Cosmos Labs has acknowledged that it wrongly assessed a critical Cosmos EVM vulnerability that attackers later exploited across six blockchain networks, stealing about $5.7 million between Aug. 20 and Aug. 25.
The flaw affected shared software that allows Cosmos-based networks to run Ethereum-compatible applications. A researcher first reported the vulnerability through Cosmos Labs’ bug bounty program on April 25. However, testers could not reproduce the exploit on the configurations used by live networks.
As a result, Cosmos Labs treated the issue as a lower-risk vulnerability and addressed it through its silent patch process rather than privately alerting chain operators.
The Vulnerability Became a Major Security Threat
The vulnerability involved an integer underflow that could manipulate token balances. Attackers could make a wallet appear to hold an enormous balance and then use that inflated amount to drain tokens from targeted accounts.
Cosmos Labs later determined that the flaw affected Cosmos EVM networks more broadly. It released a patch on Aug. 19, but the first attack occurred roughly 20 hours later.
MANTRA suffered the largest disclosed loss at about $3.6 million. TAC lost nearly 3 billion tokens, while KiiChain lost roughly 148 million KII.
- Attackers exchanged about $2.87 million through decentralized exchanges.
- Another $2.85 million moved through centralized exchanges.
- Centralized exchange accounts linked to the attackers have been frozen pending investigation.
Patch Timing Draws Criticism
The incident has triggered criticism from affected blockchain operators. MANTRA said the patch arrived only 20 hours before the attack and did not clearly identify the vulnerability.
KiiChain also argued that Cosmos Labs should have instructed affected networks to halt immediately. The chain said a shutdown could have taken minutes, while reviewing and deploying a security upgrade across validators could take days.
Cosmos Labs said it coordinated with 40 chains during the response and helped 13 networks patch or halt before attackers reached them. The company also discovered 11 previously unregistered Cosmos EVM deployments.
The incident highlights the security challenges of shared blockchain infrastructure, where one software flaw can expose multiple independent networks. No stolen funds had been recovered as of Aug. 28.