πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
DeFi

Cosmos Labs Says It Misgraded the Bug Behind a $5.7M Six-Chain Hack

30 Aug 2026by CryptoJazz Admin1 min read6 views

Cosmos Labs published a postmortem on Friday saying it graded a critical bug as low risk in April, patched it quietly in May, and only established in August that every chain running its EVM software was exposed. Attackers took roughly $5.7 million off six networks between 20 and 25 August. The advisory is GHSA-7g4w-cg88-2cq2. No CVE has been assigned.

What the postmortem admits

The flaw is an arithmetic one. When a vesting account delegated more than its spendable balance, an unchecked subtraction wrapped the balance around to roughly 2^256, and the routine that reconciles the EVM state database against the Cosmos SDK bank module then minted or burned on the difference. Vesting accounts release funds on a schedule, and only chains that let anyone create one were exploitable. Cosmos Labs tested the report it received on 25 April and could not make it fire.

"We were unable to reproduce the vulnerability on 18-decimal networks and incorrectly concluded it affected only non-18-decimal networks," the postmortem said.

That grading decided everything after it. The firm's own bounty policy says a network-wide risk triggers private fix distribution before any public disclosure. Instead the fix went out as what Cosmos Labs calls a silent public patch, merged on 15 May, with a second commit five days later. Nothing was flagged.

Two clocks between the patch and the first theft

The patched releases, v0.6.2 and v0.7.2, went out on 19 August. Hours later a Push Chain developer filed a public code change that described the exploit. The first attack hit MANTRA on 20 August, and the halt that followed stopped the chain for about 30 hours. How much warning the networks had depends on which event starts the clock. The Hacker News measures 11 hours and 50 minutes from the release; The Block says about 20 hours; CryptoSlate counts about 12 hours from the moment the exploit became public. Coindoo carries both framings and is the only account that reconciles them.

MANTRA gave the operational answer. "Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators," the chain said in remarks carried by The Block. KiiChain's incident report made the same point about halts being faster than upgrades.

The losses do not add up the same way twice

Six chains, three named. MANTRA lost 720.9 million tokens, worth about $3.6 million before the incident, taken from a burn address and a legacy multisig. The other two named victims are counted two ways. The Block puts KiiChain's loss at about $1.6 million and TAC's at about $950,000, both measured as dollars the attackers realised through sales. Protos, writing on 25 August, values KiiChain's 150 million tokens at $9 million and TAC's 3 billion at about $7.5 million, which is what the tokens were worth before anyone sold. The Defiant counts 148 million KiiChain tokens and 2,985,651,403 TAC, about 62% of that chain's circulating supply. Nominal and realised are different measures.

The chain count moved as well. The Defiant reported three networks on 25 August and Protos four, naming Nesa as the fourth. The postmortem said six three days later, and three have never been named. Cosmos Labs said it contacted 40 networks and that 13 patched, halted or mitigated before anyone reached them. It also found 11 Cosmos EVM deployments it had not known existed.

What a registry would have changed

Cosmos Labs keeps no complete list of the chains running its software. Coindoo counts more than 115 public networks in the ecosystem. The private notification went out at 03:36 UTC on 21 August by The Hacker News's account; the recommendation to halt is dated 22 August by The Defiant and 24 August by Protos. Those are separate acts, and neither timeline settles the other. ZetaChain patched. Warden Protocol blocked vesting-account creation. Core Lightning, disclosing its own bugs the same week, held the details for fourteen days. As of 28 August no tokens had been recovered, and the firm said it would revise how it grades and discloses critical vulnerabilities. It has not said what the new threshold is.

Read also: Fogo Halts Its Mainnet After 400 Million Tokens Left Its Wallets

← All news