Newsroom

Cosmos Labs Admits Error in Clearing EVM Bug Linked to $5.7 Million Multi-Chain Exploit

30 August, 2026   /   News   /  AI   /   Tags:  cosmos, mantra, vulnerability, labs, networks

Cosmos Labs Admits Error in Clearing EVM Bug Linked to $5.7 Million Multi-Chain Exploit

A vulnerability reported in April was deemed non-threatening to live networks, allowing attackers to drain funds from six blockchains in late August after a delayed patch release

Cosmos Labs has acknowledged that it incorrectly assessed a critical vulnerability in its Ethereum-compatible software stack, known as Cosmos EVM. The flaw, reported through the project's bug bounty program on April 25, 2026, was initially judged not to affect production networks. Attackers later exploited it across six chains between August 20 and August 25, moving approximately $5.7 million through exchanges.

According to the project's post-mortem, the activity involved about $2.87 million via decentralized exchanges and $2.85 million through centralised platforms. The incident revealed a significant gap between the initial report and the distribution of fixes to the affected software branches.

Initial Assessment and Silent Patching

Engineers reviewing the April report concluded that the issue applied only to configurations different from those running on live blockchains. Based on this evaluation, Cosmos Labs applied a silent fix rather than issuing a public vulnerability advisory. The correction reached the main branch of Cosmos EVM on May 15.

The vulnerability involved an unchecked subtraction in the StateDB component. When a vesting account delegated more tokens than its available spendable balance, the operation could underflow. Instead of failing, the balance wrapped around to an extremely large value near 2 to the power of 256. This allowed unauthorized transfers from affected accounts without requiring administrative privileges or compromised keys.

No new tokens were created. The total supply on the impacted networks remained largely unchanged, with funds moved from specific addresses, including dormant wallets and burn addresses in some cases.

Delayed Backports and Narrow Response Window

The fix for the release branches used by production networks arrived much later. Versions 0.6.2 and 0.7.2 were published on August 19 at 23:01 UTC. This left roughly 20 hours before the first recorded attack. The releases did not include a clear advisory describing the severity of the underlying problem.

Operators of affected chains, including MANTRA, noted that the timeframe was insufficient to coordinate a state-breaking upgrade across independent validator sets. Such updates require testing and consensus rather than a simple software change by a single entity. MANTRA reported losses of approximately 720.9 million MANTRA tokens, valued at about $3.6 million based on pre-incident prices. The chain confirmed that no validator keys, administrator credentials, or governance controls were compromised.

Key timeline elements include the April 25 report, May 15 main-branch fix, August 19 release-branch patches, and attacks spanning August 20 to 25.

In early August, further examination showed the original risk assessment had been incomplete. The vulnerability affected a broader set of live configurations than initially believed, prompting the rushed backport. During the response, Cosmos Labs also found that it lacked a full inventory of networks running its software, identifying at least 11 chains previously unknown to the team.

Shared Software and Coordination Challenges

The episode illustrates difficulties inherent in ecosystems where many independent blockchains rely on common code. While the shared framework enables rapid deployment of new networks, updates must still be applied separately by each chain's operators. There is no centralized mechanism for urgent, simultaneous patching across all instances.

Cosmos Labs stated that production testing had led it to clear the bug for live environments, an evaluation later proven incorrect by the successful exploits. Affected networks raised concerns about the absence of explicit warnings and the limited time available after the patched versions appeared. Some suggested that a temporary halt of block production could have limited the damage, though such a step would have required rapid coordination among disparate teams.

The combined losses across the six chains stand at roughly $5.72 million in exchange flows identified by the post-mortem. Individual chain impacts varied, with the largest single reported token movement occurring on MANTRA. The software vulnerability itself, rather than any breach of private keys or governance systems, enabled the transfers.

Cosmos Labs has published details of the balance-underflow issue and the sequence of events in its security communications. The case has drawn attention to the processes for evaluating, patching, and communicating risks in multi-chain environments that depend on shared components.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.