Between August 20 and August 25, 2026, attackers exploited a critical balance-handling vulnerability in the Cosmos EVM module to drain nearly $6 million across six blockchains, including MANTRA, TAC, and KiiChain. Cosmos Labs had received a report on the flaw on April 25 but misjudged its severity for four months, believing 18-decimal production networks were safe. The exploit triggered an integer underflow in vesting accounts, wrapping balances to 2^256. MANTRA suffered the largest hit, losing 720.9 million tokens valued at $3.6 million.
Story comments
Loading comments…