Cosmos Labs has admitted that it mistakenly considered a vulnerability in the Cosmos EVM module to be insufficiently dangerous. As a result, the bug was exploited to attack six blockchains, with total damages reaching $5.7 million.
Between August 20th and August 25th, attackers exploited a vulnerability in Cosmos EVM to extract funds from multiple Cosmos-based blockchains. We are committed to strengthening the systems and processes we rely on for security and are grateful for the collaboration of the...
— Cosmos Labs (@cosmoslabs_io) August 28, 2026
The issue was reported on April 25, 2026, via a bug bounty program. After testing, the team concluded that networks with production configurations were not at risk and released a public fix without a separate warning for operators. In early August, independent researchers demonstrated that the vulnerability affected all networks on Cosmos EVM. Following this, the developers masked the patch, moved it into releases v0.6.2 and v0.7.2, and published them on the evening of August 19. The first known attack began approximately 20 hours later.
In a postmortem, Cosmos Labs described the attack as a chain of underflow followed by overflow. Using a specially crafted vesting account and a malicious contract, the attacker achieved an incorrect balance recalculation and then transferred funds from addresses with large balances. The company claims that no new tokens were created and the total supply did not change.
The largest confirmed damage was to MANTRA. According to a network analysis, 720.9 million MANTRA tokens—worth approximately $3.6 million—were withdrawn from a burn address and an old multisig wallet. The network was halted on August 20, 2026, and resumed more than 30 hours later without a state rollback. MANTRA stated that no client accounts were affected, but tokens previously considered economically inactive have effectively entered circulation.
Cosmos Labs estimated TAC's losses at 2.99 billion TAC. Of these, approximately 1.21 billion tokens were sold on BNB Chain for about $950,000.
KiiChain lost ~148.3 million KII. According to the company's estimate, 64.6 million tokens were sold for about $1.6 million, while about 54.4% of the stolen amount remained in the network and could potentially be recovered after restoration.
Cosmos Labs did not name the other three affected networks.
MANTRA and KiiChain criticized the vulnerability disclosure process. The team of the former network stated that 20 hours was insufficient to assess, gather, test, and coordinate the update among its 38 validators without a separate vulnerability notification. KiiChain noted that the recommendation to halt networks came only after attacks on three blockchains had already occurred.
In response, Cosmos Labs stated that it coordinated with 40 networks and separately identified 11 unregistered Cosmos EVM deployments within the ecosystem of more than 115 public blockchains.
What is Cosmos ($ATOM)?
Recall that from January 2025 to July 2026, crypto platforms lost $3.63 billion in 245 documented incidents, according to CoinGecko data.
end-content





