Mark RadarMARK RADAR
About
EN
Sign in

Cosmos EVM Flaw Fuels $5.7 Million Hack Across Six Chains

3 reports · First detected 2026-08-29 · Last active 2026-08-30

Cosmos EVM is shared software that allows Cosmos-based blockchains to run Ethereum-style applications, making an upstream defect a potential ecosystem-wide risk. The vulnerability was reported to Cosmos Labs on April 25, 2026, but testers wrongly concluded that live networks were not exposed. A fix was merged under a silent-patch process in May, while affected release branches did not receive the update until Aug. 19 and downstream operators were not given a vulnerability-specific warning.

Attackers exploited the flaw across six networks, including MANTRA, TAC and KiiChain, from Aug. 20 through Aug. 25, converting roughly $5.7 million of stolen tokens. MANTRA accounted for about $3.6 million of the losses, while tokens linked to affected chains fell as much as 96%. Cosmos Labs recommended halting networks on Aug. 22, after the three named chains had already been hit, and published its post-mortem on Aug. 28 acknowledging that it had incorrectly cleared the bug months earlier.

All Coverage

3 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)