Cosmos EVM flaw exploited across six networks, affecting about 40 blockchains

  • Cosmos Labs disclosed exploitation of an accounting flaw across six Cosmos EVM networks.
  • Attackers converted about $5.72 million through decentralized and centralized exchange venues.
  • Cosmos Labs said 13 other potentially exposed chains mitigated the flaw before exploitation.

A Cosmos EVM (Ethereum-compatible software layer for Cosmos SDK chains) accounting vulnerability was exploited across six networks, including MANTRA, TAC and KiiChain, after Cosmos Labs initially determined it threatened only six-decimal deployments. Attackers converted about $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues; accounts linked to the centralized-exchange activity were frozen. The flaw affected a broader ecosystem of around 40 networks. Cosmos Labs said 13 potentially exposed chains patched, halted or applied mitigations before exploitation, while the response identified 11 previously unknown Cosmos EVM deployments. On MANTRA, an attacker made 720.9 million tokens transferable from a burn address and a legacy genesis-era multisig without compromising validator, administrator, governance or multisig keys or minting new tokens. The movement was valued at roughly $3.6 million before the incident, and about 38 million tokens remained immobilized as of Aug. 28. MANTRA halted its chain after a second unauthorized debit, causing an outage of about 30 hours, and the token later rebounded about 14% to roughly $0.004744 after reaching an all-time low. Cosmos Labs said it is revising vulnerability triage and disclosure procedures after the flaw reached production networks and triggered emergency action across the ecosystem.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.