started · updated
Cosmos EVM exploit drains nearly $6 million across multiple networks
An exploit of the Cosmos EVM software stack has resulted in the loss of approximately $5.72 million across several blockchain networks. The vulnerability, an arithmetic underflow occurring when mirroring balances after staking operations, was exploited across at least six networks, including MANTRA, TAC, and KiiChain.
Cosmos Labs reported that the flaw was initially identified on April 25, but engineers mistakenly believed production chains were safe because they used 18 decimals rather than the six-decimal format tested during the initial report. This misjudgment left networks exposed for months.
While the Cosmos Hub and ATOM tokens were not directly targeted, the shared software layer allowed attackers to move significant funds, including 148.33 million KII and 2.99 billion TAC. In response to the attacks, Cosmos Labs contacted 40 networks, and several chains have since patched or halted operations to mitigate further risk. Approximately half of the stolen funds were moved through decentralized exchanges, while the other half moved through centralized venues where accounts have since been frozen.
Entities
Cosmos EVM · Cosmos Labs · KiiChain · MANTRA · TAC