Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Cosmos EVM Vulnerability Exploited Across Six Networks, Nearly $6 Million Stolen

A critical accounting flaw in Cosmos EVM software went unrecognized for four months before attackers stole approximately $5.72 million across six blockchain networks, including MANTRA, TAC, and KiiChain.
1 week ago 26 views
Cosmos EVM Vulnerability Exploited Across Six Networks, Nearly $6 Million Stolen

A vulnerability in Cosmos EVM software was exploited across six networks on August 28, resulting in losses totaling approximately $5.72 million. Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues, according to a Cosmos security postmortem. Accounts connected to centralized-exchange activity have since been frozen.

The flaw affected the Cosmos/EVM ecosystem, a shared software layer that provides Ethereum-compatible functionality to Cosmos SDK chains. After the attacks began, Cosmos Labs contacted 40 networks across the broader ecosystem. Thirteen other potentially exposed chains patched, halted, or applied mitigations before exploitation, while the response also uncovered 11 previously unknown Cosmos EVM deployments.

Initial Misassessment Delayed Response

Cosmos Labs received the initial vulnerability report on April 25 but concluded that the flaw affected only six-decimal networks, while production Cosmos EVM chains used 18 decimals. Based on this assessment, the firm addressed the vulnerability through a silent public patch process rather than emergency procedures. A fix was merged into the main codebase on May 15 but was not immediately backported to older branches due to state-breaking changes requiring coordinated upgrades.

In early August, further research revealed that Cosmos EVM deployments were vulnerable regardless of decimal configuration. Patched releases arrived late on August 19. Less than 12 hours after a public pull request described the vulnerability and exploitation path, MANTRA recorded its first unauthorized transaction.

MANTRA Suffered Largest Impact

MANTRA experienced the largest publicly disclosed attack. An unprivileged wallet moved approximately 720.9 million tokens from two addresses without authorization on August 20, without compromising validator, administrator, governance, or multisig keys. The attacker accessed roughly 600 million tokens from a burn address and 120.9 million from a legacy genesis-era multisig, increasing circulating supply but minting no new tokens.

MANTRA's monitoring failed to flag the first transaction for nearly four hours because it treated the burn address as incapable of moving funds. The chain halted 14 minutes after a second unauthorized transaction, resulting in an outage of approximately 30 hours. As of August 28, no tokens had been recovered, though about 38 million remained immobilized in the attacker account and the remainder had been traced through exchange routes.

TAC reported exploitation roughly 45 hours after MANTRA, with KiiChain following shortly afterward. Cosmos Labs subsequently recommended that all Cosmos EVM chains halt and upgrade.

Technical Details and Response

The vulnerability combined two accounting failures. An attacker could trigger an unsigned-integer underflow that created an abnormally large balance, then use that state to overflow another account and extract its legitimate balance without increasing total token supply.

The incident has prompted Cosmos Labs to revise its vulnerability triage and disclosure procedures after a flaw initially assessed as unlikely to threaten production chains ultimately affected six networks and forced emergency action across dozens more.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $78,523.00-0.85% EthereumETH $2,483.18-0.39% Tether USDUSDT $0.99990.00% BNBBNB $752.12+1.68% XRPXRP $1.42+1.66% USDCUSDC $1.0000-0.01% SolanaSOL $103.07-0.82% TRONTRX $0.3382+1.05% HyperliquidHYPE $84.41-1.06% ZcashZEC $1,167.22+1.15%
Prices by Coinranking. Informational only.