The Cosmos ecosystem is currently navigating a period of turbulence marked by a series of cyberattacks targeting its critical infrastructure. Between August 20 and 25, six distinct blockchains were compromised through the exploitation of a vulnerability within Cosmos EVM, the software that enables the execution of Ethereum-compatible applications within the Cosmos architecture. Unlike an isolated attack targeting a specific protocol, this structural flaw allowed attackers to manipulate wallet balances to siphon off existing assets, resulting in a total estimated loss of approximately $5.7 million.
The technical mechanism relied on an inconsistency between the balance management module and the EVM system, which triggered a digital "underflow" error. When a manipulated transaction pushed a balance below zero, the system artificially reset that amount to its maximum value, providing attackers with a fictitious reserve used to drain funds from other target addresses. Projects such as MANTRA, TAC, and KiiChain were directly impacted, suffering massive thefts from dormant wallets or burn addresses.
However, controversy is mounting regarding how Cosmos Labs managed this crisis. It appears the vulnerability had been reported as early as April 25 via the bug bounty program. At the time, development teams—unable to reproduce the exploit in their testing environment—wrongly concluded that assets were at no risk, settling for a quiet patch without urgently alerting node operators. The delayed release of secure versions, occurring barely twenty hours before the wave of attacks began, left networks in a state of critical vulnerability despite the awareness of the risk.
Facing virulent criticism from several victimized networks, Cosmos Labs has acknowledged "assessment errors" in handling this flaw and has committed to revising its disclosure protocols. This incident highlights a major challenge for decentralized infrastructure: the need for more transparent and reactive communication between core developers and the blockchains that rely on their software components. For now, the priority is to freeze funds on centralized exchanges and consolidate security on networks that remain exposed.