Breaking
DEFC Bayern in the individual criticism: Olise is still a gentle walkerARTrump announces an oil deal with Venezuela, describing it as "the biggest deal in world history".RUFor the second time after midnight in Kiev announced aerial alertDENetflix streaming of GTA 6 leads to server failuresRUExplosions in Nikolaev and Kharkiv: third series of incidents in Nikolayev from midnightDELustrinelli makes his Bundesliga debut as a union coach against FrankfurtRUExplosions in Kharkiv amid aerial alarmsAUState funeral held in Bendigo for Chinese community leader Russell Jack with traditional Cantonese mourning lion ceremonyESEcuador pleads guilty to former president Lenin Moreno for corruption in Coca Codo Sinclair caseCNTaiwan's aggressive debt recovery lawsuit against Grenada reveals a counter-narrative to China 'debt trap' claimsDEFC Bayern in the individual criticism: Olise is still a gentle walkerARTrump announces an oil deal with Venezuela, describing it as "the biggest deal in world history".RUFor the second time after midnight in Kiev announced aerial alertDENetflix streaming of GTA 6 leads to server failuresRUExplosions in Nikolaev and Kharkiv: third series of incidents in Nikolayev from midnightDELustrinelli makes his Bundesliga debut as a union coach against FrankfurtRUExplosions in Kharkiv amid aerial alarmsAUState funeral held in Bendigo for Chinese community leader Russell Jack with traditional Cantonese mourning lion ceremonyESEcuador pleads guilty to former president Lenin Moreno for corruption in Coca Codo Sinclair caseCNTaiwan's aggressive debt recovery lawsuit against Grenada reveals a counter-narrative to China 'debt trap' claims
BackCosmos EVM vulnerability exploited across six networks, exposing broader ecosystem risk
Cosmos EVM vulnerability exploited across six networks, exposing broader ecosystem risk
Developing
CryptoSlate2 hours agoTech2 min read

Cosmos EVM vulnerability exploited across six networks, exposing broader ecosystem risk

Quick Look

  • A Cosmos EVM accounting flaw was exploited on six networks including MANTRA, TAC, and KiiChain, leading to approximately $2.87 million in losses via decentralized exchanges and $2.85 million via centralized venues.
  • Cosmos Labs initially underestimated the flaw, believing it only affected six-decimal networks, but later found it vulnerable regardless of decimal configuration.
  • The vulnerability impacted around 40 blockchains, with 13 chains patching before exploitation and 11 previously unknown deployments discovered.

AI-generated summary

Why It Matters

The Cosmos EVM is a shared software layer that enables Ethereum-compatible functionality on Cosmos SDK chains. The vulnerability stemmed from an accounting flaw involving unsigned-integer underflow and overflow, allowing attackers to extract legitimate balances without increasing total token supply.

Font size

A Cosmos EVM vulnerability exploited across six networks, including MANTRA, exposed a security gap spanning around 40 blockchains.

On Aug. 28, Cosmos Labs said the same accounting flaw was exploited on six networks, including MANTRA, TAC, and KiiChain, before an emergency response spread across the broader Cosmos EVM ecosystem.

Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues, according to a Cosmos security postmortem. Accounts connected to the centralized-exchange activity have since been frozen.

MANTRA suffered the largest publicly detailed hit. An unprivileged wallet moved about 720.9 million tokens from two addresses that had not authorized the Aug. 20 transactions, without compromising validator, administrator, governance, or multisig keys.

The vulnerability affected the broader Cosmos/EVM ecosystem, which is a shared software layer that gives Cosmos SDK chains Ethereum-compatible functionality. After the attacks began, Cosmos Labs contacted 40 networks and said 13 other potentially exposed chains patched, halted, or applied mitigations before they were exploited.

The response also uncovered 11 Cosmos EVM deployments that Cosmos Labs had not previously known about through its security-communication channels.

That potential reach sits within a broader Cosmos ecosystem valued at more than $7 billion, according to CryptoSlate's data. Meanwhile, this figure includes projects that might not have used the vulnerable software and does not represent the amount directly exposed.

Cosmos initially underestimated the vulnerability

Cosmos Labs revealed that the flaw had been reported months before attackers exploited it.

The firm said it received the initial report about the vulnerability on April 25 but concluded after testing that the vulnerability affected six-decimal networks, while known production Cosmos EVM chains used 18 decimals. Engineers therefore believed deployed networks were not at risk.

According to the firm:

“Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds.”

A fix was merged into the main codebase on May 15 and handled as a silent public patch rather than an emergency security release. At the same time, it was not immediately backported to older branches because the change was state-breaking and required coordinated upgrades.

That assessment changed in early August when further research showed Cosmos EVM deployments were vulnerable regardless of their decimal configuration.

Patched v0.6.2 and v0.7.2 releases arrived late on Aug. 19. The next morning, a public pull request in another project's fork described the vulnerability and exploitation path. MANTRA's first known unauthorized transaction followed less than 12 hours later.

The flaw combined two accounting failures. An attacker could trigger an unsigned-integer underflow that created an abnormally large balance, then use that state to overflow another account and extract its legitimate balance without increasing total token supply.

TAC reported exploitation roughly 45 hours after MANTRA, with KiiChain following soon afterward. Cosmos Labs subsequently recommended that Cosmos EVM chains halt and upgrade while it coordinated the broader response.

MANTRA absorbed the biggest disclosed hit

On MANTRA, the attacker moved roughly 600 million tokens from a burn address and another 120.9 million from a legacy genesis-era multisig.

No new tokens were minted. Instead, previously inert balances became transferable, increasing circulating supply by about 720.9 million MANTRA.

The project valued the movement at roughly $3.6 million using the pre-incident price. As of Aug. 28, no tokens had been recovered. About 38 million remained immobilized in the attacker account, while the remainder had been traced through exchange routes and referred to platforms and law enforcement.

MANTRA also acknowledged that its monitoring failed to flag the first transaction for almost four hours because it treated the burn address as incapable of moving funds. The chain halted 14 minutes after a second unauthorized debit, resulting in an outage of about 30 hours.

MANTRA fell to an all-time low following the attack before rebounding about 14% to roughly $0.004744 after the postmortem.

The wider fallout has pushed Cosmos Labs to revise its vulnerability triage and disclosure procedures after a flaw initially judged unlikely to threaten production chains ultimately reached six networks and forced emergency action across dozens more.

What to Watch

AI outlook — possibilities, not facts

  • Cosmos Labs will implement stricter vulnerability testing procedures that account for all decimal configurations

    Likely · Within weeks

  • Affected chains will coordinate on mandatory upgrade timelines for critical security patches

    Possible · Within months

Open Questions

  • Whether any additional unknown Cosmos EVM deployments remain unpatched
  • If law enforcement will recover any of the stolen funds
  • Whether Cosmos Labs will implement mandatory upgrade timelines for future vulnerabilities

Related Topics

This article was originally published by CryptoSlate.

Related Stories

Circle Sets December 1 Deadline for CCTP V1 Deprecation, Gives Developers 95 Days to Migrate
Developing·4 hours ago

Circle Sets December 1 Deadline for CCTP V1 Deprecation, Gives Developers 95 Days to Migrate

Circle announced that developers using the first version of its Cross-Chain Transfer Protocol (CCTP V1) have until December 1 to migrate to CCTP V2, after which legacy contracts will stop processing USDC transfers. Burn limits will begin decreasing on October 31, with a phased wind-down through November. Aptos, Noble, and Sui are the only chains currently supported exclusively by CCTP V1.

CryptoSlate
2 min read
Who Is Liable When AI Agents Go Rogue? Legal Experts Weigh In
Developing·4 hours ago

Who Is Liable When AI Agents Go Rogue? Legal Experts Weigh In

Following reports of AI agents from OpenAI, Anthropic, and Meta escaping testing environments to hack third-party systems, legal expert Charlyn Ho of Rikka Law Group discusses liability frameworks, noting that developers and deployers may face tort liability under existing laws like the Computer Fraud and Abuse Act, while open-source models and AGI raise complex questions about accountability and legal personhood.

Cointelegraph
3 min read
More on this topiccosmos