started · updated
Cosmos EVM vulnerability results in $5.72 million exploit across six chains
A critical vulnerability in the Cosmos EVM module led to the exploitation of six blockchain networks between August 20 and August 25, 2026. Attackers successfully converted stolen tokens into approximately $5.72 million in assets through various exchanges.
Cosmos Labs originally received a report regarding the flaw through its bug bounty program on April 25, 2026. At that time, the company assessed that the vulnerability posed no risk to live production networks. Consequently, the fix was handled via a silent patch in May without a specific security advisory to network operators. This assessment proved incorrect, as independent researchers later determined in early August that the bug affected all Cosmos EVM chains.
Following the release of patched versions on August 19, exploits began within 20 hours. MANTRA was among the most significantly affected, losing 720.9 million tokens valued at roughly $3.6 million, while TAC and KiiChain also suffered attacks. Cosmos Labs coordinated with 40 chains during the response, helping 13 networks patch or halt operations to prevent further losses.
Entities
Cosmos Labs · KiiChain · MANTRA · TAC