Upgrade your plan
Dashboard

Cosmos Labs Acknowledges Vulnerability Leading to $5.7 Million Theft Across Six Chains

Cosmos Labs has released a technical report admitting to a misjudgment regarding an integer underflow vulnerability in the Cosmos EVM. This oversight resulted in attacks on six blockchain networks between August 20 and 25, culminating in a theft of approximately $5.7 million in tokens. The vulnerability allowed an attacker to manipulate account balances to the maximum value of 2^256-1, enabling the transfer of inflated balances out of target accounts without generating new tokens.

The vulnerability was initially reported through a bug bounty program on April 25, but attempts to reproduce the issue on the existing Cosmos chain configuration were unsuccessful. Consequently, Cosmos Labs implemented a silent patch in May. However, independent researchers confirmed in early August that the vulnerability impacted all Cosmos EVM chains, leading to a patch release on August 19, just hours before the first attack occurred.

Specific losses from the attacks included 720.9 million tokens (approximately $3.6 million) from MANTRA, nearly 3 billion TAC from TAC, and about 148 million KII from KiiChain. Both MANTRA and KiiChain expressed frustration over Cosmos Labs' failure to notify affected chains in advance, suggesting that a temporary shutdown would have been more effective than waiting for the patch deployment, which could take several days. In response, Cosmos Labs stated that it coordinated with 40 chains and assisted 13 in implementing repairs or shutdowns prior to the attacks.

© 2026 KLEA News. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Source: KLEA News

.