- Cosmos Labs received a crypto bug report in April but underestimated its impact, with attackers later exploiting the flaw to steal nearly $5.7M across six Cosmos EVM chains
- The Cosmos hack showed how a narrow 20-hour window between the patch and first attack left vulnerable networks with little time to assess and respond
- The incident has put the Cosmos outlook under scrutiny, highlighting the need for stronger security reviews and better coordination across independent networks
Crypto security is still one of the most heated and debated chapters of the cryptocurrency domain. The sector continues to attract significant attention on its security ordeals, the hacks, and the scandals that continue to exploit multiple platforms. This debate has once been brought to the surface by the recent security hack involving six Cosmos EVM chains, which resulted in nearly $5.7M worth of funds being stolen.
However, the Cosmos Labs story is a bit different. Almost interesting to an extent. A security flaw was reported to Cosmos Labs in an April bug report. The company believed its testing showed that live networks were not exposed, so the issue was handled through its normal patching process. But four months later, the attackers used the same vulnerability to exploit and drain nearly $5.7M across six Cosmos EVM chains. Here’s what happened, explored in depth down below.
Also Read: Avantis V2 vs Hyperliquid: Can Base’s Perp DEX Really Challenge HYPE?
The Warning That Came In April
The story of the Cosmos hack is interesting in a unique manner. The story goes back to four months back packaged in a April bug report. It was when a researcher submitted the crypto bug through the Cosmos Labs bounty program on April 25th. The company later assessed that its testers could not reproduce the exploit against the configuration used by the production Cosmos EVM networks. This development led them to conclude that user funds were not at any potential harm.
Because of this assessment, the company changed routes. It used its public patch process rather than a private process it uses when a vulnerability is believed to pose risk to crypto funds. A fix was merged in May for this, but the full scope of the problem was not understood at the time.
The Crypto Bug That Came Crashing Down
Cosmos EVM Security Breakdown
How a Four-Month Security Gap Became a $5.7M Loss
Attackers exploited vulnerable Cosmos EVM software across six independent networks.
| Timeline | Event |
|---|---|
| Apr 25 | Vulnerability reported to Cosmos bug bounty |
| May | Fix merged after exploit could not be reproduced |
| Aug 19 | Patched EVM versions released with limited details |
| ~20 hrs | First attack followed the release |
What Was Exploited
- Accounting flaw
- Manipulated token balance
- Vulnerable deployments
What Followed
- 6 networks exploited
- ~$5.7M stolen
- Networks halted or patched
The Bigger Lesson
Finding a vulnerability is only the first step. Teams must assess its full impact and give affected networks enough time to respond.
Key Figures
| $5.7M | Stolen |
| 6 | Networks |
| 20 hrs | Attack window |
| 40 | Networks contacted |
The April bug report vulnerability was indeed bigger than it appeared to be. The vulnerability involved an integer underflow in Cosmos EVM. Cosmos chains use this software framework to run Ethereum-compatible applications.
Cosmos EVM handled token balances in a way that hid the problem deep within its accounting system. Through this vulnerability, an attacker could create a specific type of account. It could later manipulate how the software calculated the amount of tokens that that account could spend. In simple terms, a calculation that may have stopped at zero instead wrapped around and produced an extremely large balance.
The attacker then used this fake balance in another transaction to interfere with another account’s balance. This could ultimately allow the attacker to take tokens from other accounts. The vulnerability exploited an accounting error, allowing the attacker to gain access to legitimate tokens held by other accounts.
Impacted Tokens Took A Brutal Hit
The cosmos hack resulted in impacting the tokens of the related chains. MANTRA’s OM token fell about 18.5% on August 20. The token dropped from $0.00506 to $0.00413. It recovered slightly post that, but the impact jittered the token.
TAC was already under pressure, after a separate 90% intra day drop in July. It had fallen to around $0.0063 at the time. KII also came under renewed scrutiny, after attackers drained 148M tokens from KiiChain during the August exploit.
The Problem Became Much Clear in August
The situation became quite clear in August, when independent research showed how this could impact Cosmos EVM chains more broadly than Cosmos Labs had initially believed.
Cosmos Labs later released patch updates on August 19. The release notes referred to important fixes, but they did not explain the specific vulnerability to network operators. The first attack, however, began around 20 hours after the patched versions were released.
For other networks running independent validators, this was a very short window to identify the issue, let alone run a test. Mantra later said that the 20-hour window was not enough to safely organize an upgrade across its validator network.
Another striking detail was that about 12 hours before the first theft, a developer had already publicly posted the details of the vulnerability and how it could be exploited. This ultimately gave potential attackers a detailed path to understand and exploit the flaw, contributing to the Cosmos hack that followed.
Cosmos Hack Hit Six Networks
Cosmos EVM Security Incident
Nearly $5.7M stolen across six chains
The attackers ended up exploiting six networks between August 20 and August 25. Mantra suffered the largest publicly reported loss, worth around $3.6M. TAC lost nearly 3B TAC tokens. KiiChain ended up losing around 148M KII tokens in separate attacks. Cosmos Labs later estimated that the attackers may have moved $2.87M through decentralized exchanges and $2.85M through centralized ones.
This incident impacted networks running vulnerable versions of Cosmos EVM software and not one single Cosmos Labs network.
Also Read: Arbitrum Future: Can the Network Become More Than an Ethereum Scaling Solution?
The April Bug Report: What Went Wrong
The bigger question is not the recent Cosmos Hack, it’s the gap between discovering a vulnerability and understanding its impact in real time.
Cosmos Labs later shared that it contacted around 40 networks during the response. It later said that 13 potentially exposed chains that it worked with patched, halted, or otherwise protected themselves before the attackers reached them. The response also uncovered nearly 11 Cosmos EVM deployments that Cosmos Labs had not previously known about through its security channels.
The Conclusion
Cosmos Labs later acknowledged that its original assessment that live networks were unaffected was wrong. It has since been reviewing its security response and working with networks across the ecosystem following the attacks.
For the broader crypto ecosystem, the lesson is simple. Teams need to take every crypto bug report seriously, regardless of how small the impact may initially appear.. The Cosmos hack resulted in lessons surrounding how a vulnerability reported months earlier could end up becoming detrimental for users in the future.
Also Read: Robinhood Chain Tops Ethereum at $2.66M in Revenue as 5.52M Transactions Surge