← Cosmos Labs1 decision on this page
Audit log
Every state-changing event for Cosmos Labs: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-11 23:59:43ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 446,287,782
- sig
3smZo3V87DiA…nn2TUZi5explorer ↗- hash
4z5jWjC47Re1…Zwm85GBJsha256 → base58
verifying row…full verify ↗canonical bytes (25973 B) ▸
{"actor":"system:backfill","investigation_id":"7ad7b19a-7be0-4fed-b711-e3168a3adbf2","kind":"publish","page_slug":"cosmos-labs","published_at":"2026-09-11T23:59:43.418Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Cosmos Labs","sections":[{"content":"The vulnerability, designated GHSA-7g4w-cg88-2cq2 and rated Critical by Cosmos Labs, resided in the shared Cosmos EVM module used by multiple independent blockchains. The exploit chained two distinct integer-arithmetic flaws. First, a staking precompile underflow: when a vesting account delegated an amount greater than its spendable balance through the staking precompile, an unchecked subtraction in the EVM StateDB's SubBalance function caused the account's balance to wrap to approximately 2^256 (the unsigned integer maximum). Second, the attacker then used that artificially inflated balance to overflow a victim account's balance, draining legitimate tokens without creating new supply. The root cause was a tracking mismatch between the EVM StateDB, which monitored only spendable tokens, and the Cosmos SDK ledger, which also tracked locked vesting tokens that could be delegated. To execute the attack, the attacker precomputed the address a malicious contract would deploy to, converted that address to a vesting account before deployment, then deployed the contract so it inherited vesting status. Delegating one wei more than the spendable balance triggered the underflow cascade. On KiiChain alone this technique was repeated across 18 separate target wallets in a single incident.","heading":"The Vulnerability: Technical Description","severity":"critical","sources":[{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"Rekt News: KiiChain Rekt","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"CryptoSlate: TAC frozen for over 10 days after exploit forces 1.26 billion token bailout","type":"news_article","url":"https://cryptoslate.com/tac-remains-frozen-for-over-10-days-after-a-massive-exploit-forces-a-1-26-billion-token-bailout/"}]},{"content":"On April 25, 2026, a researcher reported the vulnerability through the Cosmos Immunefi bug bounty program. Cosmos Labs assessed it and concluded it posed no risk to production networks, stating they were unable to reproduce fund loss on 18-decimal networks — the actual decimal configuration used by production Cosmos EVM chains — and incorrectly concluded the flaw only affected non-18-decimal deployments. A fix was quietly merged to the main branch on May 15, 2026, with a pull request description noting it guarded StateDB balance subtraction against underflow, but no vulnerability advisory was published and no private notification was sent to downstream chain operators at that time. In early August 2026, independent researchers demonstrated that the vulnerability affected all Cosmos EVM chains regardless of decimal configuration. Cosmos Labs confirmed this on August 13, 2026. Patched versions v0.6.2 and v0.7.2 were released on August 19, 2026 at approximately 7:01 PM ET, accompanied only by generic security language in the release notes and no chain-specific advisory. Cosmos Labs' own bug bounty policy stated that when an issue presents an immediate or network-wide risk, the organization will initiate emergency mitigations, private fix distribution, or coordinated upgrades before any public disclosure occurs. According to The Hacker News, this protocol was not followed after August 13, when Cosmos Labs had confirmed the broader scope. On August 20, 2026 at 07:16 UTC — approximately 12 hours before the first attack — a developer at Push Chain, a downstream fork, submitted a public pull request (pushchain/push-chain-evm#40) that described the vulnerability and its full exploitation path in detail, identified all vulnerable released tags, and attributed the finding to an independent Hacken audit. Cosmos Labs had not issued any halt recommendation or emergency advisory by that point. The first private notification to known Cosmos EVM operators was sent at 03:36 UTC on August 21 — more than eight hours after the first attack on MANTRA began. MANTRA stated publicly that twenty hours was not a realistic window in which to assess, build, test, and coordinate a state-breaking upgrade across its validators without specific vulnerability information. KiiChain's post-mortem explicitly stated that Cosmos Labs published a security fix before giving affected chains timely private notice. Cosmos Labs later acknowledged it discovered 11 previously unregistered Cosmos EVM deployments during its post-exploitation outreach, indicating it did not have a complete registry of downstream operators.","heading":"Disclosure Timeline and Process Failures","severity":"critical","sources":[{"credibility":1,"name":"The Hacker News: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable","type":"news_article","url":"https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html"},{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"Coinpaprika: Cosmos Labs Cleared a Bug in April. Attackers Used It to Drain $5.7M From Six Chains.","type":"news_article","url":"https://coinpaprika.com/news/cosmos-labs-bug-drains-six-chains-57m/"},{"credibility":2,"name":"Protos: Cosmos Labs under fire over disclosure of bug affecting four blockchains","type":"news_article","url":"https://protos.com/cosmos-labs-under-fire-over-disclosure-of-bug-affecting-four-blockchains/"},{"credibility":2,"name":"Rekt News: KiiChain Rekt","type":"research","url":"https://rekt.news/kiichain-rekt"}]},{"content":"Six blockchains were exploited between August 20 and August 25, 2026. Three have been named publicly: MANTRA, TAC, and KiiChain. Three additional chains have not been publicly identified as of the August 28 post-mortem. Cosmos Labs' post-mortem confirmed total attacker proceeds of approximately $5.72 million: approximately $2.87 million converted through decentralized exchanges and approximately $2.85 million sold through centralized exchanges, based on August 19 token prices. Centralized exchange accounts holding attacker funds were frozen pending investigation. MANTRA lost 720.9 million OM tokens then valued at approximately $3.6 million. The MANTRA team halted the chain at block 17,449,398 and restarted approximately 30 hours later on the patched release at 05:30 UTC on August 22, with no rollback and no change to user balances. MANTRA's OM token declined approximately 18% to a record low following news of the exploit, according to CoinDesk. TAC's chain was halted at block 24,671,475 on August 22 and remained frozen for over 10 days. Approximately 2.99 billion TAC tokens representing 28.6% of total supply were drained from the bonded staking pool. The TAC Foundation pledged to replace 1.26 billion TAC from treasury reserves to cover tokens sold off the network; approximately 1.66 billion TAC remained in attacker-controlled addresses on BNB Chain as of reporting. KiiChain reported 148,326,583.15 KII drained across 18 separate attacks on August 22. Approximately 80.7 million KII (54.4%) was frozen when the network halted; approximately 67.6 million KII (45.6%) had already been bridged to BNB Chain. The attacker realized roughly $1.6 million from DEX sales. Nominal token valuations cited in some reports — including figures such as $7.5 million or $9 million for individual chains — reflect face value at higher pre-exploit prices; the Cosmos Labs post-mortem's verified realized figure across all six chains is approximately $5.72 million.","heading":"Affected Chains and Financial Losses","severity":"critical","sources":[{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":1,"name":"The Block: Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-29-cosmos-labs-says-it-wrongly-cleared-the-bug-behind-a-5-7-million-six-chain-hack-413061"},{"credibility":2,"name":"CryptoSlate: TAC frozen for over 10 days after exploit forces 1.26 billion token bailout","type":"news_article","url":"https://cryptoslate.com/tac-remains-frozen-for-over-10-days-after-a-massive-exploit-forces-a-1-26-billion-token-bailout/"},{"credibility":1,"name":"CoinDesk: MANTRA token plunges 18% to record low as blockchain halts after exploit","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit"},{"credibility":2,"name":"Rekt News: KiiChain Rekt","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"crypto.news: Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"}]},{"content":"The Hacker News reported that Cosmos Labs released patches for 37 vulnerabilities silently in the 13 months preceding this incident, without downstream developers being given descriptions of exploit paths in public. For the GHSA-7g4w-cg88-2cq2 vulnerability specifically, the May 15 merge commit and its pull request description plainly stated it guarded StateDB balance subtraction against underflow, making the change readable on the public GitHub repository to anyone monitoring commits. However, no advisory was published, no CVE-equivalent was filed publicly, and no private notification was sent to known Cosmos EVM chain operators at the time of the May 2026 fix. The August 19 patch release repeated this pattern: release notes contained generic security language urging upgrade but provided no vulnerability-specific advisory, no GHSA identifier in communications to operators, and no recommendation to halt networks while patching. Security critics characterized this practice as a breach of responsible coordinated disclosure for shared infrastructure serving multiple independent production networks. Cosmos Labs acknowledged in its post-mortem that its silent patching process was inappropriate given the public availability of the code, and committed to defining public standards for when to recommend network halts versus coordinated upgrades.","heading":"The Silent Patch Pattern","severity":"high","sources":[{"credibility":1,"name":"The Hacker News: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable","type":"news_article","url":"https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html"},{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"Protos: Cosmos Labs under fire over disclosure of bug affecting four blockchains","type":"news_article","url":"https://protos.com/cosmos-labs-under-fire-over-disclosure-of-bug-affecting-four-blockchains/"}]},{"content":"Cosmos Labs published a post-mortem on August 28, 2026. The organization acknowledged that its April assessment of the vulnerability was incorrect, stating it was unable to reproduce fund loss against 18-decimal configurations and incorrectly concluded the risk was limited to non-18-decimal networks. It further acknowledged that when independent researchers confirmed in early August that all Cosmos EVM chains were affected regardless of decimal configuration, it did not initiate emergency coordinated-disclosure outreach to downstream operators. The post-mortem identified four specific process failures: insufficient vulnerability scope assessment; over-reliance on initial testing against limited configurations; inadequate communication infrastructure, including the existence of at least 11 unregistered Cosmos EVM deployments across an ecosystem of 115+ known public blockchains; and silent patching as a process inappropriate for widely-deployed shared infrastructure. The organization's own stated bug bounty policy — that immediate or network-wide risks would trigger private fix distribution and coordinated upgrades before public disclosure — was not followed after the scope was confirmed as network-wide on August 13. Remediation commitments included developing more robust approaches for assessing vulnerability scope, expanding the coordinated vulnerability disclosure channel registry, establishing regular responsiveness health checks, defining public standards for halt-versus-upgrade decisions, and conducting a comprehensive operational security audit with external partners.","heading":"Cosmos Labs' Admissions and Post-Mortem","severity":"high","sources":[{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":2,"name":"ForkLog: Cosmos Labs Admits Error Following Attacks on Six Blockchains","type":"news_article","url":"https://forklog.com/en/cosmos-labs-admits-error-following-attacks-on-six-blockchains/"},{"credibility":1,"name":"The Block: Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-29-cosmos-labs-says-it-wrongly-cleared-the-bug-behind-a-5-7-million-six-chain-hack-413061"}]},{"content":"The disclosure was publicly characterized as 'negligent AF' by critics on social media platforms following the incident. The Hacker News, a major cybersecurity publication, published a detailed article framing the incident around Cosmos Labs' knowledge that all chains were vulnerable prior to exploitation. Protos reported that developers and security researchers expressed broad backlash over the silent patch model and the absence of advance private notification. KiiChain's post-mortem explicitly blamed Cosmos Labs' disclosure process, noting that the halt recommendation came after attacks had already compromised three blockchains. MANTRA's public statement that twenty hours was insufficient to coordinate a state-breaking upgrade without specific vulnerability information received significant attention. Security commentators noted that the public availability of a detailed exploit path in a Push Chain developer's pull request — published roughly twelve hours before the first attack — made immediate coordinated notification to all downstream operators essential, and that Cosmos Labs did not provide such notification until after exploitation had begun.","heading":"Industry and Researcher Criticism","severity":"high","sources":[{"credibility":1,"name":"The Hacker News: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable","type":"news_article","url":"https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html"},{"credibility":2,"name":"Protos: Cosmos Labs under fire over disclosure of bug affecting four blockchains","type":"news_article","url":"https://protos.com/cosmos-labs-under-fire-over-disclosure-of-bug-affecting-four-blockchains/"},{"credibility":2,"name":"Rekt News: KiiChain Rekt","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"Crowdfund Insider: Cosmos Labs Flags Ongoing Security Issue In Shared EVM Module, Advising Network Halts","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/301350-cosmos-labs-flags-ongoing-security-issue-in-shared-evm-module-advising-network-halts/"}]},{"content":"Cosmos Labs released patched versions v0.6.2 and v0.7.2 on August 19, 2026. As of the August 28 post-mortem, operators running any prior version of the Cosmos EVM module were advised to upgrade to v0.6.2 or v0.7.2 or later. The patch is state-breaking and requires application as a coordinated network upgrade rather than a simple node software swap. Cosmos Labs coordinated outreach to approximately 40 known Cosmos EVM networks following the onset of exploitation, and helped 13 of those networks patch or halt before attacks reached them. The advisory GHSA-7g4w-cg88-2cq2 was published to the GitHub Security Advisories database. Centralized exchange accounts identified as holding attacker funds were frozen as part of the response.","heading":"Remediation and Recommended Upgrades","severity":"medium","sources":[{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":1,"name":"GitHub Security Advisory: ASA-2026-002 / GHSA-54gx-3cgr-7mfm","type":"official","url":"https://github.com/cosmos/evm/security/advisories/GHSA-54gx-3cgr-7mfm"},{"credibility":2,"name":"crypto.news: Cosmos EVM chains told to halt after security incident","type":"news_article","url":"https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-incident/"}]}],"sources_used":[{"credibility":1,"name":"Cosmos Security: GHSA-7g4w-cg88-2cq2 Post-Mortem","type":"official","url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"credibility":1,"name":"The Hacker News: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable","type":"news_article","url":"https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html"},{"credibility":1,"name":"The Block: Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-29-cosmos-labs-says-it-wrongly-cleared-the-bug-behind-a-5-7-million-six-chain-hack-413061"},{"credibility":1,"name":"CoinDesk: MANTRA token plunges 18% to record low as blockchain halts after exploit","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit"},{"credibility":1,"name":"GitHub Security Advisory: ASA-2026-002 / GHSA-54gx-3cgr-7mfm","type":"official","url":"https://github.com/cosmos/evm/security/advisories/GHSA-54gx-3cgr-7mfm"},{"credibility":2,"name":"Rekt News: KiiChain Rekt","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"Protos: Cosmos Labs under fire over disclosure of bug affecting four blockchains","type":"news_article","url":"https://protos.com/cosmos-labs-under-fire-over-disclosure-of-bug-affecting-four-blockchains/"},{"credibility":2,"name":"crypto.news: Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"credibility":2,"name":"CryptoSlate: TAC frozen for over 10 days after exploit forces 1.26 billion token bailout","type":"news_article","url":"https://cryptoslate.com/tac-remains-frozen-for-over-10-days-after-a-massive-exploit-forces-a-1-26-billion-token-bailout/"},{"credibility":2,"name":"ForkLog: Cosmos Labs Admits Error Following Attacks on Six Blockchains","type":"news_article","url":"https://forklog.com/en/cosmos-labs-admits-error-following-attacks-on-six-blockchains/"},{"credibility":2,"name":"The Defiant: Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks","type":"news_article","url":"https://thedefiant.io/news/blockchains/cosmos-labs-urges-evm-chains-halt-shared-bug-drains-three-networks"},{"credibility":2,"name":"Crowdfund Insider: Cosmos Labs Flags Ongoing Security Issue In Shared EVM Module, Advising Network Halts","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/301350-cosmos-labs-flags-ongoing-security-issue-in-shared-evm-module-advising-network-halts/"},{"credibility":2,"name":"Coinpaprika: Cosmos Labs Cleared a Bug in April. Attackers Used It to Drain $5.7M From Six Chains.","type":"news_article","url":"https://coinpaprika.com/news/cosmos-labs-bug-drains-six-chains-57m/"},{"credibility":2,"name":"crypto.news: Cosmos EVM chains told to halt after security incident","type":"news_article","url":"https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-issue/"}],"summary":"Cosmos Labs, the organization maintaining the shared Cosmos EVM module, received a responsible disclosure of a critical balance-underflow vulnerability on April 25, 2026, incorrectly assessed it as low-risk to production networks, and shipped a silent patch on August 19, 2026 without issuing a vulnerability advisory or privately notifying downstream chain operators. Between August 20 and August 25, 2026, attackers exploited the unpatched or unmitigated vulnerability across six Cosmos-based blockchains — including MANTRA, TAC, and KiiChain — converting approximately $5.72 million in stolen tokens through decentralized and centralized exchanges. Cosmos Labs acknowledged in an August 28 post-mortem that it had incorrectly cleared the bug as safe and that its coordinated-disclosure process was insufficient.","timeline":[{"date":"2026-04-25","event":"Vulnerability reported through the Cosmos Immunefi bug bounty program. Cosmos Labs assessed it as posing no risk to production networks, concluding it affected only non-18-decimal configurations.","source":"Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-05-13","event":"Pull request to harden StateDB balance subtraction against underflow opened publicly on the Cosmos EVM GitHub repository.","source":"Protos","source_url":"https://protos.com/cosmos-labs-under-fire-over-disclosure-of-bug-affecting-four-blockchains/"},{"date":"2026-05-15","event":"Fix merged to main branch as a silent patch with no vulnerability advisory and no private notification to downstream chain operators.","source":"Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-07-28","event":"A security researcher published a detailed worked explanation of the flaw publicly.","source":"Protos","source_url":"https://protos.com/cosmos-labs-under-fire-over-disclosure-of-bug-affecting-four-blockchains/"},{"date":"2026-08-13","event":"Cosmos Labs confirmed that the vulnerability affected all Cosmos EVM chains regardless of decimal configuration, contradicting the April assessment. Public backports to supported v0.6.x and v0.7.x branches were opened.","source":"Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-19","event":"Patched versions v0.6.2 and v0.7.2 released at approximately 7:01 PM ET with generic security language in release notes. No vulnerability-specific advisory issued; no advance private notification sent to chain operators.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html"},{"date":"2026-08-20","event":"At 07:16 UTC, a Push Chain developer submitted a public pull request detailing the vulnerability and full exploitation path, identifying all vulnerable released tags. First attack against MANTRA began at 19:06 UTC, approximately 12 hours later.","source":"Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-21","event":"MANTRA halted its chain at block 17,449,398, freezing transactions. Cosmos Labs sent its first urgent private email notification to known Cosmos EVM operators at 03:36 UTC — over eight hours after the first attack on MANTRA began.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html"},{"date":"2026-08-22","event":"TAC halted at block 24,671,475 after an attacker drained approximately 2.99 billion TAC tokens (28.6% of total supply). KiiChain suffered 18 separate attacks, losing 148,326,583.15 KII. Cosmos Labs issued coordinated halt recommendation.","source":"crypto.news","source_url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"date":"2026-08-22","event":"MANTRA chain restarted on patched release at 05:30 UTC, approximately 30 hours after halt, with no rollback and no change to user balances.","source":"crypto.news","source_url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"date":"2026-08-25","event":"Exploitation window concluded. Six chains confirmed compromised. Total attacker proceeds approximately $5.72 million converted through exchanges.","source":"Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"},{"date":"2026-08-28","event":"Cosmos Labs published technical post-mortem acknowledging incorrect initial assessment, insufficient coordinated disclosure, and committing to process improvements.","source":"Cosmos Security Post-Mortem (GHSA-7g4w-cg88-2cq2)","source_url":"https://github.com/cosmos/security/blob/main/communications/cosmos_evm_GHSA-7g4w-cg88-2cq2_post_mortem.md"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision e28c16b9-30e8-43b7-9aeb-118d93195c7f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.