Crypto news report · source clearly identified
Cosmos EVM Bug Exploited Across Six Chains, Resulting in Nearly $6 Million Loss
A misjudged accounting flaw in the Cosmos EVM layer was exploited on six networks, including MANTRA, TAC and KiiChain, leading to the theft of roughly $5.7 million before emergency patches were applied.

A vulnerability in the Cosmos EVM software layer was exploited on six blockchain networks, resulting in the theft of almost $6 million. The flaw went unaddressed for four months, allowing attackers to move large token balances without minting new tokens.
Vulnerability Timeline and Scope
The accounting bug was first reported to Cosmos Labs on April 25. Initial testing suggested it only affected chains using six‑decimal token precision, while production Cosmos EVM chains used 18 decimals, leading the team to treat the issue as low‑risk. A silent public patch was merged on May 15 but was not back‑ported to older branches because it required coordinated upgrades.
In early August, further analysis revealed the flaw impacted all Cosmos EVM deployments regardless of decimal settings. Patches (v0.6.2 and v0.7.2) were released on August 19, and a public pull request describing the exploit appeared the next day. Within 12 hours, the first unauthorized transaction was observed on the MANTRA chain.
Exploitation Details
The bug combined two accounting errors: an unsigned‑integer underflow that created an inflated balance, followed by an overflow that allowed the attacker to transfer the legitimate balance of another account. No new tokens were minted; instead, previously inert balances became spendable.
Impact on Affected Chains
- MANTRA: Approximately 720.9 million tokens (about $3.6 million at pre‑incident prices) were moved from a burn address and a legacy multisig. The chain halted 14 minutes after a second unauthorized debit, resulting in a 30‑hour outage.
- TAC: Exploited roughly 45 hours after MANTRA.
- KiiChain: Followed shortly after TAC.
Attackers converted roughly $2.87 million through decentralized exchanges and $2.85 million through centralized venues. Accounts linked to the centralized‑exchange activity have been frozen.
Response and Recovery
Cosmos Labs contacted about 40 networks, and 13 chains applied patches or mitigations before being exploited. The investigation also uncovered 11 Cosmos EVM deployments previously unknown to the security‑communication channels.
As of August 28, no stolen tokens had been recovered. Approximately 38 million MANTRA tokens remained immobilized in the attacker’s account, while the remainder was traced through exchange routes and referred to law enforcement.
Aftermath
The incident prompted Cosmos Labs to revise its vulnerability triage and disclosure processes, shifting from a silent public patch approach to a more urgent, coordinated response for future security issues.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- August 28, 2026, 8:10 PM
- Original headline
- Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains