digital asset2026-09-11 08:03:23After the Liquid Network exploit, the real test for crypto platforms is how far risk can spreadA string of recent security incidents has pushed a familiar question back to the center of the digital asset industry: what does a platform’s security actually look like once the first line of defense fails? In early September, Bitcoin sidechain Liquid Network suffered a major incident tied to an Elements validation flaw, leading to the transfer of roughly 4,000 BTC, valued at about $320 million at the time. The reported detail that PAK and Federation keys themselves were not compromised sharpened the issue: even without key theft, how did an unauthorized transfer still move through the system? The article places that case alongside an August Cosmos EVM vulnerability that was used against six networks despite having been reported through a bug bounty program, and a July social engineering attack on Triple-A that exposed corporate funds but did not affect customer assets because those funds were held separately in trust accounts and isolated from the breached operating environment. Using BIT’s Trust White Paper V2.0 as a reference point, the report examines layered controls across identity, permissions, operational approvals, monitoring, cold wallet storage, security team veto power, and verifiable regulatory arrangements as the factors that determine whether a breach stays contained or becomes systemic.820
Nesa2026-09-07 03:12:06Nesa says revised NES contract is being deployed to exchanges as migration continuesNesa said on X that its revised NES token contract is now being deployed across exchanges and that the migration process is still underway. The project also shared the updated contract address as part of that rollout. The update follows an earlier report cited by Foresight News that Cosmos Labs had disclosed a security flaw in its shared Cosmos EVM software. According to that report, multiple chains built with the module were affected, including Nesa. The latest notice from Nesa focuses on exchange-side deployment of the revised contract and the ongoing token migration.910
security inci2026-09-02 10:20:11Crypto Security Losses Hit $215M in August: Price Manipulation and Governance Flaws DominantAugust 2026 saw a total of $215 million in crypto security losses, a sharp increase from July's $97 million, making it the third-highest month of the year. Price manipulation attacks emerged as the top threat, with the Tectonic incident alone causing $75 million in damages. Governance vulnerabilities and upstream dependency exploits also played significant roles, with Term Finance losing $8.5 million and Cosmos EVM bug affecting six chains. Phishing scams evolved, including expired domain hijacking and a fake Trump-themed rug pull. ZeroTech Security recommends stronger governance controls, multi-source oracle pricing, and user vigilance against phishing links.1260
Cronos2026-08-31 03:00:09Cronos, Fogo and Cosmos EVM Chains Turned to Shutdowns as Last-Resort Crisis ResponseThree separate incidents across Cronos, Fogo, and chains using the Cosmos EVM module ended with the same emergency measure: stop the chain. On Aug. 30, Cronos validators froze the network after an attacker allegedly manipulated TONIC, a thinly traded governance token tied to the Tectonic lending protocol, and used inflated collateral to borrow about $75 million in assets such as cbBTC, USDC, and WETH. According to on-chain researcher Weilin Li, the attacker held about 364.6 trillion TONIC, and the math implied a post-manipulation collateral value of roughly $375 million. Validators halted the chain before most of the funds could leave; around $6 million was bridged to Ethereum, while about $60 million remained stuck on Cronos. Fogo followed a different path. The Fogo Foundation said on Aug. 29 at 9:13 PM ET that an unknown attacker had "compromised" the foundation and transferred 400 million FOGO tokens. The foundation initially said the blockchain itself was unaffected and kept running, but about 15 hours later the mainnet was paused so validators could upgrade the network to "restrict addresses associated with unauthorized activity." The stolen amount represented 4% of the 10 billion genesis supply and more than 10% of circulating supply. Cosmos EVM exposed a supply-chain problem rather than a single-chain failure. Cosmos Labs said a bug in the shared open-source module affected all chains running it, and on Aug. 24 urged validators to halt if they could not immediately coordinate a state-breaking upgrade. The incidents landed differently in the market, but together they showed how quickly decentralization debates return when validator coordination becomes the final line of defense.1080
Cosmos Labs2026-08-29 20:26:13Cosmos Labs says misjudged Cosmos EVM bug after six chains lost about $5.7 millionCosmos Labs said in a technical report that it had previously misjudged an integer underflow vulnerability in Cosmos EVM, a flaw later exploited across six blockchain networks between Aug. 20 and Aug. 25. The attacks resulted in roughly $5.7 million in stolen tokens, according to the report. The company said attackers used the bug to push an account balance down to the maximum value of 2^256-1 through underflow, then reversed the operation and transferred out the inflated balance. The report added that the exploit did not mint tokens out of thin air. A researcher first submitted the flaw through a bug bounty program on April 25, but testers could not reproduce it under the existing Cosmos chain configuration. Cosmos Labs said it issued a silent patch in May. After an independent researcher confirmed in early August that the issue affected all Cosmos EVM chains, Cosmos Labs released a patch on Aug. 19. The first attack followed about 20 hours later. Among the disclosed losses, MANTRA lost 720.9 million tokens, worth about $3.6 million. TAC lost nearly 3 billion TAC, while KiiChain lost about 148 million KII. MANTRA and KiiChain criticized Cosmos Labs for not notifying affected chains in advance and not recommending a shutdown.900
Cosmos2026-08-29 00:40:24ICF Launches Discretionary Grant Program to Support Chains Affected by Cosmos EVM IncidentThe Interchain Foundation (ICF) said it remains committed to supporting the Cosmos ecosystem, while acknowledging that the recent Cosmos EVM incident has affected teams that rely on Cosmos technology for their deployments. To help those teams, ICF is establishing a discretionary grant program aimed at supporting affected chains that are cooperating with remediation efforts. As part of the same program, the foundation said it will work with the community to invest resources in strengthening security practices, improving infrastructure, and enhancing incident response capabilities across the ecosystem. The foundation also said it will continue to invest in the resilience and safety of Cosmos, and that further details of the new grant program will be announced in the coming days. The announcement reflects ICF's ongoing focus on the health and security of the broader Cosmos network, though the foundation has not yet specified the program's scope or funding amount.890
Cosmos Labs2026-08-27 02:33:15Cosmos Labs urges older Cosmos EVM chains to halt and upgrade to patched releasesCosmos Labs said in a post that many chains affected by the current security incident have already completed patch upgrades. The team added that it will continue providing mitigation information to affected chains. It also urged any chain running a Cosmos EVM version lower than v0.6.2 or v0.7.2 to halt immediately and upgrade to a release that includes the patch. The statement was published through Cosmos Labs’ official X account and addressed operators of chains still using older versions during the ongoing incident. The update did not disclose additional technical details in the brief notice, but it made clear that patched versions are now the recommended path for chains still exposed under the version thresholds cited by the team.930
Bubblemaps2026-08-26 14:03:54Bubblemaps says $50 million NES exploit yielded only about $60,000 in profitBlockchain analytics platform Bubblemaps said an attacker exploited a vulnerability in the shared Cosmos EVM module to steal $50 million worth of NES tokens, but ended up making only about $60,000. Cosmos Labs had previously disclosed a security issue in its shared Cosmos EVM software, which affected several chains built on the module, including Nesa. According to Bubblemaps, the main attacker used a wallet beginning with 0x9AE7, spent $250,000 to buy NES, bridged the tokens to Nesa Chain, then inflated the account balance by 200x through the exploit before bridging $50 million worth of NES back to Ethereum. The wallet’s initial funding reportedly came from Monero. The attacker then split the tokens across multiple wallets, swapped NES for ETH on decentralized exchanges, and deposited the proceeds to centralized exchanges. Bubblemaps said liquidity was pulled from the pools quickly, causing severe slippage on most swaps. As a result, the attacker spent $255,000 in total and cashed out only $315,000, leaving net profit at roughly $60,000. The report also said a separate $1.4 million exploit on another Cosmos EVM chain the previous day may have involved a different attacker.1060