Cosmos EVM Vulnerability Drains MANTRA TAC And KiiChain

15 min read
3 views
Aug 31, 2026

A Cosmos EVM flaw sat in a silent patch for months. Then six networks were hit in days and millions moved off-chain. The 20-hour window is the part operators still cannot stop talking about.

Financial market analysis from 31/08/2026. Market conditions may have changed since publication.

Have you ever watched a security warning arrive just late enough to feel almost cruel? That is the mood hanging over several Cosmos-linked networks this month. Between August 20 and August 25, attackers used a critical Cosmos EVM vulnerability to pull tokens from large accounts on multiple chains, then flipped a large share of those assets through exchanges. Industry estimates put the converted haul near $5.72 million. I have covered a lot of messy upgrades, and this one still stands out because the bug was reported in April, patched in public without a clear warning, and then weaponized about twenty hours after fixed software went live.

Why This Cosmos EVM Episode Feels Different

Most chain incidents have a familiar shape. A bug appears, a team rushes a fix, operators argue about downtime, markets shrug. This time the story is about process as much as code. Cosmos Labs later said the flaw first arrived through a bug bounty on April 25. Testers could not reproduce it against the setups they believed live networks were using. They judged that user funds on production chains were not in danger. That call shaped everything that followed.

Because of that assessment, the repair went out as a silent public patch. Developers merged a fix in May without telling operators which problem it actually solved. In early August, independent researchers showed the issue was not limited to exotic configs. It touched Cosmos EVM deployments in general. Only then did the tone change. Patched releases landed at 7:01 p.m. ET on August 19. Release notes spoke of “important” security work and left the rest unsaid. The first known attack started at 3:06 p.m. ET on August 20.

Twenty hours. That number is going to live in post-mortems for a long time. MANTRA later said it was not a realistic window to assess, build, test, and coordinate a state-breaking upgrade across 38 independent validators, especially without a vulnerability-specific advisory. I tend to agree. A halt can be decided in minutes. A clean upgrade across a validator set cannot.


What Operators Were Told, And What They Were Not

Silent patching is not automatically reckless. In closed software worlds it can buy time. In an open ecosystem with more than a hundred public chains and no complete registry of every Cosmos EVM deployment, it is a gamble. Cosmos Labs later said it coordinated with 40 networks during the response and helped 13 patch or halt before they were hit. It also found 11 Cosmos EVM deployments that had never been registered with the team. That last detail should make anyone uneasy.

Another disclosure landed before the first theft. In the early hours of August 20, a downstream developer publicly submitted a code change that described the weakness and the path used to abuse it. The filing credited an audit firm and listed versions thought to be exposed. It also said no released version contained the fix, even though patched builds had been published hours earlier and were missing from that version table. Cosmos Labs called the publication of an exact exploitation path “highly unusual” and warned that this kind of write-up can raise the chance of a live attack.

Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory.

– MANTRA post-mortem

MANTRA placed that public finding 11 hours and 45 minutes before the attacker’s first probe. The same project also noted, carefully, that the attacker’s wallet had been funded almost four hours before the finding was filed. “We state the timing as fact and draw no conclusion from it.” That sentence is doing a lot of work. A withdrawal of 472.70 MANTRA from a customer account at a centralized exchange later funded gas used during the attack, according to the network.

How The Flaw Distorted Account Balances

The technical root sat in Cosmos EVM, the ecosystem’s Ethereum-compatible layer built from the open-source Evmos line. Advisories described a critical accounting error in older releases, specifically versions before v0.6.2 and v0.7.2. In plain language, certain balance math could wrap around instead of failing safely. Attackers focused on fat targets: burn addresses, leftover launch multisigs, staking pools, and other accounts that looked immovable until they were not.

Labs said no extra tokens were minted through the process in a classic inflation sense. Total supply, in their framing, stayed effectively unchanged. MANTRA reported that the exploit shifted its supply by only one base unit, the smallest slice of the token. That is a comforting sentence until you remember what actually moved. Tokens sitting in accounts treated as unspendable became spendable the moment they left those addresses. Markets do not care about the philosophical difference between “new supply” and “supply that was never supposed to trade.”

I will not walk through a recipe here. There is no good reason to. What matters for holders and operators is simpler. The bug let an attacker inflate an internal balance figure, press that figure against another account, and walk away with the target’s tokens. Large, quiet balances were the prize. Monitoring that assumes a burn address can never send is not monitoring. It is a story teams tell themselves until the story breaks.

MANTRA Took The Heaviest Public Hit

MANTRA disclosed the largest public loss. Attackers lifted 720.9 million MANTRA, then valued around $3.6 million, from two addresses. One was the network’s burn address. The other was a dormant multisignature wallet left over from an older incentive campaign. No automated alarm fired when tokens first left the burn address because monitoring treated that address as frozen. The theft ran for almost four hours before anyone stopped it. That is a long time in crypto minutes.

The chain halted at 7:13 p.m. ET on August 20. About 38 million stolen MANTRA stayed stuck in the attacker’s wallet. The rest, 94.7 percent of the stolen pile, had already gone to one centralized exchange deposit address across 15 transfers. Block production stayed down for roughly 30 hours. Exchanges paused deposits and withdrawals while engineers dug in. Validators later shipped patched software and resumed without rolling the chain back or rewriting user balances. Version 8.4.0 carried the Cosmos EVM security fix.

  • 720.9 million MANTRA left two high-value addresses
  • About $3.6 million in then-market value
  • Nearly four hours before detection
  • 94.7 percent already at one exchange deposit
  • About 30 hours of halted settlement
  • No rollback, patched restart on version 8.4.0

MANTRA had added native EVM support to mainnet in September 2025, sitting beside CosmWasm so Solidity apps and Cosmos-native contracts could share the same chain. That dual stack is a selling point on a good week. On a bad week it is another surface. As of August 28, the project said none of the stolen MANTRA had been recovered. Circulating supply jumped by those 720.9 million tokens because assets once filed as unspendable were now in the wild.

There is a corporate footnote that will matter to long-term holders. MANTRA is being acquired by existing backer Inveniam Capital Partners, which made a $20 million strategic investment in August 2025. The deal is expected to close in the third quarter of 2026. Chain, token, and related infrastructure are slated to keep running under that ownership. An acquisition does not erase a burn-address drain. It does change who owns the cleanup.

TAC And KiiChain Faced The Same Pattern

The method did not stop with MANTRA. On August 22, TAC was hit. Nearly 3 billion TAC left the network’s staking pool. TAC is built to bring DeFi-style apps to TON and Telegram users, which means a lot of the story quickly left the home chain. Around 1.2 billion of the stolen tokens were sold on BNB Chain for roughly $950,000. That is not a rounding error. It is a reminder that bridge rails and sister markets decide how fast a theft becomes cash.

KiiChain was attacked the same evening and lost about 148 million KII. Roughly 64.6 million tokens were sold for about $1.6 million. Cosmos Labs estimated that around 54 percent of the stolen KII could still be recovered onchain if the network is restored. That “if” is doing heavy lifting. A recoverable balance on a halted or wounded chain is not the same thing as money in a user’s wallet.

A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes. The only measure that would have contained the risk immediately was a clear instruction to stop producing blocks, and that instruction came after the damage was done.

– KiiChain post-mortem

KiiChain was blunt about communication. The project said Cosmos Labs did not give advance notice, did not flag the release as security critical at first, and did not tell affected chains to halt until after MANTRA, TAC, and KiiChain had already been struck. The halt recommendation arrived on August 22. In my experience, that sequence is how trust frays even when the final patch is sound.

There is also a technical disagreement that should not be papered over. KiiChain argued that three upstream defects were needed to complete the attack and that only the underflow piece had been publicly patched. MANTRA tested the published repair against a working reproduction and called the underflow fix “the control that closes this attack path.” Cosmos Labs described two chained weaknesses and did not fully answer KiiChain’s claim that another upstream defect remains open. Operators now have to decide whose test bench they trust.

Three More Networks, And A Messy Identification Problem

Three further Cosmos EVM networks were exploited the same way. The official write-up did not name them. That silence is understandable and still frustrating. Markets hate unnamed victims because rumors fill the gap. One name that surfaced in later analysis is Nesa. An exchange suspended NES deposits and withdrawals on August 24, citing a critical consensus issue that led vulnerable nodes to accept invalid blocks.

On-chain analysts later described a wallet that bought about $250,000 of NES, moved it onto Nesa, abused the accounting flaw to swell a balance dramatically, and tried to send a huge pile of NES back toward Ethereum. Liquidity vanished from pools. Most attempted swaps ate themselves through slippage. The attacker, in that telling, walked away with around $60,000. The funding trail began in privacy coin rails, and the behavior looked different enough that some observers think a separate party handled the Nesa event. Two other affected chains still have no public names.

NetworkWhat movedConverted value, public estimatesNotable detail
MANTRA720.9 million tokensAbout $3.6 millionBurn address and dormant multisig
TACNearly 3 billion tokens from stakingAbout $950,000 sold on BNB Chain1.2 billion tokens sold off-home-chain
KiiChainAbout 148 million KIIAbout $1.6 million soldRoughly 54 percent called recoverable onchain
Unnamed plus possible NesaLarge inflated balancesOne analysis cited thin realized profit after slippageTwo chains still unidentified

Add those public sale figures and you can see how a $5.72 million conversion estimate comes together without every token finding a perfect bid. Theft value and realized cash are cousins, not twins. Thin books punish attackers too. That is cold comfort for the networks that had to halt.

The April Report And The Cost Of A Quiet Fix

Rewind to spring. A bounty report lands on April 25. Internal tests fail to recreate the issue on known production shapes. The team concludes live funds are safe. A silent patch follows in May. On paper, that sequence is tidy. In the wild, production is messier than a lab matrix. Chains fork configs. Teams skip upgrades. Someone leaves a launch multisig sitting in a corner. A burn address is treated as a black hole rather than a watched account.

When independent researchers later proved the bug was general, Cosmos Labs tried to obscure the repair to slow reverse engineering and then shipped patched versions on August 19. That is a reasonable second act. The missing third act was a private, blunt advisory that said halt first, argue later. Perhaps the most interesting aspect is not that people disagree about disclosure ethics. It is that both sides can quote real constraints. Publish too much and you hand attackers a map. Publish too little and honest operators keep producing blocks on broken software.

This episode also sits next to an earlier Cosmos-area disclosure from the same year: a consensus-layer stall issue rated well below critical and not used for direct theft. Different bug, different blast radius. Still, two public scares in one year train markets to flinch at every “important security fix” note. Vague release language starts to look like a tell.

Why Burn Addresses And Sleepy Multisigs Are Soft Targets

People love the poetry of a burn address. Tokens go in. Tokens never come out. Except when the accounting layer disagrees. If your alerts ignore outgoing movement from an address you have labeled immortal, you have built a blind spot on purpose. The same goes for incentive wallets that nobody wanted to dissolve after a campaign ended. Dormant does not mean defended. Dormant often means forgotten.

  1. Inventory every address that holds a material share of supply, including burns and old campaign vaults.
  2. Watch those addresses for any outbound activity, even if policy says they cannot move.
  3. Give a small on-call group authority to halt without a two-day governance novel.
  4. Treat “important security fix” notes as halt-level events until proven otherwise.
  5. Rehearse a state-breaking upgrade the way you rehearse incident comms, not the way you rehearse a blog post.

None of that is glamorous. It is also cheaper than explaining a four-hour silent drain. I’ve found that teams will spend weeks polishing a launch thread and still have no practiced halt button. That imbalance is cultural, not technical.

Exchanges, Slippage, And The Off-Ramp Clock

Look at the money path and a second clock appears. On MANTRA, most of the stolen stack reached a single exchange deposit before the halt. On TAC, a large slice was sold on another chain. On KiiChain, tens of millions of tokens hit the market the same evening. Attackers do not need to invent new coins if they can ride existing rails faster than compliance desks wake up.

The Nesa-related analysis, if it holds, shows the other side of that clock. Inflate a balance into the tens of millions of dollars on paper, then discover that pools will not absorb it. Slippage becomes an accidental defense. That is not a strategy anyone should rely on. It is a market microstructure accident. When liquidity is pulled, everyone left in the pool pays tuition.

Centralized venues now sit in an awkward seat. Freeze too slow and they look complicit. Freeze too fast on a rumor and they strand honest users. The practical middle is ugly and still necessary: pause the ticker, ask for a chain statement, and refuse to pretend that “we are investigating” is a trading product.

What Circulating Supply Really Means After A Drain

Token dashboards love clean categories. Circulating. Locked. Burned. This incident smeared those labels. MANTRA’s circulating float rose because tokens that were socially treated as dead became live inventory. The base-unit supply story stayed almost flat. Holders felt a different number: more tokens that can hit a book.

If you mark a burn as permanently removed, you should also mark the operational risk that the mark is only as good as the virtual machine underneath it. That is an unfashionable sentence. It is still true. Accounting metaphors leak. When they leak, price models that assumed a tighter float look naive overnight.

Incident clocks that actually mattered:
  April 25 — bounty report received
  May — silent merge, no operator briefing
  Early August — independent confirmation the bug is general
  Aug 19, 7:01 p.m. ET — patched builds published
  Aug 20, early morning — public write-up of the path
  Aug 20, 3:06 p.m. ET — first known attack
  Aug 20, 7:13 p.m. ET — MANTRA halt
  Aug 22 — TAC and KiiChain hit; halt guidance widens

Governance Speed Versus Attacker Speed

Cosmos culture prizes sovereign chains and independent validator sets. That design is a feature until a shared library goes bad. Thirty-eight validators cannot fake a huddle in twenty hours if they also need to rebuild, test, and ship a breaking upgrade. Ten minutes of block production after a critical advisory can be enough to empty the obvious vaults.

So the operational question is blunt. Who is allowed to say stop? If the answer is “a forum thread after a quorum,” you have already chosen delay. If the answer is “a documented emergency key set, used rarely and audited after,” you have chosen an adult process. I would rather argue about a halt that proved unnecessary than write another post-mortem about a burn address that moved.

Downstream teams also need a habit that sounds small and is not. Read release notes like a hostile lawyer. “Important security fixes” without a private briefing should trigger the same runbook as a named CVE. Assume the quiet language is there because the quiet language is load-bearing.

Lessons For Anyone Holding Cosmos EVM Assets

If you hold tokens on a Cosmos EVM chain, you are not a spectator. You are part of the detection layer whether you like it or not. Watch official halt notices. Watch deposit pauses at venues that list the ticker. Treat sudden float changes as a risk event even when a team insists supply “barely moved.” The social definition of supply is what traders price.

Do not confuse a patched binary with a finished incident. KiiChain’s unresolved-defect claim, even if later disproved, is a reason to demand a second independent reproduction. MANTRA’s test that the underflow repair closes the path is useful. One test is not a chorus. Two labs saying the same thing would have calmed more people than another thread of adjectives.

  • Confirm your chain’s exact Cosmos EVM release, not the marketing version number.
  • Ask whether burn and treasury addresses are on outbound alerts.
  • Prefer venues that already paused during the August window over venues that stayed open on vibes.
  • Separate “tokens still onchain” from “tokens you can sell without wrecking the book.”
  • Expect more unnamed victims to leak out as analytics firms keep clustering wallets.

What This Says About Shared Frameworks

Shared frameworks are how ecosystems ship faster. They are also how one accounting bug becomes a multi-chain week. Evmos-descended EVM support let teams court Solidity developers without leaving Cosmos. That product story is still real. The security story now has a scar. Every extra compatibility layer is another place for integer assumptions to drift.

There is a temptation to treat this as a reason to abandon compatibility. That would be lazy. The better read is narrower. If you expose an EVM, you inherit EVM-class failure modes plus your own staking and bank modules. Test the seams. Especially the seams that touch locked tokens, delegated amounts, and accounts that are not supposed to spend.

Cosmos Labs does not keep a full map of every public chain in the wider family. That is not a moral failing by itself. It is a structural fact. If you launch a Cosmos EVM chain and never register, you are asking to be late to the next private heads-up. Registration will not save a sloppy monitor. Non-registration almost guarantees you hear the news from a market chat.

A Note On Tone, Blame, And Useful Anger

It is easy to pick a villain. The silent patch. The public gist. The twenty-hour gap. The burn-address monitor that never existed. The halt advice that arrived after three named victims. All of those are fair exhibits. None of them is the whole file. Testers who cannot reproduce a bug are not automatically negligent. Developers who publish a path because they think the fix is missing are not automatically reckless. They can still be wrong in ways that cost people money.

Useful anger looks like checklists and rehearsals. Useless anger looks like a week of quote-tweets and no change to who can halt a chain at 3 a.m. If operators walk away from August with only a new slogan, they will meet this story again under a different ticker.

The control that closes this attack path is the one you can prove against a working reproduction, not the one that photographs well in a status thread.

Where The Story Still Has Holes

Two exploited chains remain unnamed in the main technical recap. Recovery numbers are uneven. MANTRA had not retrieved stolen tokens as of August 28. KiiChain was told a majority of its stolen stack might still be reachable if the network comes back in a clean state. TAC’s sold slice is already someone else’s inventory on another chain. Legal process against exchange deposits will move at legal speed, which is not mempool speed.

We also do not yet have a public, shared timeline that lines up every researcher note, every release hash, and every first-probe transaction in one table that outsiders can audit. Until that exists, people will keep staring at the funding-before-disclosure coincidence and filling the silence with theories. MANTRA was right to refuse a conclusion it could not support. Readers are also right to want tighter clocks.

Will more Cosmos EVM chains admit they were in the unnamed set? Probably. Shame fades. Block explorers do not. When those names land, revisit the $5.72 million figure. Conversion estimates move when new sale routes appear.

A Practical Close For Teams Still Patching

If you run a validator, stop debating aesthetics and check the binary. If you run a foundation, publish whether you halted, when you halted, and which addresses you now watch that you did not watch on August 19. If you run a treasury, assume every “unspendable” label needs an alert. If you hold the token, size the position as if circulating supply can surprise you, because this month it did.

The Cosmos EVM vulnerability did not invent cross-chain risk. It showed how a shared execution layer, a quiet patch, and a short clock can turn three public brands and a handful of unnamed networks into one messy week. The code can be fixed. The habit of treating burn addresses as furniture is optional, and it should not survive this.

I keep coming back to that twenty-hour window. Not because it is a perfect morality play. Because it is measurable. You can argue about bounty triage for months. You cannot argue with a halt that never came until after the burn address moved. Next time the notes say “important,” someone in the validator chat should be bored enough, and empowered enough, to press stop.

The stock market is designed to transfer money from the active to the patient.
— Warren Buffett
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>