Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains
A Cosmos EVM vulnerability exploited across six networks, including MANTRA, exposed a security gap spanning around 40 blockchains.
On Aug. 28, Cosmos Labs said the same accounting flaw was exploited on six networks, including MANTRA, TAC, and KiiChain, before an emergency response spread across the broader Cosmos EVM ecosystem.
Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues, according to a Cosmos security postmortem. Accounts connected to the centralized-exchange activity have since been frozen.
MANTRA suffered the largest publicly detailed hit. An unprivileged wallet moved about 720.9 million tokens from two addresses that had not authorized the Aug. 20 transactions, without compromising validator, administrator, governance, or multisig keys.
The vulnerability affected the broader Cosmos/EVM ecosystem, which is a shared software layer that gives Cosmos SDK chains Ethereum-compatible functionality. After the attacks began, Cosmos Labs contacted 40 networks and said 13 other potentially exposed chains patched, halted, or applied mitigations before they were exploited.
The response also uncovered 11 Cosmos EVM deployments that Cosmos Labs had not previously known about through its security-communication channels.
That potential reach sits within a broader Cosmos ecosystem valued at more than $7 billion, according to CryptoSlate's data. Meanwhile, this figure includes projects that might not have used the vulnerable software and does not represent the amount directly exposed.
Cosmos initially underestimated the vulnerability
Cosmos Labs revealed that the flaw had been reported months before attackers exploited it.
The firm said it received the initial report about the vulnerability on April 25 but concluded after testing that the vulnerability affected six-decimal networks, while known production Cosmos EVM chains used 18 decimals. Engineers therefore believed deployed networks were not at risk.
According to the firm:
"Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds."
A fix was merged into the main codebase on May 15 and handled as a silent public patch rather than an emergency security release. At the same time, it was not immediately backported to older branches because the change was state-breaking and required coordinated upgrades.
That assessment changed in early August when further research showed Cosmos EVM deployments were vulnerable regardless of their decimal configuration.
Patched v0.6.2 and v0.7.2 releases arrived late on Aug. 19. The next morning, a public pull request in another project's fork described the vulnerability and exploitation path. MANTRA's first known unauthorized transaction followed less than 12 hours later.
The flaw combined two accounting failures. An attacker could trigger an unsigned-integer underflow that created an abnormally large balance, then use that state to overflow another account and extract its legitimate balance without increasing total token supply.
TAC reported exploitation roughly 45 hours after MANTRA, with KiiChain following soon afterward. Cosmos Labs subsequently recommended that Cosmos EVM chains halt and upgrade while it coordinated the broader response.
MANTRA absorbed the biggest disclosed hit
On MANTRA, the attacker moved roughly 600 million tokens from a burn address and another 120.9 million from a legacy genesis-era multisig.
No new tokens were minted. Instead, previously inert balances became transferable, increasing circulating supply by about 720.9 million MANTRA.
The project valued the movement at roughly $3.6 million using the pre-incident price. As of Aug. 28, no tokens had been recovered. About 38 million remained immobilized in the attacker account, while the remainder had been traced through exchange routes and referred to platforms and law enforcement.
MANTRA also acknowledged that its monitoring failed to flag the first transaction for almost four hours because it treated the burn address as incapable of moving funds. The chain halted 14 minutes after a second unauthorized debit, resulting in an outage of about 30 hours.
MANTRA fell to an all-time low following the attack before rebounding about 14% to roughly $0.004744 after the postmortem.
The wider fallout has pushed Cosmos Labs to revise its vulnerability triage and disclosure procedures after a flaw initially judged unlikely to threaten production chains ultimately reached six networks and forced emergency action across dozens more.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

FTX and AI Apocalypse: The End of Calm Times for Anthropic

What is CBDC? Governments Push for Development of Central Bank Digital Currencies

Bitcoin Has Not Fallen Below Realized Price During the Bear Market

The Clearing House Selects Quant for US Tokenized Deposit Network

4500 Bitcoins Moved to New Addresses, Sale Status Unconfirmed
![[New York Gold, Bonds, Dollar] Interest Rates and Dollar Strength Pause... Oil Prices Drop, Won and Gold Prices Rebound](/public-static/29_4631d65680.png?format=avif)
[New York Gold, Bonds, Dollar] Interest Rates and Dollar Strength Pause... Oil Prices Drop, Won and Gold Prices Rebound

Trump Expresses Concern Over Yen Depreciation, Japanese Finance Minister Says Coordination with U.S. Will Continue

Treasuries at 21-Year High: Impact on Stocks and Interest Rates

Solana DEX volume spike hides circular trades, and automated bots are blamed

Oracle Stock vs. KRAFTON Stock: Why Are Investors Questioning Two Growing Companies?
Compare Oracle and KRAFTON stocks through their latest results, share-price questions and the different growth tests investors face in 2026.

John Templeton: "Bull markets are born in pessimism"

The Death of Hsin-Ju: A Prelude to Conspiracy

LTC Airdrop 2026: How to Claim 50,000 USDT Rewards on WEEX

Raiffeisen’s crypto deal could reach 18 million customers. How many can actually trade?

TRON Surpasses $30T in Total Transaction Volume as it Secures its Place as Leading Chain for Stablecoins

HTX DeepThink: Opportunities Concentrate on Profitable and Fund-Supported Assets, BTC Still Has Room for Recovery After Consolidation
Why Did Sui (SUI) Crypto Price Jump 44%? Crypto OI and Leverage Explain the Rally
See why Sui (SUI) jumped 44%, how crypto OI and leverage amplified the rally, what the pullback means, and how to trade SUI on WEEX.

Circle expands CCTP to EURC and cirBTC on Arc

Bitcoin, Sports, and Politics: Predictive Markets Target $10 Trillion

AI Agent Jev Expects On-Chain Innovation Through Automated Judgment

The End of the Blank Prompt: Why Trading AI Needs a Playbook

Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.

CFTC's Selig Emphasizes the Need to Prepare for the Era of Large-Scale Tokenization in the U.S.

The IMF opens an office in Venezuela to supervise an economy that has already migrated to USDT

SOXL Stock Jumped 12% Yesterday: Three Companies Explain the Entire Move

Bitcoin's Hashrate Rises as Miners Reactivate Their Machines

Bitcoin 2x Leveraged ETF Launches on Cboe, But Doesn't Buy Bitcoin: Here's Why

Crypto: The ECB Enters the Tokenized Bond Market
WEEX Bitcoin Weekly Outlook: Why Did Bitcoin Rebound Above $80,000 After the CLARITY Act Vote?
Bitcoin rebounded above $80,000 as SEC and CFTC action, renewed ETF inflows, and a short squeeze outweighed the failed CLARITY Act vote.






