Cosmos Labs EVM Security Report: $5.72M Stolen From 6 Chains in August Breach

Cosmos Labs EVM Security Report: $5.72M Stolen From 6 Chains in August Breach

N
News Editor
2026-08-30 00:26:00
Cosmos Labs has issued a security incident report on its EVM module, detailing how attackers stole roughly $5.72 million from six Cosmos chains between August 20 and August 25. The violation was first flagged by MANTRA, after which the Cosmos security team coordinated with about 40 chains to assess and mitigate the risk. Around $2.87 million in bridged assets were sold on DEXes, while another $2.85 million went through CEX accounts that have since been frozen pending investigation. Thirteen other networks that faced potential risk patched, halted chains, or applied other safeguards before any losses occurred. The underlying vulnerability had originally been reported on April 25 through a bug bounty program, but testers could not reproduce it in production configurations, so the team fixed it without a public security advisory. Going forward, Cosmos Labs says it will strengthen triage and remediation for critical vulnerabilities, widen the scope of security communications, and bring in external experts for a full audit of its security practices.

Cosmos Labs has published a detailed post-mortem of a security incident tied to its EVM module. Between Aug. 20 and Aug. 25, attackers exploited a vulnerability in Cosmos EVM to drain funds from several chains in the Cosmos ecosystem. MANTRA was the first to raise the alarm, which led Cosmos' security team to coordinate roughly 40 chains on risk assessment and mitigation efforts.

The attack hit six networks. About $2.87 million in bridged assets were sold on decentralized exchanges, while another $2.85 million moved through centralized exchange accounts linked to the attackers. Those CEX accounts have been frozen, and the investigation is ongoing. That brings total reported losses to around $5.72 million.

Beyond the six affected chains, 13 other networks with potential exposure acted quickly — patching, halting chains, or applying other protections — and reported no further losses. The vulnerability itself was first reported back on April 25 through the bug bounty program. At the time, testers couldn't reproduce the issue on production network configurations, so the team determined it didn't endanger live funds and patched it without issuing a security notice.

Cosmos Labs said it will now accelerate triage and remediation of critical vulnerabilities, broaden its security communications, and work with outside experts on a comprehensive audit of internal security practices.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.