Cosmos Labs Admits It Misjudged a Critical EVM Bug Later Used in $5.7 Million Six-Chain Exploit

Cosmos Labs has recently acknowledged that it initially misclassified a critical flaw in Cosmos EVM, the shared software layer that lets Cosmos SDK chains support Ethereum-style applications.

That error later enabled attackers to drain assets from six networks between August 20 and August 25, 2026.

According to the official post-mortem dated August 28, a researcher submitted the issue through the Cosmos bug bounty program on April 25.

Testers tried to reproduce it but could not trigger the problem on the 18-decimal setups used by known live Cosmos EVM chains.

They concluded production funds were not at risk and treated the report as a silent public patch rather than a privately coordinated emergency.

A fix landed on the main branch in May.

Because the change was state-breaking, it was not immediately backported to release branches.

Independent researchers later showed the weakness was not limited to six-decimal networks.

By early August the team confirmed every Cosmos EVM deployment was exposed.

Patches were then obfuscated and shipped as v0.6.2 and v0.7.2 on August 19, with release notes that mentioned security fixes but did not flag urgency or describe the exploit.

Attacks began roughly 20 hours later.

The technical root was an integer underflow in how Cosmos EVM reconciled token balances with the Cosmos SDK bank module.

Vesting accounts can stake both spendable and locked tokens.

When a vesting account delegated more than its spendable balance, an unchecked subtraction wrapped the EVM-visible balance to nearly 2^256.

Attackers then used that inflated figure in a single supply-neutral transaction to overflow a high-balance victim account—often a burn address or genesis multisig—and extract the victim’s tokens. Stolen assets were bridged off-chain and swapped.

Six networks were exploited. Cosmos Labs estimated about $2.87 million was sold on decentralized exchanges and another $2.85 million on centralized venues, for a combined figure near $5.7 million.

Related centralized-exchange accounts have been frozen pending investigations.

After MANTRA alerted the team that exploitation was underway, Cosmos Labs coordinated with 40 chains, helped 13 additional networks patch or halt before further theft, and identified 11 previously unregistered Cosmos EVM deployments.

The post-mortem notes that the code path had been internally and externally audited, yet this specific inconsistency was missed.

Cosmos Labs has pledged tighter triage for reports whose true blast radius exceeds the original proof of concept, broader awareness of coordinated-disclosure channels, and an external review of security practices.

The incident underscores the difficulty of securing a permissionless, multi-chain ecosystem when a shared module is used by more than a hundred public networks, many of them unknown to the core maintainers until an emergency unfolds.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend