📌 In April, Cosmos Labs deemed this vulnerability non-critical. However, attackers exploited it to siphon off $5.7 million from six blockchain networks.
– Cosmos Labs stated that from August 20 to 25, 2026, hackers exploited a vulnerability in Cosmos EVM, stealing approximately $5.7 million from six different blockchains.
A researcher reported this vulnerability back in April, but Cosmos Labs determined that live chains were secure and released a fix without public notification.
MANTRA suffered losses of approximately $3.6 million; funds were also stolen from TAC and KiiChain, and three other networks were attacked, though their names have not been disclosed.
Cosmos Labs announced that from August 20 to 25, 2026, attackers drained funds from six blockchain networks by exploiting a vulnerability in Cosmos EVM the common software that allows Cosmos blockchains to run Ethereum-style applications. The company detailed the theft in a technical report published on August 28. The attackers exchanged the stolen tokens for approximately $2.87 million on decentralized exchanges (DEXs) and approximately $2.85 million on centralized exchanges (CEXs), for a total of $5.7 million. Cosmos Labs reported that the accounts on centralized exchanges used by the attackers have been frozen pending the completion of the investigation by the relevant authorities.
According to the document, on April 25, 2026, a researcher reported this vulnerability through the Cosmos bug bounty program. Cosmos Labs stated that its testers were unable to reproduce the attack on the configurations used by active Cosmos chains and concluded that funds on these networks are secure. Therefore, the company implemented a fix as part of its quiet public patching procedure, rather than through a private distribution, which it uses in cases where it believes a vulnerability threatens users funds. Cosmos Labs noted that 37 vulnerabilities have been addressed in this manner over the past 13 months.
According to the investigation report, in early August, independent experts determined that this vulnerability affects all Cosmos EVM chains. Cosmos Labs then obfuscated the fix to prevent reverse engineering and released it on August 19 at 7:01 p.m. Eastern Time (ET) with release notes that mentioned only critical security fixes. The first attack began approximately 20 hours later, on August 20 at 3:06 p.m. Eastern Time. The MANTRA network, which was hit the hardest, stated that this was not enough time to take action. , “detected_source_language “: “EN
“”,”detected_source_language”:”RU
‘Twenty hours is an unrealistic timeframe for assessing, developing, testing, and coordinating an update that involves a state change across 38 independent validators, especially without official notification of a specific vulnerability.’ August 28, 2026
MANTRA, Attack Impact Analysis
MANTRA lost $3.6 million because its monitoring system failed to detect the theft
MANTRA lost 720.9 million tokens, worth approximately $3.6 million at the time; the funds were withdrawn from a token-burning address and an inactive multisig wallet left over from a previous incentive campaign. The alert did not trigger during the first transaction because the token burn address was considered static and was not being monitored by the blockchain. The theft went unnoticed for nearly four hours. On August 22, TAC lost nearly 3 billion tokens from its staking pool, of which about 1.2 billion were sold for approximately $950,000, while KiiChain lost about 148 million KII, of which 64.6 million were sold for approximately $1.6 million. Three other chains were attacked using the same method, although Cosmos Labs did not name them.
MANTRA is trading below one cent amid rising supply
At the time of publication, MANTRA was trading at around $0.0043, which is approximately 80% below its March 5, 2026, high of $0.022 (CoinPaprika, August 30, 2026). The tokens market capitalization stood at about $20 million. Its circulating supply increased by approximately 720.9 million tokens following the attack, as the depleted balanceswhich were previously considered inaccessible for spendinghave now become tradable.
KiiChain states that the suspension order came too late,detected_source_language:RU