Cosmos Labs says a critical Cosmos EVM vulnerability reported through its bug bounty programme in April was wrongly cleared as safe for production, then exploited across six chains between August 20 and August 25, 2026. Attackers moved roughly $5.7 million through exchanges before a delayed patch reached the affected release branches.
Cosmos Labs has confirmed that testers wrongly concluded in April that a critical Cosmos EVM flaw did not affect production networks. Attackers proved that assessment wrong months later, exploiting the bug across six chains between August 20 and August 25, 2026.
Bug bounty report was cleared after testing
Cosmos Labs' bug bounty programme received the flaw on April 25, and the company said its testers initially concluded that production networks were not vulnerable. Because of that clearance, Cosmos Labs handled the fix through a silent patch process rather than a vulnerability-specific advisory, so a patch could reach networks without operators knowing it addressed an urgent exposure.
An unchecked balance subtraction sat in the smart contract stack
The defect sat in Cosmos EVM's StateDB, the Ethereum-compatible smart contract layer used by the affected networks. An unchecked subtraction could occur when a vesting account delegated more than its spendable balance, and instead of failing safely, the account balance wrapped to roughly 2^256 — an enormous figure that let attackers move funds from accounts that never authorized the transactions.
Backported releases arrived hours before the first attack
Cosmos EVM's main branch got the fix on May 15, but the backport to the v0.6.x and v0.7.x release branches did not land until August 19. Versions v0.6.2 and v0.7.2 were published at 23:01 UTC — roughly 20 hours before the first known attack. MANTRA said that window was not realistic for coordinating a state-breaking upgrade across its validator set, since that requires coordination among network operators rather than a routine update by a single company.
Roughly $5.7 million moved through exchanges
Across the six exploited networks, Cosmos Labs estimated that about $2.87 million moved through decentralized exchanges and $2.85 million through centralized venues, for a combined $5.72 million in identified exchange flows. MANTRA separately reported a token loss of 720,923,967.99 MANTRA, valued at about $3.6 million at the pre-incident price, and said no validator keys, administrator keys, governance controls or multisig signers were compromised.
For the operators running those chains, the relevant upgrade window was measured in hours.
Source: Crypto Daily™
Trading involves risk.