Cosmos EVM Vulnerability Exploited for $5.72 Million in Cross-Chain Attacks
A critical Cosmos EVM vulnerability was exploited across six blockchain networks between Aug. 20 and Aug. 25, resulting in the theft of over $5.72 million in assets.
The attackers targeted large accounts, including burn addresses and multisignature wallets, using an integer underflow in the Cosmos EVM framework to drain funds from MANTRA, TAC, and KiiChain networks.
Cosmos Labs first received a report of the vulnerability on April 25 but initially concluded that production networks were not at risk. However, independent researchers later confirmed that the flaw could affect production chains, prompting Cosmos Labs to release patched software on Aug. 19.
The patch was released without a specific advisory to network operators, giving them only about 20 hours to assess and implement the fix. MANTRA lost approximately $3.6 million in tokens, while TAC and KiiChain suffered separate attacks using the same method.