How Did The Cosmos EVM Exploit Work?
Attackers exploited a critical flaw in shared Cosmos software across six blockchains between Aug. 20 and Aug. 25, converting stolen tokens into about $5.7 million of other assets and exposing weaknesses in how security fixes were communicated to networks using Cosmos EVM.
Cosmos Labs said approximately $2.87 million of the proceeds were exchanged through decentralized exchanges and another $2.85 million through centralized exchanges. Accounts linked to the attackers at centralized exchanges have since been frozen pending investigations by authorities.
The vulnerability was an integer underflow in Cosmos EVM, the framework that allows Cosmos-based blockchains to run Ethereum-compatible applications. It affected Cosmos EVM versions before v0.6.2 and v0.7.2.
The exploit involved creating an account with locked tokens and delegating more tokens than the account could actually spend. Instead of rejecting the transaction, the software allowed the balance calculation to fall below zero and wrap around to approximately 2^256-1 base units, effectively producing an enormous balance inside the accounting system.
The attacker could then use the inflated balance to manipulate another account and extract its tokens. No new tokens were actually minted, meaning the attack exploited accounting logic rather than directly increasing the underlying token supply.
Why Was The Vulnerability Not Fixed Earlier?
The most important issue may be the disclosure timeline. A researcher originally reported the vulnerability through the Cosmos bug bounty program on April 25. Cosmos Labs attempted to reproduce the attack against configurations used by production networks but concluded that live chains were not vulnerable.
A fix was merged into the main Cosmos EVM codebase in May through what Cosmos Labs calls its silent public patch process. The change was not immediately added to production release branches because it required a state-breaking upgrade that chain operators would need to coordinate with validators.
Independent researchers provided additional information in early August that allowed Cosmos Labs to determine that all Cosmos EVM chains were vulnerable. The fix was then backported and released in versions v0.6.2 and v0.7.2 at 11:01 p.m. UTC on Aug. 19.
The first known attack against MANTRA began approximately 20 hours later.
“Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory,” MANTRA said in its post-mortem.
Investor Takeaway
The financial loss is relatively contained compared with major crypto exploits, but the incident exposes a larger infrastructure risk: dozens of independent blockchains can inherit the same vulnerability from shared software while relying on separate validator groups to deploy emergency upgrades.
Which Cosmos Chains Were Hit?
MANTRA suffered the largest publicly disclosed loss. Attackers moved about 720.9 million MANTRA, valued at roughly $3.6 million before the incident, from the network’s burn address and a dormant multisignature wallet associated with an earlier incentive campaign.
The network halted approximately four hours after the first unauthorized transfer and resumed more than 30 hours later using patched software without rolling back the blockchain. About 38 million MANTRA remained trapped in the attacker’s wallet, while most of the stolen tokens had already been transferred to a centralized exchange deposit address.
TAC was attacked on Aug. 22, losing nearly 3 billion TAC from its staking pool. About 1.2 billion tokens were later sold for approximately $950,000. KiiChain was attacked the same evening, losing about 148 million KII, with 64.6 million tokens sold for roughly $1.6 million.
Cosmos Labs said three additional chains were exploited but did not identify them. Nesa may have been among those affected after a critical vulnerability was reportedly used to inflate a token balance and move large quantities of NES to Ethereum, although Cosmos Labs has not publicly confirmed that connection.
What Failed In The Security Response?
The affected networks have focused criticism on the gap between identifying the danger and warning operators clearly enough to act.
KiiChain said chains were not initially told that the release contained a critical security fix or that halting networks might be necessary. “A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes,” the chain said in its post-mortem.
Cosmos Labs also said a downstream developer publicly described the vulnerability and its exploitation path roughly 12 hours before the first attack. The attacker’s MANTRA wallet, however, had been funded several hours before that disclosure, and MANTRA said it was drawing no conclusion from the timing.
Cosmos Labs ultimately coordinated with 40 chains during the response and worked with another 13 to patch, halt or otherwise protect their networks before they were attacked. The firm also discovered 11 previously unregistered Cosmos EVM deployments during the incident, illustrating the difficulty of reaching every project using open-source infrastructure.
The immediate vulnerability has been patched, but the episode leaves Cosmos Labs with a broader security coordination problem. Future protection will depend not only on finding software flaws but also on identifying every exposed chain and giving validators enough information and time to respond before attackers do.







