• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
MiCA breach

Iceland’s 52.8% no vote keeps crypto industry outside MiCA rules

08/31/2026
Cross chain attacks

Cosmos EVM bug drains MANTRA, TAC and KiiChain for $5.72 million

08/31/2026
Kalshi IPO

Kalshi becomes US Open’s exclusive partner, bars rivals from ESPN ads

08/31/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
MiCA breach

Iceland’s 52.8% no vote keeps crypto industry outside MiCA rules

08/31/2026
Cross chain attacks

Cosmos EVM bug drains MANTRA, TAC and KiiChain for $5.72 million

08/31/2026
Kalshi IPO

Kalshi becomes US Open’s exclusive partner, bars rivals from ESPN ads

08/31/2026
Monday, August 31, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Breaking News

Cosmos EVM bug drains MANTRA, TAC and KiiChain for $5.72 million

A critical balance-accounting bug in shared Cosmos EVM software gave attackers a narrow window to target major token reserves before operators could coordinate emergency upgrades.

by Elizabeth Omotoke
2 hours ago
in Breaking News
Reading Time: 5 mins read
0
Cross chain attacks

Cross chain attacks

Share on FacebookShare on Twitter

A critical Cosmos EVM vulnerability let attackers drain roughly $5.72 million from six blockchain networks between August 20 and 25, according to a Cosmos Labs post-mortem, with MANTRA, TAC and KiiChain suffering the largest publicly disclosed losses.

About $2.87 million was exchanged through decentralized exchanges, while another $2.85 million was sold through centralized exchanges, according to the company’s Aug. 28 post-mortem.

The incident has put the security of shared blockchain infrastructure under renewed scrutiny. Unlike an attack targeting a single protocol, the Cosmos EVM vulnerability affected multiple independent networks using the same underlying software.

The largest publicly disclosed loss came from MANTRA, which reported that 720.9 million MANTRA tokens, worth roughly $3.6 million at the time, were moved without authorization from two addresses.

A bug reported months before the attacks

The roots of the Cross chain attacks stretch back to April, when the vulnerability was reported through Cosmos’ bug bounty program.

According to Cosmos Labs, the original testing team could not reproduce the exploit against configurations used by known production Cosmos EVM networks. The team therefore concluded that live user funds were not exposed and handled the fix through its silent public patch process.

That assessment was later overturned.

Independent researchers demonstrated in early August that the vulnerability could affect production Cosmos EVM networks. Cosmos Labs subsequently prepared patched releases and published versions 0.6.2 and 0.7.2 on Aug. 19.

The problem was that network operators were not given a vulnerability-specific warning explaining the severity or nature of the issue.

The first known attack began at 19:06 UTC on Aug. 20, roughly 20 hours after the patched software became available. Cosmos Labs later described the public disclosure of an exploitation path by a downstream developer as unusual because it could increase the likelihood of an attack.

MANTRA argued that the available window was inadequate for a coordinated upgrade involving dozens of validators.

“Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators,” MANTRA said in its post-mortem.

The timing became one of the most contentious parts of the incident, highlighting the difficulty of securing decentralized networks that must coordinate upgrades across independent validator groups.

The vulnerability created an artificial mega-balance

At the center of the Cross chain attacks was an integer-underflow bug in Cosmos EVM’s account-balance accounting.

The vulnerability involved a mismatch between how Cosmos EVM tracked spendable balances and how the underlying Cosmos SDK handled vesting and locked tokens. An attacker could use a vesting account to delegate more tokens than its spendable balance.

That caused the EVM StateDB to subtract an excessive amount from the spendable balance. Because the calculation lacked an appropriate underflow check, the resulting balance wrapped around to approximately 2²⁵⁶ — effectively producing an enormous artificial balance.

The attacker could then use that inflated balance to manipulate another account’s balance through a second arithmetic overflow.

Cosmos Labs stressed that the exploit did not actually create new tokens. Instead, it manipulated the accounting system so that existing tokens held by targeted accounts could be transferred to the attacker. MANTRA similarly said the incident altered its reported supply by only one base unit.

The affected versions were Cosmos EVM releases earlier than v0.6.2 and releases from v0.7.0 up to, but not including, v0.7.2. The patched versions are v0.6.2 and v0.7.2.

MANTRA, TAC and KiiChain take the biggest hits

MANTRA became the first major victim of the Cross chain attacks, losing 720,923,967.99 MANTRA from two addresses, according to its incident report.

Approximately 600 million tokens came from the chain’s burn address, while another 120.9 million came from a dormant multisignature wallet associated with an earlier incentive campaign.

MANTRA’s monitoring system did not immediately flag transfers from the burn address because it had been classified as an address that could not move funds. That gave the attacker additional time before the network detected the theft.

MANTRA halted its chain on Aug. 20 and remained offline for roughly 30 hours. Validators subsequently installed patched software and restarted block production without rolling back the chain or changing user balances.

The attack did not end there.

On Aug. 22, attackers used the same technique against TAC, draining nearly 3 billion TAC from its staking pool. Approximately 1.2 billion tokens were subsequently sold on BNB Chain for about $950,000, according to Cosmos Labs.

KiiChain was also targeted that day, losing roughly 148 million KII. Around 64.6 million KII was sold for approximately $1.6 million. Cosmos Labs estimated that about 54% of the stolen KII remained potentially recoverable onchain if the network could be restored.

KiiChain criticized the communication process, arguing that operators needed an immediate halt instruction rather than simply a software patch.

“A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes,” KiiChain wrote in its post-mortem.

Six networks affected as Cosmos reviews security response

The broader Cross chain attacks affected six networks, although Cosmos Labs has not publicly identified all of them.

Nesa has been linked to the incident by blockchain analytics firm Bubblemaps, which said an attacker manipulated NES balances and moved a much larger amount back to Ethereum. However, Cosmos Labs did not name Nesa in its official post-mortem, so the connection remains based on independent analysis rather than a direct confirmation from Cosmos Labs.

The scale of the incident also exposed a visibility problem inside the ecosystem.

Cosmos Labs said it coordinated with 40 chains during the response and helped 13 networks patch or halt before attackers could reach them. The team also discovered 11 Cosmos EVM deployments that had not previously been registered with it.

That is significant because Cosmos Labs said it does not maintain a complete registry of more than 115 public blockchains operating across the broader Cosmos ecosystem.

The episode therefore raises a difficult question for developers using shared blockchain infrastructure: how quickly can a critical vulnerability be communicated, tested and contained when every network has its own validators, governance procedures and upgrade schedule?

The immediate financial damage from the Cross chain attacks is estimated at about $5.72 million, but the larger cost could be measured in confidence.

Cosmos Labs has now released the technical details of the vulnerability and the patched versions. The incident is likely to become a reference point for how blockchain ecosystems handle coordinated disclosure — particularly when a single software component can expose multiple sovereign networks at once.

For MANTRA, TAC, KiiChain and the other affected chains, the priority is recovery and strengthening monitoring. For the wider Cosmos ecosystem, the bigger challenge is ensuring that the next critical bug is communicated before attackers get a 20-hour head start.

Tags: $140 million crypto hackBlockchain SecurityBrazil central bankBrazil crypto regulationC&M Software hackcrypto crimecrypto fraudcrypto launderingcrypto monitoringcrypto threat alert systemCryptocurrency Newscryptocurrency securitydigital assetsfinancial cyberattack
Share198Tweet124
Elizabeth Omotoke

Elizabeth Omotoke

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
MiCA breach

Iceland’s 52.8% no vote keeps crypto industry outside MiCA rules

08/31/2026
Cross chain attacks

Cosmos EVM bug drains MANTRA, TAC and KiiChain for $5.72 million

08/31/2026
Kalshi IPO

Kalshi becomes US Open’s exclusive partner, bars rivals from ESPN ads

08/31/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.