Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Cosmos Labs discloses critical bug behind $5.7 million six-chain hack
00

Cosmos Labs discloses critical bug behind $5.7 million six-chain hack

Aug 28, 2026

Cosmos Labs disclosed that a critical integer underflow vulnerability in Cosmos EVM led to a $5.7 million exploit across six blockchain networks, including MANTRA, TAC, and KiiChain, between August 20 and August 25, 2026. Cosmos Labs had misjudged an initial bug report submitted on April 25, 2026, wrongly concluding that live production networks were safe. This misassessment led to a silent patching process that delayed critical upgrades, drawing sharp criticism from affected chains like KiiChain and MANTRA over communication failures.

Cosmos EVM integer underflow exploit

  • ▪The Cosmos EVM vulnerability allowed attackers to overflow a target account's balance and extract its legitimate tokens without changing the total token supply
  • ▪Attackers exploited a critical integer underflow vulnerability in Cosmos EVM to trick networks into crediting attacking wallets with up to 2^256-1 base units
  • ▪The Cosmos EVM vulnerability affected releases before v0.6.2 and v0.7.2 of the native EVM framework built from the open-source Evmos codebase

April vulnerability report misassessment

  • ▪Cosmos Labs wrongly concluded live networks were safe because testers believed the vulnerability only affected six-decimal networks, whereas production chains used 18 decimals
  • ▪Cosmos Labs merged a silent public patch on May 15, 2026, but did not immediately backport it because the state-breaking change required coordinated upgrades

Silent patch process delay

  • ▪Cosmos Labs released patched versions v0.6.2 and v0.7.2 at 7:01 p.m. ET on August 19, 2026, after research established the bug affected all Cosmos EVM chains
  • ▪Attackers stole approximately $5.7 million across six blockchain networks between August 20 and August 25, 2026, using the Cosmos EVM vulnerability
  • ▪A Push Chain developer published a public code change describing the exact exploit path at 3:16 a.m. ET on August 20, 2026, crediting security firm Hacken

Six-chain attack execution August

  • ▪TAC lost nearly 3 billion TAC from its staking pool on August 22, 2026, subsequently selling 1.2 billion tokens on BNB Chain for around $950,000
  • ▪MANTRA lost 720.9 million MANTRA tokens worth approximately $3.6 million on August 20, 2026, from its immovable burn address and a legacy multisig wallet
  • ▪KiiChain lost 148 million KII on August 22, 2026, with 64.6 million tokens sold for $1.6 million and 54% remaining recoverable onchain
  • ▪KiiChain complained that Cosmos Labs gave no advance notice of the patch and only recommended halting on August 22, 2026, after multiple chains were hit

MANTRA burn address drainage

  • ▪Attackers exchanged stolen tokens for $2.87 million on decentralized exchanges and $2.85 million on centralized exchanges, where connected accounts have been frozen
  • ▪MANTRA's monitoring systems failed to alert on the first attack transaction because the system did not cover transfers from the supposedly immovable burn address
  • ▪MANTRA halted its chain at 7:13 p.m. ET on August 20, 2026, freezing 38 million MANTRA tokens in the attacker's wallet during a 30-hour outage

2 sources

CryptoSlate
Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains
View source article
The Block
Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack
View source article

Story comments

Loading comments…

Related entities

Blockchain Security

Related Projects

Cosmos LabsCosmos

Topics

Blockchain interoperabilityCryptoSmart contractsCrypto hacks