Cosmos Labs Cleared a Bug in April. Attackers Used It to Drain $5.7M From Six Chains.

By Bartek Hagan

(12 days ago)

4 min read

Share:

Cosmos Labs said attackers exploited a Cosmos EVM flaw to steal about $5.7 million from six blockchains between 20 and 25 August 2026. The firm had cleared the same bug as harmless in April.

Cosmos Labs Cleared a Bug in April. Attackers Used It to Drain $5.7M From Six Chains.

Key facts

  • Cosmos Labs said attackers exploited a Cosmos EVM flaw to steal about $5.7 million from six blockchains between 20 and 25 August 2026.
  • A researcher reported the bug in April, but Cosmos Labs judged live chains safe and shipped a quiet patch with no advisory.
  • MANTRA lost about $3.6 million; TAC and KiiChain were also drained, and three more chains were hit but not named.

Cosmos Labs says attackers drained six chains of $5.7 million

Cosmos Labs said attackers stole funds from six blockchain networks between 20 and 25 August 2026 by exploiting a flaw in Cosmos EVM, the shared software that lets Cosmos blockchains run Ethereum-style applications. The firm set out the theft in a technical post-mortem published on 28 August. Attackers swapped the stolen tokens for about $2.87 million on decentralised exchanges (DEXs) and roughly $2.85 million on centralised exchanges (CEXs), a combined $5.7 million. Cosmos Labs said the centralised exchange accounts used by the attackers have been frozen pending investigation by the relevant authorities.

A reported bug was cleared as harmless in April

A researcher reported the flaw through the Cosmos bug bounty programme on 25 April 2026, according to the post-mortem. Cosmos Labs said its testers could not reproduce the attack against the configuration used by live Cosmos chains and concluded that funds on those networks were not at risk. On that basis, the firm handled the fix through its silent public patch process rather than the private distribution it uses when a bug is believed to threaten user funds. Cosmos Labs said it has patched 37 vulnerabilities this way over the past 13 months.

The fix reached chains 20 hours before the first attack

Reports from independent researchers in early August established that the bug affected all Cosmos EVM chains, the post-mortem said. Cosmos Labs then obscured the fix to prevent reverse engineering and released it at 7:01 p.m. ET on 19 August, with release notes that referred only to "important" security fixes. The first attack began about 20 hours later, at 3:06 p.m. ET on 20 August. MANTRA, the hardest-hit network, said that window was too short to act on.

 

"Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory.", 28 August 2026. — MANTRA, exploit post-mortem

 

MANTRA lost $3.6 million as monitoring missed the theft

MANTRA lost 720.9 million tokens then worth about $3.6 million, drained from its burn address and a dormant multi-signature (multisig) wallet left from an earlier incentive campaign. No alert fired on the first transaction because the burn address was treated as immovable and fell outside the chain's monitoring. The theft went undetected for nearly four hours. TAC lost close to 3 billion tokens from its staking pool on 22 August, about 1.2 billion of which sold for around $950,000, while KiiChain lost about 148 million KII, with 64.6 million sold for roughly $1.6 million. Three further chains were hit using the same method, though Cosmos Labs did not name them.

MANTRA trades below one cent as supply climbs

MANTRA traded at about $0.0043 at the time of publication, down roughly 80% from its 5 March 2026 high of $0.022 (CoinPaprika, 30 August 2026). The token's market value stood near $20 million. Its circulating supply rose by about 720.9 million tokens after the exploit, because the drained balances had been counted as unspendable but are now tradable.

KiiChain says a halt order came too late

KiiChain, which published its own post-mortem on 23 August, said Cosmos Labs gave affected chains no advance notice and did not recommend halting until 22 August, after MANTRA, TAC and KiiChain had all been hit. KiiChain also said the exploit relied on three upstream defects and that only one has been patched publicly, while MANTRA's report said the single fix closes the attack path. Cosmos Labs coordinated with 40 chains during the response and helped 13 others patch or halt before they were attacked. It also found 11 Cosmos EVM deployments it had not known about, out of more than 115 public chains in the ecosystem.

 

"A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes.", 23 August 2026. — KiiChain, technical post-mortem

 

Primary source: Source ↗

Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.

All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.

Coinpaprika is not liable for any losses resulting from the use of this information.

Share:
Go back to All News