Cosmos EVM flaw exploited across six networks, including MANTRA

  • A Cosmos EVM accounting flaw was exploited across six networks, including MANTRA, TAC and KiiChain.
  • Attackers converted about $5.72 million through decentralized and centralized exchanges; MANTRA transfers totaled 720,923,967.99 tokens.
  • Cosmos Labs initially cleared the April-reported bug, but 13 other potentially exposed chains mitigated it before exploitation; MANTRA recovered no tokens as of Aug. 28.

A vulnerability in the Cosmos EVM module, an Ethereum-compatible software layer for Cosmos SDK chains, was exploited across six networks between Aug. 20 and Aug. 25 after Cosmos Labs initially concluded that only six-decimal deployments were at risk. Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues, with related CEX accounts frozen pending investigation. MANTRA, which first alerted the team, lost control of 720,923,967.99 previously inert tokens worth about $3.6 million, halted its chain after a second unauthorized debit and restarted with patched v8.4.0 following 30 hours and 13 minutes offline. The flaw had been reported on April 25 through a bug bounty program. As of Aug. 28, no tokens had been recovered, and Cosmos Labs said it was revising vulnerability triage and disclosure procedures after coordinating risk assessments and mitigations across about 40 chains.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.