Cosmos Labs has officially acknowledged that it made a critical error in assessing the danger of a vulnerability in the Cosmos EVM module. This miscalculation led to a series of coordinated attacks on six blockchains built on this technology, with total damage to the ecosystem exceeding $5.7 million. The incident dealt a serious blow to confidence in the security of Cosmos satellite networks.
Timeline and Scope of the Problem
The issue was first discovered on April 25, 2026, through a bug bounty program. However, after internal testing, the development team concluded that production configurations of the networks were not at risk. This decision proved fatal: the public fix was released without an urgent warning to operators. The situation changed in early August when independent researchers proved that the vulnerability affected absolutely all networks on Cosmos EVM.
Developers urgently disguised the patch and included it in releases v0.6.2 and v0.7.2, published on the evening of August 19. However, the first known attack began just 20 hours later — clearly not enough time to coordinate updates across the entire ecosystem.
Technical Details of the Exploit
In the published postmortem, Cosmos Labs revealed the attack mechanics. Attackers used a complex chain of underflow followed by overflow. Through a specially crafted vesting account and a malicious contract, hackers achieved incorrect balance recalculations, after which they withdrew funds from addresses where large sums were concentrated. It is important to note that no new tokens were minted, and the total coin supply remained unchanged.
Largest Losses
The greatest confirmed damage hit the MANTRA network. Blockchain analysis showed that 720.9 million MANTRA tokens — approximately $3.6 million — were withdrawn from a burn address and an old multisig wallet. The network was halted on August 20, 2026, and resumed operations only after 30 hours, without a state rollback. MANTRA representatives assured that no client account was affected, but tokens previously considered economically inactive effectively entered circulation.
The TAC network lost 2.99 billion tokens, of which about 1.21 billion were sold on BNB Chain for approximately $950,000. KiiChain lost roughly 148.3 million KII: 64.6 million tokens were sold for $1.6 million, while about 54.4% of the stolen funds remained in the network and may be recoverable after restoration. Cosmos Labs did not disclose the names of the other three affected networks.
Criticism and Response
MANTRA and KiiChain sharply criticized the disclosure process. MANTRA stated that 20 hours is catastrophically insufficient for assessment, testing, and coordinating updates among 38 validators, especially without a separate vulnerability notification. KiiChain noted that the recommendation to halt networks came only after three blockchains had already been attacked.
In response, Cosmos Labs reported that it had coordinated with 40 networks and additionally identified 11 unregistered Cosmos EVM deployments in an ecosystem comprising more than 115 public blockchains.
My analysis: This incident demonstrates a systemic problem in security approaches within the Cosmos ecosystem. The decision to publish a patch without urgent operator notification was flawed from the start — even if the vulnerability seemed minor. For networks with distributed validation, reaction time is critical, and saving on communication resulted in millions of dollars in losses. The market as a whole learns from such mistakes, but the price of this lesson for Cosmos proved too high.