Cosmos EVM: One Bug Hit Four Blockchains, and the '$50M' Hacker Kept $60,000
One flaw in shared Cosmos code let attackers drain MANTRA, TAC, KiiChain and Nesa in five days. About $5.7M was cashed out. One '$50M' haul netted $60,000.

Key numbers
$5.72M
Stolen (cashed out)
6 (4 named)
Chains hit
~$60K
Nesa attacker's net profit
Apr 25, 2026
Bug first reported
On 24 August 2026 someone holding about $250,000 worth of NES, the token of a small blockchain called Nesa, turned it into what looked like $50 million. The balance went up roughly 200 times in a few transactions. The attacker then bridged the new fortune back to Ethereum and started selling. By the time the selling stopped, the price of NES had collapsed by more than nine tenths and the haul had fetched about $315,000. Net of what the tokens cost to buy in the first place, the profit was roughly $60,000. The wallet behind it had been funded through Monero, a cryptocurrency designed to hide who sent what, according to the analytics firm Bubblemaps.
Nesa was the fourth of four publicly named victims of the same bug in five days. MANTRA was hit on 20 August, TAC and KiiChain on 22 August, Nesa on 24 August. Cosmos Labs, the company that maintains the shared software all four ran, says six networks were exploited in total between 20 and 25 August. Two have never been named. By Cosmos Labs' own count, the attackers turned the stolen tokens into about $2.87 million on decentralised exchanges and an estimated $2.85 million on ordinary exchanges, a total of about $5.72 million.
The headline numbers were much larger. MANTRA lost 720.9 million of its tokens, worth about $3.6 million before the attack. TAC lost 2.99 billion tokens, about $7.5 million on paper. KiiChain lost 148.3 million KII, about $9.7 million. Nesa's "$50 million" was the most dramatic of all and the least real.
AI agents and automation
Could AI answer your customers from your own documents?
Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.
AI agents and automation
One piece of shared code
Cosmos is a family of more than 115 independent blockchains built from the same open-source toolkit, the way many different companies build cars on one manufacturer's chassis. Cosmos EVM is an add-on for that toolkit, maintained by Cosmos Labs, that lets a Cosmos chain run Ethereum-style apps: smart contracts, which are programs that move money by themselves, plus the wallets and tools Ethereum users already know. MANTRA, a chain aimed at tokenised real-world assets; TAC, built to bring Ethereum apps to the Telegram messaging app's TON network; KiiChain, a payments chain whose KII token had launched on 14 August; and Nesa, an AI-focused network, all ran it.
That is efficient until the chassis has a fault. Every chain using the add-on carried the same flaw, so finding it once meant finding it on all of them. Cosmos Labs says it coordinated with 40 chains during the attacks. Thirteen patched or halted in time. In the process it discovered eleven chains running Cosmos EVM that had never signed up for its security warnings.
How the bug worked
Each of these chains keeps two ledgers of the same money. The Ethereum-style side tracks only what an account can spend. The Cosmos side also tracks tokens that are locked. Locked tokens sit in what Cosmos calls a vesting account, the equivalent of staff shares that cannot be sold until they vest.
Locked tokens can still be staked. Staking means lending tokens to a validator, one of the computers that run the network, in return for a share of fees, a little like lodging shares as collateral. The flaw was that when a vesting account staked its locked tokens through the Ethereum-style side, that side subtracted them from the spendable balance it knew about. It subtracted more than was there, and it never checked.
Computer counters of this kind cannot go below zero. Like a car's mileage counter wound backwards past nothing, they roll round to the largest number they can show. The attacker's balance became, in effect, the maximum possible number of tokens.
The second step used the same trick in reverse. The attacker sent a carefully calculated slice of that impossible balance to a rich account, enough to push its counter past the top so that it rolled round to zero. The arithmetic left the victim account empty and the attacker holding what it used to contain. A malicious smart contract did both steps in one transaction, so the network's total supply barely moved and none of the normal alarms fired. Strictly, no tokens were minted. Existing ones were moved without permission.
The victims were whichever accounts held the most. On MANTRA, 600 million tokens came out of the burn address, the place where tokens are sent to be destroyed forever, and 120.9 million from a reserve wallet set up when the chain launched. On TAC, 2.99 billion tokens, 28.6% of the supply, came out of the pool holding everyone's staked coins. KiiChain was drained in 18 separate runs.
Fixed in May, released on a Wednesday, exploited on Thursday
The bug was not new to Cosmos Labs. A researcher reported it through its bug bounty programme, which pays outsiders for finding flaws, on 25 April 2026. Cosmos Labs tried to reproduce the theft on live-network settings, failed, and concluded the networks were safe. It merged a fix into its main code on 15 May without announcing it, the standard practice for a bug thought to be harmless, and planned to ship it later.
Further reports in the summer changed its mind. By 13 August it had confirmed every Cosmos EVM chain was exposed. Rather than warn chains privately, it disguised the fix and published new versions, v0.6.2 and v0.7.2, at 23:01 UTC on 19 August, with release notes that mentioned security fixes but not urgency. At 07:16 UTC the next morning a developer at Push Chain, another Cosmos EVM user, opened a public pull request on GitHub that described the flaw and how to exploit it in detail, crediting an audit by the security firm Hacken. Less than twelve hours later MANTRA was being drained.
MANTRA halted its chain 14 minutes after the second attack. Cosmos Labs told chains on its private security list to upgrade. Upgrading meant 38 or more independent validator operators testing and installing new software, which takes days. TAC was hit about 45 hours after MANTRA. Only then, at 23:45 UTC on 22 August, did Cosmos Labs tell every chain to stop producing blocks immediately. KiiChain had already been emptied.
Where the money went

TAC's attacker bridged the tokens to BNB Chain within about 95 seconds, a bridge being a service that moves tokens between blockchains, and sold 1.21 billion of them in about 80 small trades for 950,293 USDT, a digital dollar issued by Tether. With a smaller sale on TON, TAC puts the proceeds at about $1 million. The other 1.66 billion TAC never sold.
KiiChain's attacker moved 67.6 million KII to BNB Chain and sold 64.6 million for 1,607,323 USDT. The other 80.7 million KII, 54.4% of the haul, was still on KiiChain when it halted.
MANTRA's attacker sent 683 million tokens, 94.7% of the take, to a single exchange deposit address in 15 scripted transfers before the chain stopped. Cosmos Labs says the exchange accounts the attackers used have been frozen pending a police investigation. Nobody has been named or charged.
Thin markets did the rest. Each token was small, so every sale drove its own price down. KII fell about 83% on the day. MANTRA's token fell 18.5% to a record low of $0.004126 during its halt. NES fell from about $0.196 to $0.013 on the day of the attack, and the Nesa attacker's last sales went through at $0.0003. A sum that existed only at the old price could not survive being sold.
The aftermath
No stolen money has been returned voluntarily, and nobody has been identified or charged. What has been clawed back came from freezes and from chains rewriting their own records. Cosmos Labs says the exchange accounts used to cash out about $2.85 million have been frozen pending a police investigation.
TAC stayed halted for 13 days. Its foundation promised to replace the roughly 1.26 billion tokens the attacker sold from its own treasury, wrote 65.1 million frozen attacker tokens out of the ledger, and restarted on 4 September with the staking pool restored. On BNB Chain it took a snapshot at block 119,573,620 on 2 September and swapped every holder to a new token contract, leaving the attacker's 1.66 billion TAC on the old, worthless one. It was TAC's second hack of 2026: in May a separate $2.8 million attack on its TON link was reclassified as a white hat incident after the hacker returned the funds for a 10% bounty.
KiiChain resumed on 28 August and said the 80.7 million KII stuck on its chain would go to recovery wallets. Its post-mortem was blunt about Cosmos Labs: a patch takes days, a halt takes minutes, and the halt instruction came after the damage was done.
MANTRA restarted on 22 August without rolling back its history, which meant 720.9 million tokens once regarded as dead were now in circulation. MANTRA's own post-mortem said twenty hours was not a realistic window to upgrade 38 independent validators without a specific warning. As of 28 August none of its tokens had been recovered. The incident landed in the middle of Inveniam Capital Partners' proposed takeover of MANTRA, and on a token that had already lost about 90% of its value in a single crash in April 2025.
Nesa's recovery split its holders by where they kept their coins. Binance Alpha offered a 1:1 swap only for NES held before 14:51 UTC on 24 August and still held when trading was suspended on 5 September; later buyers were promised a refund on terms not fully published. Kraken moved holders 1:1 to a new Ethereum contract and dropped BNB Chain support. People holding NES in their own wallets were left without a clear route at first.
Cosmos Labs called its April assessment a mistake, said it would set public rules on when to tell chains to halt rather than upgrade, and asked developers not to publish exploit details. It pointed out it had patched 37 vulnerabilities silently in 13 months without one leaking.
What this teaches
- Shared code means shared risk. One flaw in Cosmos EVM was the same flaw on every chain that used it, and the attacker simply went down the list.
- A quiet fix only works while nobody notices it. Once the patch was public and a downstream developer described it, the 20-hour gap before the first attack was not enough time for 38 validators to upgrade.
- Halting is fast, upgrading is slow. The instruction to stop blocks came after the second chain fell; KiiChain was drained within the hour.
- Paper losses are not real losses. Tokens worth $50 million at the old price fetched $315,000 once someone tried to sell them all at once.
- Accounts no one expects to move, such as burn addresses, launch reserves and staking pools, hold the biggest balances and were the first targets.
COMMENTS