Cosmos EVM Vulnerability Leads to $5.7 Million Loss Following Disclosure Error
Cosmos Labs disclosed a calculation overflow flaw in Cosmos EVM that extracted roughly $5.7 million across multiple Cosmos-based chains between August 20 and 25.
Caleb North·updated September 02, 2026

According to the post-mortem, arithmetic boundary errors in pre-patch releases allowed a malicious vesting account paired with a crafted contract to corrupt balance accounting. The fix shipped in versions 0.6.2 and 0.7.2. Attackers were live within 20 hours of public release.
The Overflow Path
The defect lived in releases prior to 0.6.2 and 0.7.2. A downward integer overflow triggered a secondary overflow during balance recalculation. The state mutation returned an incorrect value. Balance diverged from ledger truth. Subsequent transfers executed against a false total.
The attacker staged a vesting account configured to provoke the recalculation branch. The contract forced state transitions until the overflow condition fired. Once the balance drifted, withdrawals targeted addresses holding the largest deposits. No new tokens entered circulation. Total supply held constant. Loss originated from state corruption, not mint logic. The invariant — total supply equals sum of account balances — held only because both sides of the ledger were corrupted in lockstep.
Disclosure Failure
The bug landed on April 25, 2026 through a bug bounty submission. Internal testing concluded that production configurations were not at risk. The patch was merged into the 0.6.2 and 0.7.2 release branches and shipped publicly on the evening of August 19. Independent researchers confirmed in early August that the vulnerability affected every Cosmos EVM deployment, not a subset.
Twenty hours after release, the first exploit executed.
MANTRA stated publicly that 20 hours is insufficient for safe patch deployment across distributed validator sets. KiiChain noted that the recommendation to halt networks came only after three chains had already been drained. Cosmos Labs reports it coordinated with 40 networks and separately identified 11 unregistered Cosmos EVM deployments inside an ecosystem of more than 115 public blockchains. The patch was merged into routine version bumps without a separate critical advisory to operators. Silence during the window between patch merge and public release is what turned a contained fix into a live attack vector.
Operator Audit
1. Confirm nodes run Cosmos EVM 0.6.2 or 0.7.2 minimum. Earlier versions carry the overflow defect.
2. Diff the patched overflow guards into any custom EVM fork before the next deployment.
3. Audit vesting account implementations against the arithmetic boundary exposed by the patch notes. The overflow path is reproducible from the disclosed trace.
4. Treat any unannounced upstream patch merged into a minor release as a potential silent critical fix. Inspect commit history before deploying.
5. Bound integer arithmetic in precompile paths with explicit checked math. Downward overflow on a single value cascades through dependent state mutations and replicates the same attack surface.
CoinGecko's 2026 State of Crypto Security Report places this incident inside a wider pattern: Web3 platforms lost $3.63 billion across 245 documented exploits between January 2025 and July 2026. Smart contract vulnerabilities accounted for $777 million of that total. Supply chain compromises and infrastructure breaches drove $1.81 billion. The Cosmos EVM incident is neither novel nor isolated. It is a deterministic failure of disclosure process replicated across the broader stack.