The exploit leveraged a flaw in the Ethereum-compatible framework built from the Evmos codebase. By manipulating account balances through token delegation and subtraction, attackers pushed recorded values past the 2^256-1 numerical ceiling. This caused the balance to wrap around, granting the attacker control over assets held in target accounts, including burn addresses and dormant multisignature wallets.
Cosmos Labs first received a report regarding the vulnerability on April 25 but initially concluded that production networks were safe, opting for a silent patch process in May without notifying operators. Following independent research in August, the team released a fix on Aug. 19. However, the lack of a specific security advisory left network operators with only 20 hours to coordinate complex upgrades across distributed validator sets. MANTRA, the hardest-hit network, lost 720.9 million tokens worth roughly $3.6 million, while TAC and KiiChain suffered losses of $950,000 and $1.6 million, respectively.
Downstream projects criticized the communication strategy, noting that a coordinated halt would have been more effective than a rapid, unannounced patch. While Cosmos Labs coordinated with 40 chains to mitigate further damage, the incident highlights the difficulty of managing security across the fragmented Cosmos ecosystem. As of late August, most stolen funds remained unrecovered, and three additional networks affected by the same method have yet to be publicly identified.

Comments (0)
No comments yet. Be the first!