Cosmos EVM bug triggers $5.7M theft across six blockchains

A Cosmos EVM bug enabled $5.7M theft from six blockchains. Cosmos Labs misjudged the issue, and attacks occurred before a patch was widely deployed. Security processes are under review.

A critical vulnerability in the Cosmos EVM module was exploited between August 20 and 25, 2026, resulting in the theft of approximately $5.7 million from six blockchain networks. The flaw, an integer underflow, enabled attackers to manipulate account balances and extract tokens without minting new ones. Cosmos Labs initially underestimated the bug's severity, applying a silent fix in May after it was reported via a bounty program, but failed to issue a security advisory. An independent researcher later confirmed the issue affected all Cosmos EVM chains, leading to a patch release on August 19. Despite this, attacks began roughly 20 hours later. Networks including MANTRA, TAC, and KiiChain were impacted, with MANTRA losing about $3.6 million. Cosmos Labs coordinated with around 40 chains, helping 13 to patch or halt operations in time. The incident exposed weaknesses in security communication and highlighted the risks of shared software dependencies. Cosmos Labs has pledged to improve its vulnerability response and conduct a comprehensive security audit.

Related Tokens

Related News