Cosmos EVM Bug Exposed to Hackers for Four Months
A critical bug in the Cosmos EVM (Ethereum Virtual Machine) ecosystem went unaddressed for four months before hackers stole nearly $6 million across six networks.
The vulnerability, which affected around 40 blockchains, was initially reported on April 25 but underestimated by Cosmos Labs. Engineers believed it only threatened 'six-decimal' networks, while production chains used '18 decimals,' so they treated it as a low-risk issue.
A fix was merged into the main codebase on May 15 and handled as a silent public patch rather than an emergency security release. However, it wasn't backported to older branches due to its state-breaking nature.
The bug combined two accounting failures: unsigned-integer underflow and overflow. An attacker could trigger this flaw to create an abnormally large balance and then extract the legitimate balance without increasing total token supply.
The first known unauthorized transaction on MANTRA occurred less than 12 hours after a public pull request described the vulnerability and exploitation path. The project suffered the largest publicly detailed hit, with an attacker moving about 720.9 million tokens from two addresses that hadn't authorized the transactions.