Attacks on blockchains in the Cosmos ecosystem in late August exposed a serious miscalculation in Cosmos Labs' operations. The company admitted it mistakenly underestimated the criticality of a vulnerability in the Cosmos EVM module, leading to a combined loss of $5.7 million across six networks.

Timeline of the incident

The issue was first discovered on April 25, 2026, through a bug bounty program. After internal testing, the team concluded that production networks were not at risk and released a public patch without notifying operators. However, in early August, independent researchers proved otherwise—the vulnerability affected all networks running Cosmos EVM. Developers had to disguise the fix by integrating it into releases v0.6.2 and v0.7.2, published on the evening of August 19. The first attack followed just 20 hours later.

Technical details

In its postmortem, Cosmos Labs describes the attack as a combination of underflow followed by overflow. The attacker used a specially crafted vesting account and a malicious contract to trigger incorrect balance recalculations and drain funds from addresses with large balances. Importantly, no new tokens were minted—the total supply remained unchanged.

Scale of losses

The hardest-hit network was MANTRA: 720.9 million MANTRA (~$3.6 million) was withdrawn from a burn address and an old multisig wallet. The network was halted on August 20 and resumed after 30 hours without a state rollback. Although MANTRA stated that client accounts were unaffected, tokens previously considered economically inactive entered circulation.

TAC's losses amounted to 2.99 billion tokens, of which 1.21 billion were sold on BNB Chain for approximately $950,000. KiiChain lost about 148.3 million KII, with 64.6 million tokens sold for ~$1.6 million. Part of the stolen funds (54.4%) remains in the network and could be recovered. The names of the other three affected networks have not been disclosed.

Criticism and response

MANTRA and KiiChain sharply criticized the disclosure process. In their view, 20 hours is insufficient time to assess and coordinate an upgrade among 38 validators without separate advance warning. Cosmos Labs counters that it coordinated with 40 networks and identified 11 unregistered Cosmos EVM deployments among more than 115 public blockchains.

My analysis: this incident is another reminder that even mature ecosystems are vulnerable to errors in risk assessment. The decision to hide the patch without urgent notification to operators looks extremely risky, especially given that independent researchers had already pointed out the global nature of the problem. The question is not whether the vulnerability existed, but why the response process was so slow. Given that from January 2025 to July 2026, crypto platforms lost $3.63 billion across 245 incidents, the market clearly lacks standardized emergency notification protocols.