Crypto news report · source clearly identified

Cosmos EVM Flaw Enables Multi‑Chain Token Drains Worth $5.7 Million

A critical integer‑underflow bug in Cosmos EVM was exploited across six networks between Aug. 20‑25, stealing tokens from MANTRA, TAC and KiiChain and converting them into roughly $5.72 million of assets.

Cosmos Labs disclosed that a critical integer‑underflow vulnerability in its Cosmos EVM framework was exploited on six blockchain networks from Aug. 20 to Aug. 25. Attackers drained large token holdings, converting the stolen assets into about $5.72 million through both decentralized and centralized exchanges.

Vulnerability Details

The flaw, present in Cosmos EVM releases before v0.6.2 and v0.7.2, allowed an attacker to create an account with locked tokens, delegate more tokens than the account could spend, and trigger an underflow that wrapped the balance to the maximum 2^256‑1 value. By sending this inflated balance to a target account, the target’s balance overflowed and wrapped back down, effectively transferring the target’s tokens to the attacker. No new tokens were minted; total supply remained unchanged.

Timeline of Exploitation

  • April 25 – Cosmos Labs received the bug report via its bounty program.
  • May – A silent public patch was merged without notifying network operators.
  • Early Aug. – Independent researchers confirmed the bug affected live Cosmos EVM chains.
  • Aug. 19, 7:01 p.m. ET – Patched Cosmos EVM versions were released, with generic “important security fixes” notes.
  • Aug. 20, 3:06 p.m. ET – First known attack began, roughly 20 hours after the patch became available.

Impacted Networks and Losses

  • MANTRA: 720.9 million tokens (~$3.6 M) stolen from a burn address and a dormant multisig wallet. About 94.7 % of the stolen tokens were moved to a centralized exchange within hours. The chain halted on Aug. 20 and resumed after validators upgraded to v8.4.0.
  • TAC: Approximately 3 billion tokens taken from the staking pool on Aug. 22. Around 1.2 billion were sold on BNB Chain for roughly $950 k.
  • KiiChain (KII): About 148 million tokens lost on Aug. 22‑23. Roughly 64.6 million were sold for $1.6 M; Cosmos Labs estimates ~54 % of the stolen KII could be recovered if the network is restored.
  • Nesa (NES): An additional chain reportedly suffered a similar exploit, with an attacker inflating balances 200‑fold and moving roughly $50 M of NES back to Ethereum, netting about $60 k profit after slippage.

Response and Coordination

Cosmos Labs coordinated with roughly 40 chains during the incident, helping 13 networks apply patches or halt production before further attacks. The patch was released without a vulnerability‑specific advisory, which network operators cited as a major obstacle to timely mitigation. MANTRA, TAC and KiiChain each issued post‑mortems criticizing the lack of advance notice and the short window (≈20 hours) for implementing a state‑changing upgrade across multiple validators.

Broader Context

This incident follows an earlier Cosmos software disclosure (a CometBFT flaw) that did not enable direct asset theft but highlighted systemic risks in the ecosystem. The Cosmos EVM exploit underscores the challenges of silent patching and the need for clear, vulnerability‑specific communication to downstream chains.

Source & attribution

News Source

Publisher
crypto.news
Original date
August 31, 2026, 7:45 AM
Original headline
Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks
View original report ↗