Cosmos Labs Admits It Cleared a Bug That Drained $5.7M from Six Chains

By Electra

Cosmos Labs Admits It Cleared a Bug That Drained $5.7M from Six Chains

A bug flagged through Cosmos Labs' own bug bounty program in April sat quietly in the codebase for four months before attackers used it to drain $5.7 million from six Cosmos EVM chains in five days. The reason it went unaddressed at the right urgency level: Cosmos Labs concluded it wasn't dangerous, patched it without warning chain operators, and got the assessment wrong.

Cosmos Labs confirmed in a post-mortem published Friday that the attacks ran across six blockchain networks between August 20 and August 25, exploiting a flaw in Cosmos EVM — the shared software layer that lets Cosmos chains run Ethereum-style applications. A researcher had identified the flaw and submitted it through the bug bounty program on April 25. Testers could not reproduce the attack against the configuration used by live Cosmos chains and therefore concluded that funds on those networks were not at risk.

X postView the original post on XOpen post →

Based on that assessment, Cosmos Labs addressed the vulnerability through what it calls its "silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds." The fix was merged in May under that silent process, which ships bug fixes without telling chain operators what it addresses. Cosmos Labs said it has patched 37 vulnerabilities that way over the past 13 months.

That routine approach had a critical flaw: on August 13, the team confirmed internally that all Cosmos EVM chains are affected, regardless of their decimal configuration — the very assumption that had led testers to clear the bug in April. Affected versions are below v0.6.2 and v0.7.2, and the fix shipped in those releases on August 19. The first unauthorized transaction on MANTRA followed roughly twelve hours later.

A Patch That Arrived Too Late, and Said Too Little

MANTRA Chain, which lost $3.6 million, published its own post-mortem saying the patch was released only 20 hours before the attack began and did not identify the flaw it fixed. That timing detail is pointed: operators who upgraded would have had no reason to treat the release as an emergency without a security advisory attached to it.

The attacker exploited a bug known as integer underflow to trick the Cosmos EVM networks into crediting the attacking wallets with effectively infinite tokens. Cosmos Labs said the targets were arbitrary accounts holding large balances, such as burn addresses and multi-signature wallets created when a chain launched. In MANTRA's case, about 720.9 million tokens that were previously inert became transferable: roughly 600 million from a burn address and another 120.9 million from an old multisig.

Operational failures compounded the delay. MANTRA's monitoring system assumed the burn address could never move funds, so it didn't flag the first unauthorized transaction for almost four hours. After a second suspicious debit arrived, the chain was halted just 14 minutes later, leaving it offline for about 30 hours.

The two post-mortems now on the table do not fully agree. KiiChain said the exploit required three upstream defects rather than just two, and that only the underflow has been patched publicly.

MANTRA's account goes the other direction, describing the underflow fix as "the control that closes this attack path." That contradiction has not been resolved publicly.

Forty Chains in the Blast Radius

The incident forced Cosmos Labs to contact 40 networks, with 13 potentially exposed chains patching, halting, or deploying mitigations. The response also uncovered 11 Cosmos EVM deployments that Cosmos Labs had not previously known about through its security-communication channels — a detail that puts the silent patch process in a harder light. If the maintainer didn't have a full map of who was running the software, a non-advisory release was structurally unable to reach every exposed operator.

Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues, according to the Cosmos security post-mortem. Cosmos Labs said affected chains reported that the centralized-exchange accounts had been frozen while police investigations continued. The $5.72 million conversion total will not change, but recovery of frozen exchange balances could reduce the final net loss.

This is not the first time the Cosmos EVM shared codebase has been exploited at scale in 2026. In January, an attacker took roughly $7 million from Saga's EVM network through the ICS20 precompile, according to Cosmos Labs' ASA-2026-002 advisory.

X postView the original post on XOpen post →

MANTRA was among the 15 chains that Cosmos Labs contacted to coordinate remediation during that earlier incident. The fact that MANTRA was named as a remediation participant in January and still took the largest loss in August sharpens the question of what coordinated remediation actually means in practice.

"Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds." — Cosmos Labs post-mortem, August 28, 2026

Cosmos Labs is now revising its security triage and disclosure process after discovering the flaw's real blast radius only shortly before the attacks. Chain operators are told to upgrade to v0.6.2, v0.7.2, or later — a state-breaking change that requires a coordinated network upgrade. Operators who cannot upgrade immediately are told to halt the chain rather than attempt a coordinated governance upgrade.

The underlying issue is structural: shared infrastructure means a single triage misjudgment propagates across every chain running the module. When the blast radius spans 40 networks and 11 of them were unknown to the maintainer, a silent patch is not a disclosure strategy — it is the absence of one.

Source: The Block

Sources

  • Cosmos EVM Vulnerability: Six Chains Affected
  • Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
  • Ignored Cosmos EVM Bug Cost Nearly $6M — What Went Wrong
  • Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains
  • Cosmos Labs Misread Bug Before $5.7M Six-Chain Hack
  • Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks | The Defiant
  • MANTRA Chain Hacked Via Cosmos EVM Bug That Already Cost Saga $7M in January

Explore more: More Cosmos coverage

Published on Safe

Cosmos Labs Admits It Cleared a Bug That Drained $5.7M from Six Chains