Cosmos Labs Wrongly Cleared Bug That Enabled $5.7M Six-Chain Exploit
A balance-underflow vulnerability in Cosmos EVM that Cosmos Labs incorrectly marked as resolved in April 2026 was exploited across six EVM-compatible networks in August, draining $5.7 million before a patch could be widely applied.
Cosmos Labs Wrongly Cleared Bug That Enabled $5.7M Six-Chain Exploit
A balance-underflow vulnerability in Cosmos EVM that Cosmos Labs incorrectly marked as resolved in April 2026 was exploited across six EVM-compatible networks in August, draining $5.7 million before a patch could be widely applied.
Cosmos Labs acknowledged that a bug report filed in April was prematurely closed before the underlying flaw was actually fixed. That administrative failure created a false sense of security among protocols built on Cosmos EVM, leaving them exposed for months. Attackers eventually exploited the unfixed vulnerability in a coordinated sweep across six chains, with MANTRA Chain absorbing the single largest loss at $3.6 million.
"Cosmos Labs says a balance-underflow bug reported in April was wrongly cleared before attackers exploited six EVM networks in August."
Cosmos Labs, via statement
The timing of the patch compounds the problem. Cosmos Labs released a fix only 20 hours before the attack began, an interval too narrow for most chain operators to assess, test, and deploy the update. The patch release did not clearly identify which vulnerability it addressed, leaving protocol teams without the context needed to treat it as urgent.
"MANTRA Chain, which lost $3.6 million, claimed the patch was only released 20 hours before the attack began and did not identify the flaw it fixed."
MANTRA Chain, via statement
A balance-underflow bug is a class of arithmetic vulnerability in which a subtraction operation produces an unintended result when the value being subtracted exceeds the balance it is drawn from. In EVM (Ethereum Virtual Machine) environments, these bugs can allow attackers to mint tokens from nothing or drain funds by manipulating accounting logic. Across six chains sharing the same Cosmos EVM codebase, one unfixed flaw became six attack surfaces simultaneously.
Cosmos Labs may argue that the original April report lacked sufficient technical detail to isolate the root cause, and that the 20-hour patch window at least demonstrates urgency once the threat was identified. Individual chain operators also bear partial responsibility for prioritizing security updates when a patch is available. Multi-chain ecosystems present a coordination problem that no single development team fully controls. The core failure, however, remains clear: a bug report was closed without verification that the fix was actually in place.
The incident fits a pattern that has repeated across DeFi. Incomplete patches, inadequate disclosure language, and fragmented coordination across shared codebases have preceded major exploits before. When a single vulnerability propagates through a shared execution layer used by multiple sovereign chains, the blast radius scales with adoption. The Cosmos ecosystem's interoperability strengths, the same properties that make it attractive to developers, become a liability when a flaw at the base layer goes unresolved. $5.7 million across six chains in a single attack is the arithmetic of that tradeoff.
The more durable lesson concerns process. Closing a bug report should require verified proof that the fix is deployed and tested, not just that a patch exists. Patch release notes should identify the class of vulnerability being addressed with enough specificity for downstream operators to triage correctly. Twenty hours is not a deployment window. It is a warning.




