BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Cosmos EVM Bug Behind $5.7M Six-Chain Hack Was Cleared Too Early

Cosmos Labs says a critical Cosmos EVM vulnerability reported through its bug bounty programme in April was incorrectly judged not to affect production networks. Attackers exploited the vulne

AnonymousCryptoCompass newsroom
August 30, 2026
3 min read
NEWS
Cosmos EVM Bug Behind $5.7M Six-Chain Hack Was Cleared Too Early
CryptoCompass editorial visual for altcoins coverage.

Cosmos Labs says a critical Cosmos EVM vulnerability reported through its bug bounty programme in April was incorrectly judged not to affect production networks. Attackers exploited the vulnerability across six chains between August 20 and August 25, 2026.

The activity moved about $2.87 million through decentralised exchanges and another $2.85 million through centralised exchanges, according to the Cosmos Security post-mortem.

The incident exposed a months-long gap between the initial report and releases reaching affected branches shortly before the first known attack. Cosmos Labs said it used its silent patch process because early testing found production chains were safe; the releases did not include a vulnerability-specific advisory.

April report was cleared after production testing

Cosmos Labs’ bug bounty programme received the flaw on April 25. The company said its testers initially concluded that production networks were not vulnerable; the exploit’s use in August later disproved that assessment.

The later post-mortem called the issue a critical balance-underflow vulnerability in Cosmos EVM, the Ethereum-compatible stack used by the affected networks. Because the production networks were judged safe, Cosmos Labs handled the remediation through a silent patch process instead of issuing a vulnerability-specific advisory.

A patch could therefore be available without operators knowing that it addressed an urgent security exposure, and no vulnerability-specific public warning was given before the attacks began.

Unchecked StateDB subtraction created unauthorised balances

The underlying defect sat in Cosmos EVM’s StateDB, according to the project’s security advisory. An unchecked subtraction could occur when a vesting account delegated more than its spendable balance.

Instead of failing safely, the account balance wrapped to approximately 2256. That enormous resulting balance enabled attackers to transfer funds from accounts that had not authorised those transactions.

The exploit mechanism did not depend on an attacker obtaining administrative access. It arose from the balance-handling error itself, which is why the speed and clarity of the software upgrade became central after the fix was made available.

Backported releases arrived hours before the first attack

Cosmos EVM’s main branch received the fix on May 15, but it was not backported to the v0.6.x and v0.7.x release branches until August 19. Versions v0.6.2 and v0.7.2 were published at 23:01 UTC, roughly 20 hours before the first known attack, according to MANTRA Chain’s incident post-mortem.

MANTRA said that window was not realistic for organising a state-breaking upgrade across its validator set, which requires coordination among network operators rather than a routine update by a single company. The Block reported that the patched releases did not identify the vulnerability, corroborating MANTRA’s account of the narrow response window.

The main-branch fix had therefore existed for months before the relevant release-branch versions were published.

Six-chain exploitation moved roughly $5.7 million through exchanges

Across the six exploited networks, Cosmos Labs estimated that roughly $5.72 million was exchanged: approximately $2.87 million via decentralised exchanges and $2.85 million through centralised venues. Those figures describe exchange flows identified in the Cosmos Labs post-mortem, rather than a complete chain-by-chain accounting of losses.

MANTRA reported a separate token-loss figure of 720,923,967.99 MANTRA, valued at about $3.6 million at the pre-incident price. The chain said no validator keys, administrator keys, governance controls or multisig signers were compromised.

The combined record points to a software vulnerability that was reported in April, cleared after testing, and only patched in the affected release lines shortly before exploitation began. For the operators running those chains, the relevant upgrade window was measured in hours.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.