Cosmos Labs Hack Exposes Bug Reported in April That Drained $5.7M Across 6 Chains

Cosmos Labs logo representing the April bug report, crypto bug, Cosmos hack, and Cosmos outlook for blockchain security.

Crypto security is still one of the most heated and debated chapters of the cryptocurrency domain. The sector continues to attract significant attention on its security ordeals, the hacks, and the scandals that continue to exploit multiple platforms. This debate has once been brought to the surface by the recent security hack involving six Cosmos EVM chains, which resulted in nearly $5.7M worth of funds being stolen.

However, the Cosmos Labs story is a bit different. Almost interesting to an extent. A security flaw was reported to Cosmos Labs in an April bug report. The company believed its testing showed that live networks were not exposed, so the issue was handled through its normal patching process. But four months later, the attackers used the same vulnerability to exploit and drain nearly $5.7M across six Cosmos EVM chains. Here’s what happened, explored in depth down below.

Also Read: Avantis V2 vs Hyperliquid: Can Base’s Perp DEX Really Challenge HYPE?

The Warning That Came In April

Coldcard RNG vulnerability Bitcoin self-custody risks Coldcard Mk4 drain Hardware wallet security flaw Weak Bitcoin seed entropy
chSource: Anonymous Wallpapers

The story of the Cosmos hack is interesting in a unique manner. The story goes back to four months back packaged in a April bug report. It was when a researcher submitted the crypto bug through the Cosmos Labs bounty program on April 25th. The company later assessed that its testers could not reproduce the exploit against the configuration used by the production Cosmos EVM networks. This development led them to conclude that user funds were not at any potential harm.

Because of this assessment, the company changed routes. It used its public patch process rather than a private process it uses when a vulnerability is believed to pose risk to crypto funds. A fix was merged in May for this, but the full scope of the problem was not understood at the time.

The Crypto Bug That Came Crashing Down

Cosmos EVM Security Breakdown

How a Four-Month Security Gap Became a $5.7M Loss

Attackers exploited vulnerable Cosmos EVM software across six independent networks.

Timeline Event
Apr 25 Vulnerability reported to Cosmos bug bounty
May Fix merged after exploit could not be reproduced
Aug 19 Patched EVM versions released with limited details
~20 hrs First attack followed the release

What Was Exploited

  • Accounting flaw
  • Manipulated token balance
  • Vulnerable deployments

What Followed

  • 6 networks exploited
  • ~$5.7M stolen
  • Networks halted or patched

The Bigger Lesson

Finding a vulnerability is only the first step. Teams must assess its full impact and give affected networks enough time to respond.

Key Figures

$5.7M Stolen
6 Networks
20 hrs Attack window
40 Networks contacted

The April bug report vulnerability was indeed bigger than it appeared to be. The vulnerability involved an integer underflow in Cosmos EVM. Cosmos chains use this software framework to run Ethereum-compatible applications.

Cosmos EVM handled token balances in a way that hid the problem deep within its accounting system. Through this vulnerability, an attacker could create a specific type of account. It could later manipulate how the software calculated the amount of tokens that that account could spend. In simple terms, a calculation that may have stopped at zero instead wrapped around and produced an extremely large balance.

The attacker then used this fake balance in another transaction to interfere with another account’s balance. This could ultimately allow the attacker to take tokens from other accounts. The vulnerability exploited an accounting error, allowing the attacker to gain access to legitimate tokens held by other accounts.

Impacted Tokens Took A Brutal Hit

The cosmos hack resulted in impacting the tokens of the related chains. MANTRA’s OM token fell about 18.5% on August 20. The token dropped from $0.00506 to $0.00413. It recovered slightly post that, but the impact jittered the token.

TAC was already under pressure, after a separate 90% intra day drop in July. It had fallen to around $0.0063 at the time. KII also came under renewed scrutiny, after attackers drained 148M tokens from KiiChain during the August exploit.

The Problem Became Much Clear in August

The situation became quite clear in August, when independent research showed how this could impact Cosmos EVM chains more broadly than Cosmos Labs had initially believed.

Cosmos Labs later released patch updates on August 19. The release notes referred to important fixes, but they did not explain the specific vulnerability to network operators. The first attack, however, began around 20 hours after the patched versions were released.

For other networks running independent validators, this was a very short window to identify the issue, let alone run a test. Mantra later said that the 20-hour window was not enough to safely organize an upgrade across its validator network.

Another striking detail was that about 12 hours before the first theft, a developer had already publicly posted the details of the vulnerability and how it could be exploited. This ultimately gave potential attackers a detailed path to understand and exploit the flaw, contributing to the Cosmos hack that followed.

Cosmos Hack Hit Six Networks

Cosmos EVM Security Incident

Nearly $5.7M stolen across six chains

TOTAL STOLEN
~$5.7M
August 20–25, 2026
MANTRA
~$3.6M
~720.9M tokens
TAC
~3B
~1.2B sold for ~$950K
KII
~148M
64.6M sold for ~$1.6M
FUNDS CONVERTED DEXs: $2.87M CEXs: $2.85M
6 CHAINS ATTACKED
3 identified • 3 unnamed

The attackers ended up exploiting six networks between August 20 and August 25. Mantra suffered the largest publicly reported loss, worth around $3.6M. TAC lost nearly 3B TAC tokens. KiiChain ended up losing around 148M KII tokens in separate attacks. Cosmos Labs later estimated that the attackers may have moved $2.87M through decentralized exchanges and $2.85M through centralized ones.

This incident impacted networks running vulnerable versions of Cosmos EVM software and not one single Cosmos Labs network.

Also Read: Arbitrum Future: Can the Network Become More Than an Ethereum Scaling Solution?

The April Bug Report: What Went Wrong

The bigger question is not the recent Cosmos Hack, it’s the gap between discovering a vulnerability and understanding its impact in real time.

Cosmos Labs later shared that it contacted around 40 networks during the response. It later said that 13 potentially exposed chains that it worked with patched, halted, or otherwise protected themselves before the attackers reached them. The response also uncovered nearly 11 Cosmos EVM deployments that Cosmos Labs had not previously known about through its security channels.

The Conclusion

Cosmos Labs later acknowledged that its original assessment that live networks were unaffected was wrong. It has since been reviewing its security response and working with networks across the ecosystem following the attacks.

For the broader crypto ecosystem, the lesson is simple. Teams need to take every crypto bug report seriously, regardless of how small the impact may initially appear.. The Cosmos hack resulted in lessons surrounding how a vulnerability reported months earlier could end up becoming detrimental for users in the future.

Also Read: Robinhood Chain Tops Ethereum at $2.66M in Revenue as 5.52M Transactions Surge

Juhi Mirza

Written by Juhi Mirza

Juhi Mirza covers cryptocurrency, DeFi, blockchain, and on-chain markets, translating complex developments into clear, data-driven reporting.

Read Next