
A critical Cosmos EVM vulnerability exploit resulted in the movement of $5.72 million worth of stolen tokens across six blockchain networks between August 20-25, according to Cosmos Labs. The vulnerability, first reported through Cosmos Labs' bug bounty program on April 25, 2025, involved an integer underflow that allowed attackers to inflate account balances by 2^256-1 base units and drain large accounts including burn addresses and multisignature wallets. The flaw had been initially assessed as not posing a risk to production networks, but independent researchers confirmed in early August that all Cosmos EVM chains were affected. Cosmos Labs released patched versions at 7:01 p.m. ET on August 19, but network operators were not given vulnerability-specific warnings about the critical security fix.
The attacker's final profit was severely impacted by market liquidity issues and slippage. As reported by multiple networks, the tokens moved through multiple addresses before being swapped for ETH on decentralized exchanges and routed to centralized platforms. However, liquidity disappeared from the pools before most of the selling occurred, resulting in extreme slippage that swallowed almost the entire position. The vulnerability allowed attackers to drain large accounts holding locked tokens, with no additional tokens created through the process - total token supply remained effectively unchanged. MANTRA suffered the largest publicly disclosed loss with 720.9 million MANTRA tokens worth about $3.6 million taken from two addresses, while TAC lost nearly 3 billion TAC from its staking pool and KiiChain lost approximately 148 million KII.
MANTRA suffered the most severe impact with 720.9 million MANTRA tokens worth about $3.6 million taken from two addresses - the network's burn address and a dormant multisignature wallet from an earlier incentive campaign. The attack remained undetected for almost four hours before MANTRA halted the network at 7:13 p.m. ET on August 20. About 38 million stolen MANTRA remained frozen in the attacker's wallet, but 94.7% of the stolen tokens had already been transferred to one centralized exchange through 15 transactions. The chain remained unable to process transactions for roughly 30 hours before validators deployed patched software and resumed block production. TAC was attacked on August 22, with nearly 3 billion TAC taken from the network's staking pool, of which around 1.2 billion were sold on BNB Chain for roughly $950,000. KiiChain reported losing approximately 148 million KII with 64.6 million sold for roughly $1.6 million, with Cosmos Labs estimating that around 54% of the stolen KII remains recoverable if the network is restored.
Cosmos Labs disclosed the incident on August 24 and advised affected chains to halt operations. According to the team's technical post-mortem, "Many affected chains have now patched. We continue to provide mitigation information to affected chains. Chains that use a Cosmos EVM version less than v0.6.2 or v0.7.2 are recommended to immediately halt the blockchain and upgrade it to include the patches in those releases." The incident prompted criticism of Cosmos Labs' vulnerability disclosure process, with KiiChain noting that affected networks were not notified beforehand and that the patch release was not initially identified as a critical security update. KiiChain specifically criticized the lack of advance notice, stating "A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes." The warning reportedly came after MANTRA, TAC and KiiChain had already been hit, with KiiChain disputing part of the technical assessment and claiming three upstream defects were needed to carry out the exploit.
Three further chains were exploited with the same method, though Cosmos Labs did not identify them in its report. Bubblemaps identified Nesa Chain as one of the affected networks, reporting that an attacker bought about $250,000 worth of NES, bridged it to Nesa, used the flaw to increase the balance about 200-fold, and transferred roughly $50 million in NES back to Ethereum. Most attempted swaps suffered extreme slippage as liquidity was removed from trading pools, leaving the attacker with about $60,000 in profit. The remaining two affected chains have not been publicly identified. Cosmos Labs coordinated with 40 networks during its response and worked with 13 others to patch the vulnerability or halt before they were attacked. The firm said it does not maintain a complete registry of the more than 115 public blockchains operating across the Cosmos ecosystem, with its response uncovering 11 Cosmos EVM deployments that had not previously been registered.