WangDou logo
WangDou

A Known Bug Sat for Four Months: Cosmos EVM Flaw Drains Nearly $6M Across Six Chains

2026-08-29·WangDou AI Express·Web3 / Security / Cosmos

The most expensive thing on-chain has never been the bug in the code — it's the phrase "we thought it was fine."

Three Key Facts

On August 28, Cosmos Labs published a post-mortem: a balance-handling flaw (GHSA-7g4w-cg88-2cq2, rated Critical) in the shared Cosmos EVM module was exploited between August 20 and 25 to drain funds from six blockchains, with the total estimated by multiple outlets at roughly $6 million. The bug lives in the code reconciling EVM state with the Cosmos SDK's x/bank module: an unchecked subtraction can wrap a balance to roughly 2^256, letting an attacker mint value or burn a victim's real holdings.

The most damning part is the timeline. The flaw was reported through the bug-bounty program on April 25. Because the team couldn't reproduce it on 18-decimal networks, they "incorrectly concluded that it affected only non-18-decimal networks" and judged it posed no risk to live funds. Only on August 13 did they confirm every Cosmos EVM chain was affected — yet on August 19 the fix still went through the public silent-patch process reserved for issues that don't cause fund loss, instead of the private distribution their own policy mandates for threats to user funds.

MANTRA Chain was hit first: around 19:06 UTC on August 20, an attacker moved 600 million tokens from a burn address and another 120.9 million from a legacy multisig, about $3.6 million in total. The chain halted for roughly 30 hours and resumed on August 22 after patching. TAC and KiiChain were also attacked inside the window. Cosmos Labs told affected chains to upgrade immediately to v0.6.2 / v0.7.2 — or halt outright.

WangDou's Take

What should keep chain builders up at night isn't the $6 million — it's those four months. The bug arrived at the front door in late April; the team signed themselves a liability waiver called "couldn't reproduce it," then processed a funds-at-risk flaw through the "no risk" pipeline at a leisurely pace. The cruelty of on-chain is that attackers don't wait for your post-mortem meeting: you confirmed every chain was exposed on August 13, and money started flowing out on August 20. Routing a vulnerability that threatens user funds into the silent-patch process designed for vulnerabilities that don't isn't a technical slip — it's a process co-signing negligence. Security response is measured in working days between "reported" and "stopped bleeding"; the longer the gap, the bigger the bill. This time it was $6 million. Next time it could be an entire chain's trust.

Source: The Hacker News, CryptoSlate

Comments

Log in to comment
    This briefing was auto-written by WangDou AI Express for reference only; corrections welcome if you spot a factual error.
    指挥舱👽