A large-scale incident in the Cosmos ecosystem exposed a systemic problem in the risk management process. I conducted my own analysis of the postmortem published by Cosmos Labs and concluded that a chain of errors led to the loss of $5.7 million across six blockchains based on Cosmos EVM. The key point is that the vulnerability was initially misclassified as minor, which became the root cause of the cascading failure.
Timeline and technical details of the exploit
The issue was discovered as early as April 25, 2026, through a bug bounty program. After internal testing, the security team concluded that production networks were not at risk and released a public patch without notifying operators. However, in early August, independent researchers proved otherwise — the vulnerability affected all networks on Cosmos EVM. Developers had to urgently mask the fix, embedding it into releases v0.6.2 and v0.7.2, published on the evening of August 19. The first attack followed just 20 hours later.
Technically, the attack was a complex chain of underflow and overflow. The attacker used a specially crafted vesting account and a malicious contract to incorrectly recalculate balances, then withdrew funds from addresses with large holdings. It is important to note: no new tokens were minted, and the total supply remained unchanged.
Distribution of damage
The largest blow hit the MANTRA network — 720.9 million MANTRA tokens (~$3.6 million) were withdrawn from the burn address and an old multisig wallet. The network was halted on August 20 and resumed 30 hours later without a state rollback. Notably, although client accounts were not affected, tokens previously considered economically inactive entered circulation.
TAC's losses amounted to 2.99 billion tokens, of which about 1.21 billion were sold on BNB Chain for approximately $950,000. KiiChain lost ~148.3 million KII, with 64.6 million tokens sold for $1.6 million, while 54.4% of the stolen amount remains in the network and could be recovered.
Criticism and response measures
MANTRA and KiiChain harshly criticized the disclosure process. In their view, 20 hours is catastrophically little time to coordinate an update among 38 validators without prior warning. In response, Cosmos Labs stated that it coordinated with 40 networks and identified 11 unregistered Cosmos EVM deployments among more than 115 public blockchains.
My analysis: This incident demonstrates a fundamental problem in DeFi security approaches — underestimating the criticality of a vulnerability with limited testing. The fact that Cosmos Labs did not disclose three of the six affected networks undermines trust in the transparency of the process. Given that from January 2025 to July 2026, crypto platforms lost $3.63 billion across 245 incidents, the market urgently needs stricter coordination standards and mandatory operator notification.