Cosmos Labs has officially acknowledged its underestimation of the criticality of a bug in the Cosmos EVM module. This error led to a series of attacks on six blockchains between August 20 and 25, with total damages amounting to $5.7 million. The situation exposed systemic issues in security coordination within the Cosmos ecosystem.

Timeline of the Incident

The problem was first discovered on April 25, 2026, through a bug bounty program. After internal testing, the team concluded that production networks were not at risk and released a public patch without special notification to operators. However, in early August, independent researchers proved that the vulnerability affected all networks on Cosmos EVM. Developers had to urgently mask the fix, integrating it into releases v0.6.2 and v0.7.2, which were published on the evening of August 19. The first attack was recorded just 20 hours later—clearly insufficient time for all validators to update.

Technical Details of the Exploit

In its postmortem, Cosmos Labs revealed the attack mechanics: attackers used a chain of underflow and overflow. Through a specially crafted vesting account and a malicious contract, they achieved incorrect balance recalculations, after which they withdrew funds from addresses with large balances. It is important to note that no new tokens were minted—the total supply remained unchanged, but specific wallets were affected.

Scale of Losses by Network

The largest impact was on MANTRA. A total of 720.9 million MANTRA (~$3.6 million) was withdrawn from the burn address and an old multisig wallet. The network was halted on August 20 and resumed after 30 hours without a state rollback. MANTRA assured that client accounts were not affected, but tokens previously considered economically inactive effectively entered circulation.

TAC's losses amounted to 2.99 billion tokens, of which approximately 1.21 billion were sold on BNB Chain for about $950,000. KiiChain lost approximately 148.3 million KII: 64.6 million tokens were sold for $1.6 million, while 54.4% of the stolen amount remained in the network and may be recoverable. Cosmos Labs did not disclose the names of the other three affected networks.

Criticism and Response Measures

MANTRA and KiiChain strongly criticized the vulnerability disclosure process. According to them, 20 hours is catastrophically insufficient for assessing, testing, and coordinating the update among 38 validators without a separate warning. KiiChain also noted that the recommendation to halt networks came only after attacks on three blockchains. In response, Cosmos Labs stated that it coordinated with 40 networks and identified 11 unregistered Cosmos EVM deployments among more than 115 public blockchains.

My comment: This incident is a vivid example of how even mature ecosystems can underestimate the complexity of cross-network coordination. The delay in communication and insufficient attention to unregistered deployments is a lesson for the entire industry. Security in the multichain world requires not only technical patches but also transparent, prompt notification of all network participants, regardless of their size.