Attackers exploited a critical Cosmos EVM vulnerability across six blockchain networks from Aug. 20 to Aug. 25, converting stolen tokens into about $5.72 million through decentralized and centralized exchanges. Cosmos Labs received the bug report on April 25 but initially concluded that production networks were not exposed, leading developers to use a silent public patch rather than privately distribute a security fix. The flaw was later confirmed to affect all Cosmos EVM chains. MANTRA lost 720.9 million tokens valued at about $3.6 million, while TAC and KiiChain suffered separate attacks using the same method. Cosmos Labs coordinated with 40 networks and helped 13 patch or halt before they were attacked, but recommended vulnerable chains stop producing blocks only after MANTRA, TAC and KiiChain had been hit. The incident also exposed weaknesses in emergency coordination across Cosmos EVM’s validator-based networks, where state-breaking upgrades require testing and agreement among operators.