The Cosmos EVM Bug Was Reported in April. Six Chains Fell in August.

A researcher flagged the Cosmos EVM bug in April. Cosmos Labs judged live chains safe and patched it quietly. Six networks still lost $5.7 million.

Ramy Morton Tech

A security researcher handed Cosmos Labs the bug on April 25. Cosmos Labs had the report, wrote a fix, and judged the live networks safe enough to skip any public warning. That call cost six chains close to $5.7 million. The same flaw in the Cosmos EVM module that testers waved off in the spring is the one attackers used in August to drain balances across the network, and the postmortem published this week admits the assessment was simply wrong.

Four months to judge it, one day to lose the money

The flaw was an integer underflow in how Cosmos EVM reconciled balances between the EVM state and the Cosmos SDK bank module. An account could delegate more tokens than it actually held. The subtraction that followed ran with no bounds check, so the balance wrapped around to a 78-digit figure near 2^256. From there an attacker could pull funds out of the inflated account, or push a victim's balance down until reconciliation burned their real holdings. No keys, no governance, no multisig. Just arithmetic doing what unchecked arithmetic does.

Cosmos Labs merged an initial patch on May 15 and a second one five days later, both through its quiet public-patch process, with no advisory attached. The team ran the flaw through its testers, could not reproduce it on 18-decimal networks, and concluded that only a narrow slice of chains was exposed. The postmortem states it plainly: the team was unable to reproduce the vulnerability on 18-decimal networks and incorrectly decided it affected only the others. Every chain running the module, it turned out, was at risk.

Date (2026)What happened
April 25Flaw reported through the Cosmos bug bounty
May 15First fix quietly merged (PR #1176)
May 20Second fix merged (PR #1187)
Aug 13Cosmos Labs confirms every chain is affected
Aug 19Patched builds v0.6.2 and v0.7.2 ship
Aug 20Public disclosure posts; first attack hits MANTRA within hours
Aug 20 to 25Attacks spread to TAC, KiiChain and others
Aug 28Cosmos Labs publishes its postmortem

The public fix is what started the clock

On August 13, four months after the report, Cosmos Labs confirmed internally that every chain running Cosmos EVM was affected. Patched builds went out on the 19th. The next morning a public disclosure landed on GitHub, laying out the vulnerability and the path to exploit it while leaving off the versions that carried the fix. The first attack hit MANTRA within hours of that post.

The silent-patch process is meant to protect chains by shipping a fix before anyone can read it as a set of instructions. For Cosmos EVM it worked in reverse. The patched builds and the public write-up arrived inside the same 24 hours, so the disclosure ended up doing the attacker's reconnaissance, pointing straight at the accounts on chains that had not yet upgraded. A four-month head start collapsed into a one-day scramble.

MANTRA put the timing in blunt terms. The security finding, it said, was filed 11 hours and 45 minutes before the attacker's first probe. Twenty hours was not a realistic window to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, the chain argued. It halted the network 14 minutes after the second unauthorized debit. By then the money was already moving out. MANTRA restarted its chain a week later and still would not fully account for what happened.

Six chains hit, and eleven the team did not know were running it

MANTRA took the largest loss, near $3.6 million, as 720.9 million tokens moved out of a burn address and a legacy multisig. TAC was drained roughly 45 hours later, KiiChain after that, with smaller amounts on Nesa and two chains that have not been named. Every one of them shared the same Cosmos EVM dependency, which is how a single arithmetic flaw crossed six unrelated networks. Across sales on decentralized and centralized venues, the attacker cleared about $5.72 million, split almost evenly between the two.

The response numbers say more about the blast radius than the theft does. Cosmos Labs reached 40 networks once it understood the scope. Thirteen patched, halted, or deployed mitigations before anyone touched them. Eleven more were deployments the team did not know existed until it went looking. This is the same Cosmos EVM module coinliva flagged when Saga lost $7 million to it earlier, and it fits a pattern where code bugs drive most crypto hacks even when the dollar losses stay modest.

The attacker never touched a validator key or cracked a multisig. This was a math error that sat in the open for four months, patched but undisclosed, until the disclosure itself handed attackers the map. The open question now is how many of those 40 networks upgraded in time, and how many are still running a build that Cosmos Labs already knows how to break.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Ramy Morton
Author

Ramy Morton

Ramy Morton is Coinliva's Markets & On-Chain Analyst. He covers crypto markets with a focus on price action, ETF flows, derivatives positioning, stablecoin movements, and exchange reserves. His analysis is built on primary data sources including Glassnode, CryptoQuant, Coinglass, and ETF issuer disclosures.