A single, devastating error within the balance accounting mechanism of Cosmos EVM directly precipitated a coordinated series of attacks. These attacks simultaneously targeted several distinct blockchain networks. Between August 20 and August 25, malicious actors actively exploited the critical vulnerability designated as GHSA-7g4w-cg88-2cq2. Consequently, they successfully extracted valuable assets from at least six independent networks operating within the broader Cosmos ecosystem.
The Arithmetic Overflow Vulnerability
Cosmos EVM functions as a dedicated module. It effectively integrates a fully operational Ethereum Virtual Machine directly into blockchains built utilizing the Cosmos SDK. The fundamental problem originated precisely at the boundary separating two distinct accounting systems. Specifically, the EVM StateDB only recognized the readily available account balance. Conversely, the Cosmos SDK independently tracked locked tokens, which users could legitimately allocate for staking purposes.
Exploiting the Accounting Discrepancy
The attacker initiated the exploit by creating a specialized vesting account alongside a malicious smart contract. Subsequently, they intentionally delegated a quantity of tokens far exceeding the amount the StateDB considered available. This action triggered an uncontrolled arithmetic overflow. As a result, the recorded balance mutated into an astronomically large number, nearing 2^256. A secondary bug then permitted the attacker to leverage this artificially inflated value. They used it to intentionally overflow the balance of a separate account, effectively stealing the genuine tokens residing there. The total circulating supply of coins remained unchanged during this operation because the attacker seamlessly combined both errors within a single, unified transaction.
The Financial Impact of the Heist
Following the successful extraction of funds, the attackers systematically routed the stolen assets toward other networks utilizing cross-chain bridges. They then rapidly liquidated these assets. According to official estimates from Cosmos Labs, the attackers successfully exchanged assets worth approximately $2.87 million across various decentralized exchanges. This stolen loot included roughly 2.61 million USDT, 114 ETH, and 93.78 TON, among other diverse tokens. Furthermore, approximately $2.85 million worth of assets funneled directly through centralized exchanges. Authorities subsequently froze the specific accounts utilized by the attackers on these platforms as part of the ongoing investigation.
Targeted Networks and Specific Losses
The published post-mortem timeline details the specific attacks against the MANTRA, TAC, and KiiChain networks. Cosmos Labs deliberately withheld the identities of three additional affected networks. On the TAC network, the attacker successfully extracted nearly 2.99 billion TAC tokens. They transferred a portion to the BNB Chain, eventually exchanging roughly 1.21 billion TAC for 950,000 USDT. From KiiChain, the attacker acquired approximately 148.3 million KII. They subsequently sold 64.6 million KII for an estimated 1.61 million USDT.
A Preventable Tragedy and Delayed Patching
The history of this incident reveals a particularly frustrating reality. The core developers actually knew about this specific error long before the attacks commenced. A security researcher initially reported the vulnerability via the established bug bounty program on April 25. The development team attempted to reproduce the problem on networks utilizing a different configuration. Unfortunately, they erroneously concluded that active Cosmos EVM blockchains faced no imminent risk of financial loss. The necessary fix merged into the main repository branch on May 15. However, the developers failed to backport it immediately to the stable release versions. This delay occurred because the required modification necessitated a carefully coordinated network state update.
The Disastrous Disclosure Timeline
By early August, new, independent reports finally helped Cosmos Labs comprehend the true severity. They realized the problem fundamentally affected all Cosmos EVM networks, regardless of their specific configuration. On August 19, the team urgently released versions v0.6.2 and v0.7.2 containing the crucial fix. However, the release notes merely mentioned the inclusion of security changes. They utterly failed to describe the actual severity of the imminent threat.
The very next day, a developer from an entirely unrelated third-party project, Push Chain, publicly posted a detailed pull request. This request explicitly described the vulnerability, the precise method of exploitation, and a comprehensive list of vulnerable versions. The first documented attack against the MANTRA network commenced less than 12 hours later.
Post-Incident Response and Protocol Changes
Following the widespread incident, Cosmos Labs urgently contacted approximately 40 separate blockchains. They actively assisted 13 potentially vulnerable networks in updating their software, halting operations, or implementing other necessary protective measures. Securing the 0.6.x branch explicitly requires version v0.6.2 or higher. Similarly, the 0.7.x branch requires version v0.7.2 or higher. The company also promised to significantly overhaul its internal process for evaluating critical errors. Furthermore, they intend to revise their rules regarding the silent release of security patches. The disastrous combination of an incorrect initial risk assessment and the sudden, public appearance of exploitation instructions created an incredibly convenient window for the attackers.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!