Cosmos Labs has admitted that it underestimated the severity of a vulnerability in the Cosmos EVM module. This oversight led to attacks on six different blockchains, resulting in total losses amounting to $5.7 million.
Between August 20th and August 25th, attackers exploited a vulnerability in Cosmos EVM to extract funds from multiple Cosmos-based blockchains. We are committed to strengthening the systems and processes we rely on for security and are grateful for the collaboration of the…
— Cosmos Labs (@cosmoslabs_io) August 28, 2026
The issue was first reported on April 25, 2026, through a bug bounty program. After conducting tests, the team concluded that production networks were not at risk and released a public fix without notifying operators separately. In early August, independent researchers revealed that the vulnerability affected all networks using Cosmos EVM. Consequently, developers disguised the patch and included it in releases v0.6.2 and v0.7.2, which were published on the evening of August 19. The first known attack occurred approximately 20 hours later.
In its post-mortem report, Cosmos Labs described the attack as a combination of underflow and subsequent overflow. Through a specially crafted vesting account and a malicious contract, the attacker manipulated balance calculations and then transferred funds from addresses with large balances. The company asserts that no new tokens were created and that the total supply remained unchanged.
The largest confirmed loss was incurred by MANTRA. According to the network's analysis, 720.9 million MANTRA tokens were withdrawn from a burn address and an old multi-signature wallet, amounting to about $3.6 million. The network was halted on August 20, 2026, and resumed over 30 hours later without a state rollback. MANTRA stated that no customer accounts were affected, but tokens that were previously considered economically inactive entered circulation.
Cosmos Labs estimated the losses for TAC at 2.99 billion TAC tokens, of which approximately 1.21 billion were sold on the BNB Chain for about $950,000.
KiiChain experienced a loss of around 148.3 million KII tokens. The company estimates that 64.6 million tokens were sold for about $1.6 million, while around 54.4% of the stolen tokens remained in the network and could potentially be recovered after restoration.
Three other affected networks were not named by Cosmos Labs.
Both MANTRA and KiiChain criticized the disclosure process regarding the vulnerability. The team from MANTRA stated that 20 hours was insufficient for assessing, gathering, testing, and coordinating updates among 38 validators without prior notification of the vulnerability. KiiChain pointed out that the recommendation to halt networks came only after attacks on three blockchains had occurred.
In response, Cosmos Labs indicated that it had coordinated with 40 networks and had identified 11 unregistered deployments of Cosmos EVM within an ecosystem of over 115 public blockchains.
For context, from January 2025 to July 2026, cryptocurrency platforms lost $3.63 billion in 245 documented incidents, according to CoinGecko data.
