
Photo: Illustrative
Cosmos Labs Admits Misjudging Bug That Led to $5.7M Multi Chain Hack
Cosmos Labs has acknowledged it incorrectly assessed a software vulnerability that attackers later exploited to steal roughly $5.7 million across six blockchain networks between August 20 and 25. According to the company's technical review, the flaw existed in Cosmos EVM, shared infrastructure that allows Cosmos-based chains to run Ethereum-style applications. Stolen funds were split between decentralized and centralized exchanges before some attacker accounts were frozen pending investigation.

Cosmos Labs has acknowledged it incorrectly assessed a software vulnerability that attackers later exploited to steal roughly $5.7 million across six blockchain networks between August 20 and 25. According to the company’s technical review, the flaw existed in Cosmos EVM, shared infrastructure that allows Cosmos-based chains to run Ethereum-style applications. Stolen funds were split between decentralized and centralized exchanges before some attacker accounts were frozen pending investigation.
Vulnerability Was Reported Months Earlier but Misclassified
A security researcher had flagged the bug back in April through Cosmos Labs’ bug bounty program. At the time, testers concluded that live networks weren’t actually at risk and quietly patched the issue without issuing a public security advisory. That decision proved costly: independent researchers later determined in August that the flaw did in fact affect all Cosmos EVM chains, prompting an urgent, though vaguely worded, patch release just 20 hours before the first attack began.
How the Exploit Worked
The attack relied on a technical flaw called integer underflow, which tricked the system into crediting attacker wallets with an enormous, effectively unlimited token balance. This inflated balance was then transferred to drain targeted accounts, including old wallets and burn addresses, without actually creating new tokens or changing total token supply.
Affected Networks and Losses
One affected network lost the equivalent of $3.6 million from its burn address and a dormant wallet, a loss that went undetected for hours because that address wasn’t actively monitored. Two other named networks lost close to $950,000 and $1.6 million respectively, while three additional unnamed chains were also compromised using the same method. A blockchain analytics firm has pointed to a possible seventh case, though details remain unconfirmed.
Fallout and Response
One affected network publicly criticized Cosmos Labs’ disclosure process, arguing that a 20-hour window was not enough time to properly coordinate a network wide upgrade without a clear vulnerability warning. It has since called for more transparent security communication going forward.
Live market reaction
Disclaimer
This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.
Start trading
with BloFin today
Up to $500 sign-up bonus and zero-fee trading on your first 30 days.
Buy crypto nowⓘ You will be redirected to BloFin
About the author

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.


