
Cosmos EVM Vulnerability Drained $5.7M Across Six Chains in August
Attackers exploited a critical Cosmos EVM bug between August 20 and 25 to steal nearly $6 million across MANTRA, TAC, KiiChain and three other networks. Cosmos Labs had identified the vulnerability but took four months to patch it, with the fix reaching release branches hours before the attacks began.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Vulnerability and Timeline
Comos Labs disclosed a critical Cosmos EVM vulnerability that attackers exploited across six blockchain networks between August 20 and August 25. Cosmos Labs had identified the flaw four months prior but the upstream fix did not reach release branches until hours before the incident occurred, according to CryptoSlate reporting. The timing raised questions about the lag between identification and deployment of security patches across networks running the shared codebase.
Stolen Assets and Recovery Status
Attackers converted stolen tokens into approximately $5.7 million to $6 million in assets through both decentralized and centralized exchanges, Cosmos Labs said. Affected networks included MANTRA, TAC, and KiiChain. According to MANTRA's statement cited in reports, none of the stolen tokens have been recovered to date. The attackers moved funds through multiple exchange channels, complicating recovery efforts.
Cross-Chain Attack Surface
The exploit demonstrated a coordinated attack across six distinct Cosmos-based chains rather than an isolated incident on a single network. This cross-chain scope underscores the shared vulnerability in the underlying Cosmos EVM implementation used by multiple independent blockchains. The incident highlights the timing risk when a security fix is deployed upstream but adoption by individual networks lags, creating a window where coordinated attackers can target multiple chains still running vulnerable code.
Why It Matters
For Traders
Tokens on affected chains face liquidity disruption and potential reputational pressure; monitor exchange listings and trading halts on MANTRA, TAC, and KiiChain over the next 48 hours.
For Investors
The four-month delay between bug identification and patch deployment reveals governance or coordination gaps in Cosmos ecosystem security practices, raising systemic risk questions for multi-chain validators.
For Builders
Teams deploying on Cosmos EVM forks must audit their upgrade adoption timelines; a gap between upstream patch and local deployment creates exploitability windows that attackers can weaponize across coordinated networks.
This article is for information only and is not financial advice. Read the full disclaimer.





