A vulnerability in Cosmos EVM, software used by Cosmos-based blockchains to run Ethereum-compatible applications, was exploited across six networks between Aug. 20 and Aug. 25, allowing attackers to sell roughly $5.7 million in stolen tokens, Cosmos Labs said in a technical post-mortem published Friday.
The incident exposed the risks facing chains that rely on common infrastructure but operate independently. Cosmos Labs had issued a “silent patch” for the flaw on Aug. 19, withholding technical details to make reverse engineering harder. The first attack began about 20 hours later, before several affected networks had identified the release as an urgent security upgrade or had time to coordinate validator-approved software changes.
Cosmos Labs said the attackers converted about $2.87 million of assets through decentralized venues and another $2.85 million through centralized venues. The company said centralized accounts linked to the activity had been frozen while authorities investigate.
The flaw affected Cosmos EVM versions before v0.6.2 and v0.7.2, which Cosmos Labs rated as critical in its advisory. The software is used by chains that want Ethereum-style smart contracts while retaining Cosmos’ modular blockchain framework.
An arithmetic flaw targeted dormant large balances
The exploit relied on an integer underflow, a programming error that occurs when a number is reduced below zero. In this case, Cosmos Labs said an attacker could cause a zero balance to wrap around to the maximum possible value for the system: 2^256 minus one base units, a 78-digit figure.
The attacker could then reverse the calculation, pushing another account beyond that ceiling. The resulting overflow wrapped the balance downward, effectively shifting tokens from the target account to the attacker.
Cosmos Labs said the mechanism did not mint new tokens and left total supply effectively unchanged. MANTRA, one of the affected chains, said its own calculations found that the exploit altered its token supply by only one base unit, the smallest unit into which its token can be divided.
Attackers focused on addresses holding large balances that networks had treated as inaccessible, including burn addresses and dormant multisignature wallets. Those accounts may be excluded from circulating-supply calculations or monitoring systems, yet their balances can remain vulnerable if the underlying chain logic permits transfers.
MANTRA said it lost 720.9 million MANTRA tokens, formerly known as OM, valued at about $3.6 million at the time. The funds came from a burn address and an inactive multisig wallet connected to an earlier incentives campaign.
The chain’s first alert did not trigger because its monitoring did not cover transfers from the burn address, which it had considered immovable. MANTRA said the breach remained undetected for nearly four hours, allowing the attacker to drain the second wallet.
MANTRA halted its network at 7:13 p.m. ET on Aug. 20 and resumed operations more than 30 hours later on patched software, without rolling back the blockchain. By the time of the halt, roughly 38 million MANTRA remained in the attacker’s wallet. The attacker had already transferred 94.7% of the stolen tokens to one deposit address in 15 transactions, according to MANTRA.
As of Aug. 28, MANTRA said none of the stolen tokens had been recovered. It also said its reported circulating supply had risen by roughly 720.9 million tokens because the stolen balances had previously been classified as unspendable but had become tradable after the attack.
Patch timing became a point of dispute
Cosmos Labs said the vulnerability was initially reported through its bug bounty program on April 25. Internal testing did not reproduce the issue under the configurations used by live Cosmos EVM chains, leading the team to conclude that production networks were not exposed.
The company merged a fix in May under that assumption. Independent researchers later determined in early August that all Cosmos EVM chains could be affected, Cosmos Labs said. It then used a silent-patch process, publishing the fix without identifying the specific vulnerability in release notes.
Cosmos Labs said it has deployed 37 silent patches over the past 13 months. The approach is intended to give operators time to upgrade before attackers can study a public fix and identify the underlying bug.
MANTRA argued that the compressed timeline made that goal unrealistic for an independent network. Its post-mortem said that 20 hours was insufficient to assess the flaw, prepare a state-breaking upgrade, test the software and coordinate 38 validators, especially without a direct advisory explaining the vulnerability.
KiiChain raised similar concerns in its Aug. 23 post-mortem. The chain said downstream users received no advance warning, the release was not marked as security-critical, and affected networks were not told that a public patch had been released until two days later. KiiChain said Cosmos Labs only recommended that chains halt operations on Aug. 22, after MANTRA, TAC and KiiChain had been attacked.
Cosmos Labs said a public code change filed by a Push Chain developer at 3:16 a.m. ET on Aug. 20 described the vulnerability and a possible exploitation path, citing an audit by Hacken. That filing came hours after the patch release but before the first confirmed attack.
MANTRA said the finding was submitted 11 hours and 45 minutes before the attacker’s first probe. It also said the wallet used in the attack had been funded almost four hours before the public report was filed, while a 472.70 MANTRA withdrawal from a customer account at a centralized venue covered gas costs.
Other chains faced losses and emergency halts
Cosmos Labs said TAC lost nearly 3 billion TAC from its staking pool on Aug. 22. Around 1.2 billion TAC were sold on BNB Chain for approximately $950,000, the company said.
KiiChain lost about 148 million KII during an attack that evening, with 64.6 million KII sold for roughly $1.6 million, according to Cosmos Labs. It said about 54% of the stolen KII remains recoverable onchain if KiiChain’s network is restored.
Three additional Cosmos EVM networks were attacked using the same method, although Cosmos Labs did not name them. Nesa may have been among them. Bitvavo suspended NES deposits and withdrawals on Aug. 24, citing an exploited “critical consensus vulnerability” that caused nodes to accept invalid blocks.
Blockchain analytics platform Bubblemaps said on Aug. 26 that an attacker bought roughly $250,000 worth of NES, bridged it to Nesa, inflated the balance by 200 times and moved $50 million worth of NES back to Ethereum. The resulting sales faced heavy slippage after liquidity was pulled, leaving an estimated $60,000 in profit, Bubblemaps said. It added that the funding and operating patterns differed from the earlier incidents, potentially indicating a separate attacker.
Shared code requires faster coordination
The incident places renewed pressure on software providers and independent chains to define how critical fixes are communicated when a vulnerability affects a shared codebase. A quiet patch can slow opportunistic attackers, but operators unable to identify its urgency may leave networks exposed through the period when attackers are examining the same code changes.
Cosmos Labs said it coordinated with 40 chains during the incident response and helped 13 others patch or halt operations before an attack. The company also said it does not maintain a complete registry for the more than 115 public chains in the broader Cosmos ecosystem, and identified 11 previously unregistered Cosmos EVM deployments during the response.
MANTRA was trading near $0.0043 on Saturday, down about 70% since the start of 2026, according to CoinGecko. The project is also in the process of being acquired by Inveniam Capital Partners in a transaction expected to close this quarter.
After this Cosmos EVM exploit, strengthen your defenses by learning core crypto safety standards every trader should know before your next on-chain move.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
