Cosmos EVM bug exploited in cross-chain attacks, $5.7M siphoned from multiple networks Cosmos Labs has confirmed a severe vulnerability in Cosmos EVM — the Ethereum-compatible framework derived from Evmos — was exploited across at least six blockchains between Aug. 20 and Aug. 25. Attackers converted stolen tokens into roughly $5.72 million through a mix of decentralized and centralized exchanges, according to the firm’s technical post‑mortem. What happened (timeline) - April 25: Cosmos Labs’ bug-bounty program receives the initial report. Testers were unable to reproduce the issue against known production configurations and concluded live funds were not at risk. - May: Developers merged a silent fix into the codebase rather than issuing a targeted, vulnerability‑specific advisory to downstream network operators. - Early August: Independent researchers demonstrate the bug can affect production Cosmos EVM chains. - Aug. 19, 7:01 p.m. ET: Cosmos Labs publishes patched releases (notes call them “important” security fixes but do not describe the vulnerability). - Aug. 20, 3:06 p.m. ET: First known attack begins roughly 20 hours after the patched software becomes available. - Aug. 20–25: Multiple networks are drained; attackers convert proceeds across exchanges. The bug, explained simply The root issue was an integer underflow in Cosmos EVM. In essence: - An attacker could set up an account with locked tokens and delegate more tokens to a validator than the account could legally spend. - Subtracting the delegated amount caused the account balance to underflow and wrap to the maximum 2^256‑1 base units. - The attacker then used the artificially inflated balance to push another account’s balance past that same numerical ceiling; the overflow wrapped the victim’s balance down while leaving the attacker in control of the target’s tokens. Cosmos Labs stresses that this manipulation didn’t mint new tokens in the economic sense — total supply remained effectively unchanged — with MANTRA noting the supply changed by only a single base unit. Networks and losses - MANTRA: Largest public loss — 720.9 million MANTRA (about $3.6M) were taken from two addresses: the network’s burn address and a dormant multisignature wallet. A small withdrawal (472.70 MANTRA) from a centralized exchange funded attack gas. No automated alert was triggered for the burn address because it was treated as immovable; the exploit went undetected for nearly four hours. MANTRA halted its chain on Aug. 20 at 7:13 p.m. ET, froze some funds, deployed patched software (v8.4.0) and resumed without a chain rollback. As of Aug. 28, no stolen MANTRA had been recovered and circulating supply rose by about 720.9M because previously “unspendable” addresses were emptied. - TAC: Attacked Aug. 22; nearly 3 billion TAC were taken from the staking pool. About 1.2 billion were sold on BNB Chain for roughly $950,000. - KiiChain: Lost ~148 million KII on Aug. 22; about 64.6 million KII were sold for ~ $1.6M. Cosmos Labs estimates ~54% of the stolen KII could be recoverable on‑chain if the network is restored. - Additional chains: Cosmos Labs says three more chains were hit by the same method but did not identify them all publicly. Blockchain analytics firm Bubblemaps highlighted Nesa as likely affected: an attacker allegedly bought ~$250K NES, bridged to Nesa, inflated balances ~200x, and moved roughly $50M back to Ethereum, but due to slippage the attacker’s profit may have been as little as ~$60K. Bitvavo suspended NES deposits and withdrawals after the incident. Where communication and process broke down - Silent patching: After initial testing in April suggested production chains weren’t vulnerable, Cosmos Labs merged a fix in May without notifying network operators about the specific vulnerability. That decision proved problematic when independent researchers later showed production chains were affected. - Limited advance notice: Cosmos Labs released patched binaries on Aug. 19 without a vulnerability‑specific advisory. A downstream developer (Push Chain) publicly submitted a code change on Aug. 20 that described the vulnerability and exploitation path, an action Cosmos Labs called “highly unusual” because it can raise exploit risk. - Timing concerns from downstream projects: MANTRA said the 20‑hour window between patch availability and the first attack was insufficient to coordinate a state‑breaking upgrade across its 38 independent validators. KiiChain criticized the lack of clear instructions to halt block production and disputed parts of Cosmos Labs’ technical assessment, arguing multiple upstream defects were needed and only one was initially patched. Cosmos Labs maintains the underflow was a critical component of the exploit and described two chained vulnerabilities in its report. Cosmos Labs’ response and scope - Cosmos Labs coordinated with roughly 40 networks and worked with 13 others to patch or halt. The team discovered 11 Cosmos EVM deployments that had not previously been registered with them. - Vulnerable releases were identified as any Cosmos EVM versions before v0.6.2 and v0.7.2. - The firm does not maintain a complete registry of the more than 115 public Cosmos ecosystem chains, complicating proactive communication. Aftermath and broader context - Between Aug. 20–25 attackers moved and converted stolen assets, netting about $5.72M through swaps and exchange deposits. - The incident follows other Cosmos ecosystem disclosures earlier in the year (e.g., a CometBFT synchronization bug disclosed in April). - MANTRA is undergoing an acquisition by Inveniam Capital Partners (which invested $20M in Aug. 2025). The deal is expected to close in Q3 2026; MANTRA Chain and its token are slated to continue operating under Inveniam. Key takeaways for the ecosystem - Silent or non‑specific patches increase risk: downstream chains that don’t receive vulnerability‑specific advisories may lack time or information to coordinate urgent, state‑critical upgrades or halts. - Monitoring assumptions can be dangerous: treating burn addresses or dormant multisigs as immutable may allow large illicit moves to go unnoticed. - The rapidly composable, multi-chain nature of Cosmos EVM deployments magnifies the consequences of upstream defects; maintaining an accurate registry and faster, clearer disclosure channels is critical. Cosmos Labs continues to investigate and coordinate mitigations with affected networks. Several projects involved have published their own post‑mortems and are engaged with exchanges and analytics teams to trace and, where possible, freeze stolen funds. Read more AI-generated news on: undefined/news