Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Cosmos EVM vulnerability exploited across six blockchains after four-month delay, draining nearly $6 million
00

Cosmos EVM vulnerability exploited across six blockchains after four-month delay, draining nearly $6 million

Aug 28, 2026

Between August 20 and August 25, 2026, attackers exploited a critical balance-handling vulnerability in the Cosmos EVM module to drain nearly $6 million across six blockchains, including MANTRA, TAC, and KiiChain. Cosmos Labs had received a report on the flaw on April 25 but misjudged its severity for four months, believing 18-decimal production networks were safe. The exploit triggered an integer underflow in vesting accounts, wrapping balances to 2^256. MANTRA suffered the largest hit, losing 720.9 million tokens valued at $3.6 million.

Cosmos EVM vulnerability exploitation

  • ▪Attackers sold approximately $2.87 million in affected assets on decentralized exchanges and an estimated $2.85 million on centralized exchanges following the Cosmos EVM exploits.
  • ▪A critical balance-handling vulnerability in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026.

Delayed security assessment process

  • ▪Cosmos Labs confirmed by August 13, 2026, that all Cosmos EVM chains were vulnerable regardless of their decimal configuration.
  • ▪Cosmos Labs received the initial report about the Cosmos EVM vulnerability on April 25, 2026, through its bug bounty program.
  • ▪Cosmos Labs initially misjudged the vulnerability as posing no risk to live networks, incorrectly concluding it only affected non-18-decimal networks rather than all Cosmos EVM chains.

Balance reconciliation technical flaw

  • ▪Exploitation of the Cosmos EVM vulnerability requires that the target blockchain permits permissionless vesting-account creation.
  • ▪When a vesting account delegates more than its spendable balance, an unchecked subtraction causes the balance to underflow and wrap to approximately 2^256.
  • ▪The Cosmos EVM vulnerability, designated GHSA-7g4w-cg88-2cq2, lies in the code reconciling the Ethereum Virtual Machine state with the Cosmos SDK x/bank module.

Six blockchain impact

  • ▪The Cosmos EVM vulnerability exposed a security gap spanning around 40 blockchains within the broader Cosmos ecosystem.
  • ▪Cosmos Labs contacted 40 networks during the incident, and 13 other potentially exposed chains patched, halted, or applied mitigations before being exploited.
  • ▪The six blockchains exploited during the Cosmos EVM incident included MANTRA, TAC, and KiiChain.

Emergency patch distribution

  • ▪A public pull request in Push Chain's fork of Cosmos EVM described the vulnerability and exploitation path in detail at 07:16 UTC on August 20, 2026.
  • ▪Cosmos Labs released patched versions v0.6.2 and v0.7.2 late on August 19, 2026, to resolve the critical EVM vulnerability.
  • ▪The emergency response uncovered 11 Cosmos EVM deployments that had never registered with Cosmos Labs' security-communication channels.

MANTRA chain largest loss

  • ▪The attacker on MANTRA moved 600 million tokens from a burn address and 120.9 million tokens from a legacy genesis-era multisig.
  • ▪MANTRA suffered the largest publicly detailed hit, with an attacker moving approximately 720.9 million tokens valued at $3.6 million.
  • ▪MANTRA's monitoring failed to flag the first unauthorized transaction for almost four hours because it treated the burn address as incapable of moving funds.

2 sources

Cryptoslate
Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains
View source article
Thehackernews
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
View source article

Story comments

Loading comments…

Related Projects

Cosmos Labs

Topics

Blockchain interoperabilityBlockchain governanceEthereum Virtual Machine (EVM)Smart contract vulnerabilities