MANTRA postmortem puts exploit at 720.9 million tokens and says no recovery yet
The chain says an unsigned-integer underflow in the Cosmos EVM dependency let an attacker move 720.9 million MANTRA without privileged access; 37.96 million remained immobilized and none had been recovered as of Aug. 28.
Cosmos Labs has urged public blockchains running older versions of its Cosmos EVM module to halt and upgrade after attackers hit three networks in the same week. The Defiant reported that the recommendation covers versions below v0.6.2 or v0.7.2 and follows incidents on MANTRA, TAC and KiiChain.
The shared module lets Cosmos SDK chains run Ethereum-style smart contracts. The common dependency means the event is larger than MANTRA's original halt: it has involved at least one major token drain, emergency validator stops and a continuing question about which other chains use the exposed configuration.
Cosmos Labs publicly described the matter as an ongoing security incident and said its security and engineering teams were responding. It had not published a full incident report in the latest available account, so the complete list of affected chains and the total loss remain unconfirmed.
MANTRA's Aug. 28 postmortem now says an unsigned-integer underflow in the balance-accounting layer of the upstream `cosmos/evm` dependency let an attacker move 720,923,967.99 MANTRA from two unauthorised addresses. The chain says no validator, administrator, governance or multisig keys were compromised, and that the attacker needed no privileged access.
A new Cosmos Labs postmortem broadens the incident beyond the three chains previously identified. It says six Cosmos-based networks were exploited between Aug. 20 and Aug. 25, with about $2.87 million in assets bridged from affected chains and sold on decentralized exchanges, plus an estimated $2.85 million sold through centralized exchanges. Cosmos Labs says the figures were supplied by affected chains and have not been independently audited; it also says the exchange accounts used by the attacker were frozen pending investigation.
The maintainer's timeline adds a disclosure warning. The flaw was reported through Cosmos Labs' bug-bounty process on April 25 and initially assessed as posing no risk to funds on live networks, according to The Hacker News' review of the postmortem. The affected production ranges are below v0.6.2 and from v0.7.0 through v0.7.1; operators unable to upgrade are told to halt rather than attempt a coordinated state-breaking upgrade. That history explains why the incident is an operational exposure as well as a code defect, but it does not establish that every Cosmos EVM deployment was compromised.
The same review says Cosmos Labs' postmortem counted 37 vulnerabilities patched through its silent process over the prior 13 months, while the v0.6.2 and v0.7.2 release notes did not identify the security backports or the pull requests carrying them. Cosmos Labs' published policy says emergency mitigations or private fix distribution should precede public disclosure when a flaw presents an immediate or network-wide risk. Those disclosure findings come from the postmortem and The Hacker News' repository review; they do not establish that all 37 issues were exploitable or that every downstream deployment was affected.
Three chains, different damage
KiiChain said an attacker drained 148,326,583 KII across 18 attacks on Aug. 22 before validators halted the chain at block 9,355,723. The report, described by The Defiant, said 80.7 million KII remained in addresses immobilized by the halt, while 64.6 million was bridged to BNB Smart Chain and sold for about 1.61 million BUSD.
TAC said an attacker drained 2,985,651,403 TAC from a single account and that the network stopped at block 24,671,475. That amount was about 62% of circulating supply at the time, according to the report. TAC and KiiChain remained frozen in the latest account.
MANTRA halted after activity involving two project-managed wallets and later resumed on a patched v8.4.0 binary. Its postmortem says the chain restarted without a rollback or state rewrite; approximately 37.96 million MANTRA, or 5.27% of the extracted total, remained immobilised in the attacker account as of Aug. 28, and no tokens had been recovered.
The patch and the disclosure gap
The Cosmos EVM release history marks the relevant patch releases as containing important security fixes and recommends that chains upgrade through a coordinated process. The releases are state-breaking, which helps explain why a halt may be operationally safer than an immediate upgrade on a live validator set.
KiiChain's account, as reported by The Defiant, says Cosmos Labs published a fix in the open on Aug. 19 before downstream chains had been privately warned, and that two of three defects it identified remained unfixed upstream. That is an allegation from an affected chain, not an independently established finding; Cosmos Labs had not responded to that account in the report.
The immediate operational question is whether each Cosmos EVM chain has halted, applied the correct patch and audited vesting-account or precompile configurations. Until the maintainer publishes the promised post-mortem, the evidence supports a multi-chain exposure and confirmed incidents, but not a final scope or a claim that every Cosmos EVM deployment is compromised.