Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains

NewsFri, 28 Aug 2026 20:10:23 UTC3 hours ago
Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains

A Cosmos EVM vulnerability exploited across six networks, including MANTRA, exposed a security gap spanning around 40 blockchains.

On Aug. 28, Cosmos Labs said the same accounting flaw was exploited on six networks, including MANTRA, TAC, and KiiChain, before an emergency response spread across the broader Cosmos EVM ecosystem.

Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues, according to a Cosmos security postmortem. Accounts connected to the centralized-exchange activity have since been frozen.

MANTRA suffered the largest publicly detailed hit. An unprivileged wallet moved about 720.9 million tokens from two addresses that had not authorized the Aug. 20 transactions, without compromising validator, administrator, governance, or multisig keys.

Related Reading

MANTRA Chain is back online, but silent code changes spark developer concerns

The vulnerability affected the broader Cosmos/EVM ecosystem, which is a shared software layer that gives Cosmos SDK chains Ethereum-compatible functionality. After the attacks began, Cosmos Labs contacted 40 networks and said 13 other potentially exposed chains patched, halted, or applied mitigations before they were exploited.

… Continue reading the full article at the original source below.

Read from Source · cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related