OKX Banner
BTC $78,623.00 (-0.68%)
ETH $2,465.27 (-2.02%)
BNB $688.47 (-2.02%)
XRP $1.37 (-2.61%)
SOL $102.49 (-3.99%)
TRX $0.33 (-2.18%)
HYPE $81.84 (-2.14%)
ZEC $839.67 (-3.75%)
DOGE $0.08 (-3.50%)
RAIN $0.02 (-2.73%)
XMR $522.21 (+4.70%)
LEO $9.64 (+0.70%)
LINK $11.32 (-2.77%)
ADA $0.20 (-4.43%)
XLM $0.18 (-2.80%)
BCH $244.76 (-3.53%)
CC $0.12 (-0.95%)
GRAM $1.42 (+3.02%)
LTC $48.37 (-3.41%)
USDG $1.00 (+0.01%)

Cosmos EVM Bug Drains $5.7M Across Six Blockchains

Share on X icon · Published hace 10 horas on August 31, 2026 · Hassan Maishera

Attackers exploited a critical Cosmos EVM flaw across six networks, converting about $5.7 million in stolen tokens as affected chains criticized the patch disclosure process.

Cosmos EVM Bug Drains $5.7M Across Six Blockchains

TL;DR

  • Attackers exploited an integer-underflow flaw in Cosmos EVM across six blockchain networks between August 20 and August 25.

  • The stolen tokens were exchanged for approximately $2.87 million on decentralized exchanges and $2.85 million on centralized platforms.

  • Cosmos Labs learned of the vulnerability in April but initially concluded that production networks were not at risk.

Cosmos EVM Vulnerability Exploited Across Six Networks

Attackers stole funds from six blockchain networks between August 20 and August 25 by exploiting a critical vulnerability in Cosmos EVM, according to a technical post-mortem published Friday by Cosmos Labs.

Cosmos EVM is shared software that enables Cosmos-based blockchains to support Ethereum-compatible applications.

The attackers converted stolen tokens into approximately $2.87 million in assets through decentralized exchanges and another $2.85 million through centralized exchanges. Accounts used by the attackers on centralized platforms have since been frozen while relevant authorities investigate the incident, Cosmos Labs said.

The security breach affected Cosmos EVM versions released before v0.6.2 and v0.7.2. The project’s advisory assigns the vulnerability a critical severity rating.

Cosmos Labs disclosed that a security researcher first identified the vulnerability and submitted it through the project’s bug bounty program on April 25.

After receiving the report, the company attempted to reproduce the exploit using the configurations deployed by live Cosmos chains. Its testers were unable to trigger the attack across the known production Cosmos EVM networks and consequently concluded that user funds were not at risk.

Based on that assessment, Cosmos Labs addressed the issue through its silent public patching process. That method allows the company to merge security fixes without explaining the vulnerability to downstream chain operators.

A separate private distribution process is used when Cosmos Labs believes a security issue threatens funds on live networks.

The company said it has silently patched 37 vulnerabilities over the past 13 months.

The exploit relied on an integer-underflow bug that allowed an attacker to make a wallet appear to hold a virtually unlimited number of tokens.

First, the attacker created an account containing locked tokens. The account then delegated more tokens to a validator than it was permitted to spend.

When the blockchain subtracted the delegated amount, the wallet’s balance fell below zero. Because the system represented balances as unsigned integers, the value wrapped around to the maximum possible figure: 2256−12^{256}-1 base units.

That is a 78-digit number. The attacker then transferred the inflated balance to a targeted account holding a large quantity of tokens. This caused the target’s balance to exceed the same numerical limit, producing an overflow that wrapped its value back down.

The result left the attacker in possession of the target’s legitimate tokens while reducing the target’s balance to zero.

No new tokens were created through the process, and the networks’ total token supplies remained effectively unchanged. MANTRA said the exploit altered its total supply calculation by only one base unit, the smallest divisible amount of its token.

The targeted accounts included large burn addresses and multisignature wallets established during blockchain launches.

Patch Arrived 20 Hours Before the First Attack

Cosmos Labs merged an initial fix in May while still operating under the assumption that live networks were unaffected.

That assessment changed in early August, when independent researchers established that all Cosmos EVM chains could be vulnerable.

Cosmos Labs said it subsequently obscured the patch to make it more difficult for outside parties to reverse-engineer the flaw. Updated versions were released at 7:01 p.m. Eastern Time on August 19.

However, the release notes referred only to “important” security fixes and did not explain the vulnerability or warn chain operators that funds could be at risk.

The first attack began at 3:06 p.m. on August 20, around 20 hours after the patched versions became available.

MANTRA argued that the time between the release and the attack was insufficient for its validator network to complete a major upgrade.

“Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory,” MANTRA said in its post-mortem.

The network has formally raised the delay with Cosmos maintainers and called for clearer disclosure procedures and better-defined expectations for backporting security fixes.

Cosmos Labs identified a public code submission by a Push Chain developer as another factor contributing to the incident.

At 3:16 a.m. on August 20, approximately 12 hours before the first theft, the developer submitted a public code change describing the vulnerability and how it could be exploited. The submission credited an audit by security company Hacken and listed affected Cosmos EVM versions.

Although the report stated that no released version contained a fix, its version table omitted v0.6.2 and v0.7.2, which had been published roughly eight hours earlier.

Cosmos Labs described the public disclosure of a precise exploitation path by a downstream developer as highly unusual, noting that such disclosures can increase the likelihood of an attack.

MANTRA said the public finding appeared 11 hours and 45 minutes before the attacker’s first probe. However, the attacker’s wallet had been funded almost four hours before the filing.

The network emphasized that it was only presenting the timeline and was not drawing a conclusion about the relationship between those events.

According to MANTRA, a withdrawal of 472.70 MANTRA tokens from a centralized exchange customer account funded the gas fees for the entire attack.

MANTRA Loses 720.9 Million Tokens

MANTRA was among the largest disclosed victims of the exploit. The attacker drained approximately 720.9 million MANTRA tokens, then valued at around $3.6 million, from two addresses. 

One was the network’s burn address, while the other was a dormant multisignature wallet associated with a previous incentive campaign.

MANTRA’s monitoring system did not flag the initial transaction because the burn address was considered immovable and was therefore excluded from transfer monitoring.

The theft remained undetected for nearly four hours, giving the attacker time to drain the dormant multisignature wallet.

MANTRA halted its blockchain at 7:13 p.m. on August 20 and resumed operations slightly more than 30 hours later after deploying the patched software. The network did not roll back transactions.

The halt froze approximately 38 million MANTRA tokens in the attacker’s wallet. However, the attacker had already sent the remaining 94.7% of the stolen tokens to a single exchange deposit address through 15 transfers.

MANTRA said no tokens had been recovered as of August 28.

The attack also increased MANTRA’s reported circulating supply by approximately 720.9 million tokens. The stolen balances had previously been excluded from circulating-supply calculations because they were considered unspendable, but the exploit made them tradable.

TAC and KiiChain Report Major Losses

TAC, a network designed to bring decentralized finance applications to users of TON and Telegram, was attacked on August 22.

The attacker removed almost 3 billion TAC tokens from the network’s staking pool. Around 1.2 billion were subsequently sold on BNB Chain for approximately $950,000.

KiiChain, a blockchain focused on foreign exchange infrastructure, was targeted later the same day. The attacker stole roughly 148 million KII tokens and sold 64.6 million of them for approximately $1.6 million.

Cosmos Labs estimates that around 54% of the stolen KII remains recoverable onchain if the network is restored.

Three additional networks were attacked using the same technique, although Cosmos Labs did not identify them publicly.

One of the unnamed networks may be Nesa, an AI-focused blockchain. Crypto exchange Bitvavo suspended NES deposits and withdrawals on August 24 after what it called a critical consensus vulnerability caused some nodes to accept invalid blocks.

Blockchain analytics company Bubblemaps subsequently identified Nesa as one of the networks affected by the Cosmos EVM flaw.

According to Bubblemaps, the attacker purchased approximately $250,000 worth of NES, bridged the tokens to Nesa, and exploited the vulnerability to inflate the balance by 200 times. The attacker then moved $50 million in NES back to Ethereum.

Most of the attempted swaps reportedly suffered extreme slippage after liquidity was removed from trading pools. Bubblemaps estimated that the attacker ultimately made only around $60,000 in profit.

The analytics firm said the wallet was initially funded through Monero. It also noted that the Nesa attacker’s funding and behavior differed substantially from those involved in the earlier attacks, suggesting a separate party may have been responsible.

Cosmos Labs did not name Nesa in its report, and Nesa has yet to publish a post-mortem.

The two remaining affected networks have not been publicly identified.

Cosmos Labs Discovers Previously Unknown Deployments

Cosmos Labs said it coordinated with 40 chains during the emergency response and worked with another 13 networks to patch the vulnerability or halt operations before they could be attacked.

The incident also exposed shortcomings in tracking deployments across the Cosmos ecosystem.

Cosmos Labs does not maintain a complete registry of the more than 115 public blockchains operating within the broader ecosystem. During the response, it discovered 11 Cosmos EVM deployments that had not previously been registered.

The absence of a comprehensive registry complicated efforts to warn operators, coordinate patches, and determine which networks remained exposed.

 

Bybit Launches Tokenized SpaceX IPO Access Product Ahead of Planned Nasdaq Debut
Next article Bybit Launches Tokenized SpaceX IPO Access Product Ahead of Planned Nasdaq Debut
Hassan Maishera
Hassan Maishera Senior Reporter

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.