Cosmos EVM Shared-Code Exploit (2026) — Crypto Hack
Partially RecoveredAttacker exploited a balance underflow/overflow flaw in the shared Cosmos EVM code (GHSA-7g4w-cg88-2cq2), draining vesting accounts on six Cosmos EVM chains including MANTRA, TAC and KiiChain.
Summary
Attacker exploited a balance underflow/overflow flaw in the shared Cosmos EVM code (GHSA-7g4w-cg88-2cq2), draining vesting accounts on six Cosmos EVM chains including MANTRA, TAC and KiiChain.
How It Was Compromised — DeFi via Balance Underflow/Overflow (Vesting Account Delegation)
Between August 20-25, 2026, attackers exploited a critical vulnerability in the shared cosmos/evm code affecting six Cosmos EVM chains (MANTRA, TAC, KiiChain and others). The flaw: when a vesting account delegates more than its spendable balance through the staking precompile, an unchecked underflow wraps the EVM balance to ~2^256; the attacker then sent the underflowed balance to a victim account (burn address or genesis multisig), causing an overflow that left the attacker holding the victim's balance with no net supply change. MANTRA lost 720.9M tokens (~$3.6M) and halted; TAC lost ~2.99B TAC (~62% of circulating supply) and halted; KiiChain lost 148M KII (~$9.7M at cited price) and halted. MANTRA resumed on patched v8.4.0; Cosmos Labs urged all vulnerable chains to halt and upgrade to v0.6.2/v0.7.2. Attackers converted ~$5.72M total (~$2.87M via DEX, ~$2.85M via CEX).
Fund Flow & Laundering Analysis
Funds were bridged off affected chains (TAC via LayerZero OFT to BNB Chain, KII via Hyperlane) and sold through DEXs (KyberSwap, PancakeSwap) and centralized exchanges; some CEX-linked accounts were frozen, and ~54% of KII remained on-chain recoverable after the halt.