NewsCryptoCosmos Labs Admits Misjudging Critical Bug Before $5.7 Million Six-Chain Hack

Cosmos Labs Admits Misjudging Critical Bug Before $5.7 Million Six-Chain Hack

Author: CryptoMeter io·

Key Takeaways

  • Attackers exploited an integer underflow vulnerability in Cosmos EVM shared software to inflate wallet balances and drain roughly $5.7 million from six blockchain networks between August 20 and 25.
  • Cosmos Labs classified the reported flaw as lower-risk after failing to reproduce it on live network configurations and used a silent patch process instead of privately warning chain operators.
  • MANTRA suffered the largest disclosed loss of about $3.6 million, while TAC lost nearly 3 billion tokens and KiiChain lost roughly 148 million KII.
  • The patch was released on August 19, only about 20 hours before the first attack, leaving validators a narrow window to coordinate and deploy the upgrade across independent operators.
  • As of August 28, none of the stolen funds had been recovered, and centralized exchange accounts linked to the attackers have been frozen pending investigation.
Cosmos Labs Admits Misjudging Critical Bug Before $5.7 Million Six-Chain Hack

Cosmos Labs has acknowledged that it incorrectly assessed a critical vulnerability in Cosmos EVM that attackers subsequently exploited across six blockchain networks, stealing approximately $5.7 million between Aug. 20 and Aug. 25.

The flaw resided in shared software that enables Cosmos-based networks to run Ethereum-compatible applications. A researcher first reported the vulnerability through Cosmos Labs' bug bounty program on April 25. However, testers were unable to reproduce the exploit on the configurations used by live networks.

As a result, Cosmos Labs classified the issue as a lower-risk vulnerability and handled it through its silent patch process rather than privately alerting chain operators. That decision meant many chain operators first learned of the flaw's severity only after attacks had already begun.

The Vulnerability Became a Major Security Threat

The vulnerability involved an integer underflow that could be used to manipulate token balances. Attackers were able to make a wallet appear to hold an enormous balance and then use that inflated amount to drain tokens from targeted accounts.

Cosmos Labs later determined that the flaw affected Cosmos EVM networks more broadly. A patch was released on Aug. 19, but the first attack took place roughly 20 hours later — a narrow window for validators, who must coordinate across independent operators to review and deploy upgrades.

MANTRA suffered the largest disclosed loss, at approximately $3.6 million. TAC lost nearly 3 billion tokens, while KiiChain lost roughly 148 million KII.

The attackers exchanged about $2.87 million through decentralized exchanges, while another $2.85 million moved through centralized exchanges. Centralized exchange accounts linked to the attackers have been frozen pending investigation.

Patch Timing Draws Criticism

The incident has drawn criticism from affected blockchain operators. MANTRA said the patch arrived only 20 hours before the attack and did not clearly identify the vulnerability.

KiiChain argued that Cosmos Labs should have instructed affected networks to halt immediately. The chain noted that a shutdown could have been carried out within minutes, whereas reviewing and deploying a security upgrade across validators could take days.

Cosmos Labs said it coordinated with 40 chains during the response and helped 13 networks patch or halt before attackers reached them. The company also discovered 11 previously unregistered Cosmos EVM deployments — deployments whose operators had no direct channel for receiving security notifications.

The incident underscores the security challenges of shared blockchain infrastructure, where a single software flaw can expose multiple independent networks simultaneously. It also highlights the trade-offs of coordinated disclosure in multi-chain ecosystems, where patching speed must be balanced against alerting potential attackers. As of Aug. 28, none of the stolen funds had been recovered.