Security Incident
Cosmos EVM Vulnerability Drains MANTRA, TAC, and KiiChain Across Multiple Cross-Chain Attacks
According to reporting by crypto.news, a critical vulnerability within the Cosmos EVM framework was exploited across multiple blockchain networks between August 20 and August 25, converting stolen tokens into approximately $5.72 million worth of assets through various exchanges. This incident, which is not officially confirmed by independent law enforcement, highlights profound communication gaps in ecosystem-wide security patch deployments.

Vulnerability Genesis and Silent Patch Deployment
Published reports from crypto.news indicate that the security flaw originated from a numerical underflow mechanism within the Cosmos EVM framework, which is constructed directly from the open-source Evmos codebase. Malicious actors discovered that creating accounts containing locked tokens and delegating quantities exceeding spendable limits could force account balances to drop below zero, wrapping mathematical values around to the maximum possible parameters of 2^256-1 base units. By leveraging these inflated balances against targeted accounts, perpetrators were able to manipulate recorded figures across vulnerable ledgers without directly generating newly minted token supplies.
Initial bug bounty disclosures submitted months prior were incorrectly assessed by developers who concluded that production networks faced minimal exposure, leading to the deployment of public silent patches without explicit vulnerability advisories. When independent researchers subsequently demonstrated that live production environments remained highly vulnerable, developers rushed out modified software versions containing critical upgrades. However, the absence of clear operational warnings severely disadvantaged downstream network administrators attempting to secure their respective node infrastructures prior to the initiation of active exploitation campaigns across the broader ecosystem.
Escalation Across MANTRA, TAC, and KiiChain
The multi-network assault materialized rapidly after the release of patched software versions, with MANTRA suffering the largest publicly documented loss within the ecosystem. Approximately 720.9 million MANTRA tokens, valued at an estimated $3.6 million at the time of the incident, were extracted from two specific addresses comprising a designated network burn address and a dormant multi-signature wallet. Because internal monitoring systems erroneously treated the burn address as completely immovable, automated alerts failed to trigger during the initial outflow, granting malicious operators nearly four hours of uninterrupted access to drain remaining auxiliary funds before validators successfully executed a network halt.
Subsequent attacks struck additional projects including TAC and KiiChain utilizing identical underflow exploit mechanics to target staking pools and reserve accounts. TAC experienced the theft of nearly 3 billion tokens designed to support decentralized finance applications, with a substantial portion subsequently funneled into alternative blockchain liquidity pools for conversion. KiiChain similarly suffered the unauthorized extraction of approximately 148 million tokens before emergency countermeasures could be deployed. Project representatives from these networks voiced severe criticism regarding the lack of timely communication and coordinated emergency warnings from upstream framework maintainers.
Exchange Liquidation and Cross-Chain Asset Laundering
Stolen digital assets were systematically funneled through an intricate network of decentralized and centralized exchange venues to convert compromised tokens into stable and liquid market capital. Investigative findings show that malicious operators utilized centralized exchange deposit addresses to launder massive volumes of stolen funds rapidly, with a dominant percentage of MANTRA assets transferred across numerous sequential transactions within hours of the initial exploit. This rapid movement overwhelmed traditional compliance monitoring systems and underscored the persistent challenges associated with freezing illicitly obtained crypto assets once they enter high-volume trading environments.
Similarly, attackers targeting TAC bridged significant portions of their ill-gotten gains across alternative chains such as BNB Chain to execute automated swaps and avoid immediate traceability. Blockchain analytics firms observing the activities noted that while a portion of the plundered tokens suffered from extreme slippage due to depleted liquidity pools, millions of dollars in economic value were successfully extracted and converted. The reliance on centralized platforms for off-ramping stolen cryptocurrency continues to represent a critical pressure point for regulatory compliance and cross-chain security collaboration among major trading operators.
Ecosystem Wide Coordination and Unidentified Networks
In the wake of the multi-chain security breaches, core development entities initiated extensive coordination efforts involving dozens of public blockchain networks to prevent further catastrophic losses. Reports indicate that collaborative remediation channels were established with over forty distinct chains, successfully assisting a subset of networks in executing emergency patches or implementing chain halts prior to being compromised. However, the fluid nature of decentralized open-source development meant that numerous independent EVM deployments operating across the broader ecosystem lacked official registration or direct communication channels with upstream maintainers.
Further analytical disclosures from blockchain intelligence providers revealed that additional unnamed networks fell victim to identical exploitation vectors during the same operational window. For instance, analytics firms identified anomalous bridging transactions and severe liquidity pool drainage affecting networks like Nesa, where attackers leveraged consensus vulnerabilities to manipulate node verification parameters. The existence of these undisclosed and vulnerable chains emphasizes the profound difficulty of securing modular software architectures where downstream implementers frequently customize foundational components without maintaining synchronized security update protocols.
Conclusion and Ongoing Risk Assessment
In conclusion, the reported Cosmos EVM security incidents have exposed severe vulnerabilities in cross-chain software maintenance, affecting prominent entities such as MANTRA, TAC, and KiiChain alongside unconfirmed downstream networks. The affected user groups, including token holders and liquidity providers, faced substantial economic disruptions and sudden liquidity crunches. While project teams have scrambled to deploy emergency patches and resume block production, the stolen assets totaling approximately $5.72 million remain largely unrecovered, and these specific allegations are not officially confirmed by regulatory or judicial authorities.
Moving forward, affected networks and exchanges must implement rigorous upgrade verification standards and establish immediate communication protocols for critical security vulnerabilities. Users are advised to exercise heightened caution, refrain from interacting with unpatched protocols, and monitor official announcements closely. Independent risk intelligence desks will continue to track these developments without altering current ratings until verified official findings emerge from competent investigative bodies.
Cexvia conclusion
Conclusion and Ongoing Risk Assessment
The investigation published by crypto.news indicates that a numerical underflow vulnerability allowed unauthorized actors to manipulate account balances and drain multi-signature wallets, burn addresses, and staking pools across several networks. Affected entities include MANTRA, TAC, and KiiChain, impacting token holders and liquidity providers. This finding remains not officially confirmed by independent regulatory or judicial authorities.
- Risk meaning
- The exploitation exposes severe systemic fragilities in how silent patches are distributed and how multi-chain ecosystems manage coordinated emergency responses. When upstream framework developers withhold vulnerability-specific warnings during security upgrades, downstream network operators face insurmountable obstacles in protecting validator sets and safeguarding user funds effectively.
- User action
- Token holders and decentralized finance participants interacting with vulnerable blockchain networks should immediately verify the operational security status of their chosen platforms, monitor official communications for network halts, and avoid depositing assets into protocols that have not definitively confirmed the deployment of verified software patches.

