit history like a hawk. Based on my own experience with disclosure timelines, I'd put high confidence on the patch being reverse-engineered from the public code. You don't move that fast without a map. Then there's the monitoring failure. MANTRA's own dashboard flagged the burn address as "immovable funds." For nearly four hours, abnormal transactions slid through without a single alert. Four hours. In crypto, that's an eternity. Liquidity flows where trust is liquid, but trust evaporates when your security stack treats a graveyard as a fortress. I've seen this pattern before—in 2022, during the Ethereum Merge sprint, I scraped validator data and spotted a 15% deviation in slashing rates that the official monitors missed for hours. The lesson is always the same: your monitoring logic is only as good as its assumptions. And assumptions about immutability are the most dangerous kind. Here's where I go contrarian. Everyone's focused on the $5.7 million stolen, the underflow, the overflow, the patch. They're asking, "Is MANTRA safe now?" That's the wrong question. The real story is that the token's supply is now permanently larger by 720.9 million units. The burn mechanism—the one feature that gave holders confidence in scarcity—just got reclassified as a myth. The market's response tells you how under-priced this is. MANTRA dropped to an all-time low, then bounced 14% to around $0.004744. That's not resilience. That's mispricing. I saw the same delusion during the Lido stETH depeg chatter in 2023, when everyone called it a dip and it turned out to be a structural repricing. The 38 million MANTRA still sitting in the attacker's wallet? That's not a windfall. That's a sword hanging over the order book. If they start selling, the 14% bounce turns into a 40% slide. And the CEX angle? A few accounts with exchange activity got frozen in the aftermath. That's the compliance machinery waking up. It looks good for the exchanges—like they're on top of it. But in my book, most exchange "Proof of Reserves" exercises are theater anyway. They prove a snapshot, not a process. Freezing accounts now is damage control, not prevention. The real question is whether KYC data gets handed over, whether AML investigations spiral, and whether the regulatory gaze shifts from the attacker to the platforms that let $2.85 million flow through without a flag. That's the chain reaction nobody's watching. Now zoom out. This isn't a MANTRA problem. It's a Cosmos EVM problem, which means it's a shared-software-layer problem. One module, forty-plus chains. That's the single point of failure you get when modularity optimizes for speed and permissionless innovation over security. The fact that Cosmos Labs didn't know about eleven deployments isn't a knowledge gap. It's an architectural blind spot. Permissionless deployment means anyone can run the code, but it also means no one has a complete map of the attack surface. The merger wasn't the dress rehearsal for this—it was a warning. And the industry didn't listen. Here's what I think happens next. First, security auditors are going to have a field day. Forty-plus networks need their accounting logic re-reviewed, and that's a 3-to-6-month revenue pipeline for every audit firm in the space. Second, the "shared security" narrative—the Polkadot model, actively validated services, the whole ecosystem safety net—just got a massive credibility boost. This event is the best argument for pooled security since the DAO hack. Third, and this is the one I'm betting on, expect the next wave of cross-chain standards to mandate continuous monitoring and private patch distribution as baseline requirements. Silent public patches? Dead. The cat's out of the bag, and the attackers subscribe to the same repos you do. But here's the uncomfortable truth nobody wants to admit. The underflow and overflow are fixed. The patched code is live. But the accounting logic in Cosmos EVM was built on a foundation of assumptions that just proved false. If two edge cases could combine to drain a burn address, what else is hiding in the margins? I've audited enough DeFi protocols to know that every bug you find is preceded by a bug you didn't. The 45-day window between report and re-assessment, the 12-hour gap between patch and exploit, the 11 unknown deployments—these aren't one-off failures. They're symptoms of a security culture that treats verification as an afterthought. Whispers before the ticker opens—that's how this ended up in my feed. The market's calm now. MANTRA bounces, Cosmos shrugs, and the ecosystem moves on. But the next time a burn address gets "activated," or a multisig drains without a transaction, remember this: the chain doesn't forget, and neither should you. The question isn't whether the patch holds. It's whether your model of what's "impossible" is ready for its next underflow. Staking is a promise, liquidity is the reality. And reality, in this case, just woke up a few billion tokens from the dead. I'm Andrew Wilson, and I'll be watching the attacker's wallet like a hawk. You should too.

Fear & Greed

73

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xc5b7...7af7
Top DeFi Miner
+$3.2M
61%
0x284f...ac59
Experienced On-chain Trader
+$1.8M
81%
0x5335...8f2c
Arbitrage Bot
-$0.5M
66%