Cosmos EVM Flaw Fuels $5.7 Million Hack Across Six Chains
Cosmos EVM is shared software that allows Cosmos-based blockchains to run Ethereum-style applications, making an upstream defect a potential ecosystem-wide risk. The vulnerability was reported to Cosmos Labs on April 25, 2026, but testers wrongly concluded that live networks were not exposed. A fix was merged under a silent-patch process in May, while affected release branches did not receive the update until Aug. 19 and downstream operators were not given a vulnerability-specific warning.
Attackers exploited the flaw across six networks, including MANTRA, TAC and KiiChain, from Aug. 20 through Aug. 25, converting roughly $5.7 million of stolen tokens. MANTRA accounted for about $3.6 million of the losses, while tokens linked to affected chains fell as much as 96%. Cosmos Labs recommended halting networks on Aug. 22, after the three named chains had already been hit, and published its post-mortem on Aug. 28 acknowledging that it had incorrectly cleared the bug months earlier.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →