Cosmos Labs
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3smZo3…UZi5Summary
Cosmos Labs, the organization maintaining the shared Cosmos EVM module, received a responsible disclosure of a critical balance-underflow vulnerability on April 25, 2026, incorrectly assessed it as low-risk to production networks, and shipped a silent patch on August 19, 2026 without issuing a vulnerability advisory or privately notifying downstream chain operators. Between August 20 and August 25, 2026, attackers exploited the unpatched or unmitigated vulnerability across six Cosmos-based blockchains — including MANTRA, TAC, and KiiChain — converting approximately $5.72 million in stolen tokens through decentralized and centralized exchanges. Cosmos Labs acknowledged in an August 28 post-mortem that it had incorrectly cleared the bug as safe and that its coordinated-disclosure process was insufficient.
Connected Entities
1 entities- + 1 more
Timeline(12 events)
25 April 2026
Vulnerability reported through the Cosmos Immunefi bug bounty program. Cosmos Labs assessed it as posing no risk to production networks, concluding it affected only non-18-decimal configurations.
Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)13 May 2026
Pull request to harden StateDB balance subtraction against underflow opened publicly on the Cosmos EVM GitHub repository.
Protos15 May 2026
Fix merged to main branch as a silent patch with no vulnerability advisory and no private notification to downstream chain operators.
Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)28 July 2026
A security researcher published a detailed worked explanation of the flaw publicly.
Protos13 August 2026
Cosmos Labs confirmed that the vulnerability affected all Cosmos EVM chains regardless of decimal configuration, contradicting the April assessment. Public backports to supported v0.6.x and v0.7.x branches were opened.
Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)19 August 2026
Patched versions v0.6.2 and v0.7.2 released at approximately 7:01 PM ET with generic security language in release notes. No vulnerability-specific advisory issued; no advance private notification sent to chain operators.
The Hacker News20 August 2026
At 07:16 UTC, a Push Chain developer submitted a public pull request detailing the vulnerability and full exploitation path, identifying all vulnerable released tags. First attack against MANTRA began at 19:06 UTC, approximately 12 hours later.
Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)21 August 2026
MANTRA halted its chain at block 17,449,398, freezing transactions. Cosmos Labs sent its first urgent private email notification to known Cosmos EVM operators at 03:36 UTC — over eight hours after the first attack on MANTRA began.
The Hacker News22 August 2026
TAC halted at block 24,671,475 after an attacker drained approximately 2.99 billion TAC tokens (28.6% of total supply). KiiChain suffered 18 separate attacks, losing 148,326,583.15 KII. Cosmos Labs issued coordinated halt recommendation.
crypto.news22 August 2026
MANTRA chain restarted on patched release at 05:30 UTC, approximately 30 hours after halt, with no rollback and no change to user balances.
crypto.news25 August 2026
Exploitation window concluded. Six chains confirmed compromised. Total attacker proceeds approximately $5.72 million converted through exchanges.
Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)28 August 2026
Cosmos Labs published technical post-mortem acknowledging incorrect initial assessment, insufficient coordinated disclosure, and committing to process improvements.
Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)Decision Log
- hash: 4z5jWjC47Re1y3YWqnvbQs88M21m7xgzY6uxZwm85GBJ
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 14 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/11/2026, 11:59:33 PM
last updated: 9/11/2026, 11:59:43 PM
avoid.net — verified advice for a post-truth world