Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Blockchain Technology, Every Layer Deconstructed
chain-bible.com
LATEST
Why Can't You Reverse a Crypto Transaction? And the Two Times It Was Effectively Undone Anyway  ·  One Shared Framework, One Integer Underflow, Six Chains Drained in Five Days: Why the Cosmos EVM Incident Is an Ecosystem Problem  ·  Ethereum's Glamsterdam Goes Live on Sepolia: Gas Limit Jumps From 60M to 200M in 11 Hours, While Creating New Storage Costs Nearly 5x More  ·  "Decentralized" DAO Governance: 1% of Token Holders Control 90% of the Voting Power  ·  You Staked Your ETH — Now You Can't Get It Back for Days: How the Validator Exit Queue Actually Works  ·  Symbiosis Bridge Minted $46 Billion in Fake syBTC — The Attacker Only Managed to Cash Out $336,000
ecosystem

One Shared Framework, One Integer Underflow, Six Chains Drained in Five Days: Why the Cosmos EVM Incident Is an Ecosystem Problem

30-Second Version · For the impatient
A public patch is an exploit map. Silent patching only works if nobody reads the diff before you ship it.

Full Explanation +
01 · Why did this happen?

How is shared-framework risk different from one protocol being hacked?

When a single protocol is hacked, the damage is confined to that protocol's users. When a shared framework fails, the damage reaches every chain that adopted it, and those chains operate independently with different patching speeds. In the Cosmos EVM case the same flaw was exploited separately on six chains, and each chain team had to decide for itself whether to halt and when to upgrade. The risk shifts from 'one team's code quality' to 'one upstream maintainer's disclosure process plus every downstream team's reaction time'.

02 · What is the mechanism?

Why did silent patching become standard practice?

The logic common in open-source projects is to merge the fix to the main branch with short release notes, so that the existence of a bug is not announced to attackers before users can upgrade. That makes sense when a bug affects few people or carries no fund risk. The trouble comes when a bug can move funds directly and the upstream has no reliable list of downstream users: silent patching then becomes a bet that attackers will not read the diff before operators do. Cosmos Labs' 37 silent patches suggest it leaned on that bet for a long time.

03 · How does it affect me?

How does an integer underflow turn a balance into an astronomical number?

Computers store integers in a fixed number of bits. The smallest value of a 256-bit unsigned integer is 0; if a program subtracts 1 from 0 without a check, the result is not negative but wraps around to the maximum, roughly 2^256. Here a vesting account delegated more than its spendable balance, the subtraction had no guard, and the balance wrapped to the maximum, after which reconciliation logic combined with an overflow moved other people's tokens. The fix is not complicated: check the balance is sufficient before subtracting, which is what Cosmos's patch #1176, an underflow guard, does.

04 · What should I do?

How can an ordinary holder tell whether a chain they hold carries this kind of risk?

There are three public signals to check. Whether the chain runs on Cosmos EVM or another large shared framework, which official documentation usually states. Whether its Node software keeps up with upstream security advisories, which Block explorers or governance proposals often reveal through upgrade records. And whether the team has published post-mortems after incidents. In this episode KiiChain published its post-mortem on August 23, five days ahead of upstream; that kind of transparency is a clue to how mature a team is.

Full Content +

Between August 20 and 25, 2026, six blockchains in the Cosmos ecosystem were hit by the same bug in quick succession, with Cosmos Labs estimating about $5.7 million of assets sold. The amount is modest, but the incident exposes a structural problem usually glossed over: when dozens of chains share one open-source framework, one bug is dozens of bugs, and the gap between patching and deploying is the attacker's window.

The Bug Itself: Underflow Plus Overflow

The culprit was Cosmos EVM, the shared framework that lets Cosmos chains run Ethereum-style applications, derived from the Evmos codebase. According to reporting by The Block and The Hacker News, the attack chained two flaws: an integer underflow inflated one account's balance to the maximum 256-bit value, and an overflow then let the attacker move a target account's tokens to themselves. As The Hacker News explains it, a vesting account delegates more than its spendable balance, the subtraction is unchecked, and the balance wraps to roughly 2^256. The path also requires that the chain allow anyone to create vesting accounts. MANTRA said its supply moved by a single base unit, meaning no tokens were conjured; other people's tokens were moved.

The Timeline Is the Story

On April 25, a researcher reported the flaw through the bug bounty; Cosmos Labs judged that live funds were not at risk because its testers could not reproduce it on the configuration live chains use. On May 15 and 20, related fixes merged to the main branch. Around August 13, Cosmos Labs confirmed every Cosmos EVM chain was affected regardless of decimal configuration. On August 19, v0.6.2 and v0.7.2 shipped. In the early hours of August 20, a pull request in a Push Chain fork publicly described the vulnerability and exploit path; at 19:06 UTC that evening MANTRA suffered the first attack, roughly 11 to 12 hours after the public PR. Cosmos Labs sent its first private notification at 03:36 UTC on August 21, about two hours after MANTRA reported being hit. On August 28, it published its post-mortem.

The Problem With Silent Patching

Cosmos Labs' own bounty policy says that for network-wide risks it will start emergency mitigations, private fix distribution, or coordinated upgrades before any public disclosure. Here, the team treated the patch as already public with no known exploitation and chose the silent patch process. The Hacker News reports Cosmos Labs had silently patched 37 vulnerabilities in the preceding 13 months, and that the v0.6.2 and v0.7.2 release notes do not list the security PRs. A public patch is itself an exploit map: an attacker only needs to read the diff to work backward to the bug. Worse, 11 deployments had never registered with Cosmos Labs' security channels, and the team holds no complete registry of networks running its software, so even a private notification could not have reached everyone.

The Knock-On Effect: TAC Halts the Whole Chain

One victim, TAC, announced on August 22 that it was working with validators to halt block production for the entire chain; the last block the reporter saw was 24,671,475. TAC said the exploited vulnerability sat on its Cosmos EVM side and affected only the TAC Token supply. It has not disclosed the vulnerable component, the exploit transaction, or a loss figure, and has published no restart timetable. This is a typical bind: when the flaw lives in a shared base layer, a chain team often cannot isolate the affected module and has to stop everything.

What This Means for Your Money

If your assets sit on a Cosmos-ecosystem chain, or any chain built on a shared open-source framework, the risk comes not only from that chain's own team but from the framework maintainer's disclosure process. Three practical checks follow. See whether the chain tracks the latest framework version and whether release notes say what security fixes they contain. Check whether the chain has a record of halting block production over a vulnerability, and whether restarts were handled openly. And avoid leaving large sums long-term on a single small chain, especially one that depends on a framework with a freshly disclosed bug. KiiChain said about 54% of its taken KII could be recovered onchain if the network is restored, but as of August 28 MANTRA said no tokens had been recovered, so after-the-fact remedies are not something to count on.

Sources: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable (The Hacker News), Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack (The Block), TAC chain halt follows supply exploit as restart remains unclear (CryptoSlate), Cosmos EVM GHSA-7g4w-cg88-2cq2 post-mortem (cosmos/security)
Diagram
Cosmos EVM 事件時間線從 4 月通報到 8 月六條鏈被攻擊,公開 PR 到第一次攻擊只隔約 11 到 12 小時Cosmos EVM Incident Timeline (2026)Apr 25Bug reportedJudged no riskMay 15-20Fix merged to mainSilent patchAug 13All chains affectedConfirmedAug 19-20v0.6.2 / v0.7.2Public PR on Aug 20Aug 20-256 chains exploited~$5.7M soldAug 28Post-mortemFirst attack came ~11-12 hours after a public PR described the exploit pathChain Bible · chain-bible.com
Feel free to share. Please credit the source.
Ask a Question
Please enter at least 10 characters
Related Articles
"Decentralized" DAO Governance: 1% of Token Holders Control 90% of the Voting Power
ecosystem · Oct 01
The Weekend US-Iran Tensions Spiked, Tokenized Gold Volume Jumped Ninefold — That's What Tokenization Actually Changes
ecosystem · Sep 05
Public, Private, and Consortium Chains: Pick the Wrong One and It's Not Performance You Lose, It's the Entire Governance Model
ecosystem · Aug 31
Restaking Lets One Stake Earn Multiple Yields — It Also Taught Risk How to Spread Across Protocols: What the Kelp DAO Incident Revealed
ecosystem · Aug 31
More Related Topics