๐Ÿ“… Friday, 4 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Celah Cosmos EVM Kuras $5,72 Juta dari 6 Jaringan - MANTRA Paling Telak Meski Patch Sudah Rilis 20 Jam Sebelumnya

Cosmos EVM Flaw Drains $5.72M Across 6 Chains - MANTRA Hit Hardest Despite Patch Released 20 Hours Earlier

Six Cosmos EVM-based blockchain networks were breached by hackers between August 20-25, 2026, resulting in total losses of $5.72 million that were immediately swapped across centralized and decentralized exchanges. The hardest-hit victim was MANTRA, which lost 720.9 million tokens worth $3.6 million from a burn address and a dormant multisig wallet.

The root cause stems from an integer underflow vulnerability in Cosmos EVM, a framework that utilizes open-source Evmos code. This programming flaw allowed attackers to manipulate system calculations and roll back account balances to the maximum limit of 2 to the power of 256 minus 1.

The initial report regarding this system flaw was submitted through a bug bounty program on April 25. Cosmos Labs failed to assess the threat while handling the ticket. The development team was unable to reproduce the exploit scenario in their testing environment and concluded that user funds were safe.

A new code update was pushed to the public months later on August 19 at 19:01 ET. The bug patch was released without detailed disclosure of the underlying flaw, aiming to prevent attackers from discovering the vulnerability before systems could be fully upgraded.

An Accidental Morning Leak

An oversight derailed the security efforts the following day. On August 20 at 3:16 a.m., a Push Chain developer inadvertently published the complete exploit path publicly, providing hackers with precise instructions to breach Cosmos EVM defenses. The first exploit occurred at 15:06 ET, 20 hours after the official patch was deployed. The chain of attacks quickly spread across multiple parties, also hitting the TAC and KiiChain ecosystems.

MANTRA developers stated that the 20-hour window was not enough for their network to react. The team needed time to assess the exploit risk, build fixes, test updates, and coordinate software upgrades with 38 independent validators. By the time network operations were halted at 19:13 ET, the attacker had already relocated 94.7% of the stolen tokens across 15 consecutive transactions to a centralized exchange deposit address.

The Toll of a 30-Hour Outage

The network shutdown ultimately trapped the remaining 38 million MANTRA tokens in the attacker’s wallet. In exchange, the MANTRA network went completely offline, processing zero user transactions for 30 full hours. The downtime was necessary to ensure all validators completed the installation of software version 8.4.0.

This incident highlights the real-world risks of decentralized software vulnerabilities: hackers armed with ready-to-use exploit paths consistently move faster than upgrade procedures across dozens of independent network security entities.

Reported by crypto.news.

Read also: Central Bank of Brazil Partners with Hypernative for Real-Time Crypto Tracking - Following $180M Software Breach


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share