Threat reportVulnerabilityTL-2026-2194
Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchains
Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) (TL-2026-2194), also tracked as Cosmos EVM Balance-Handling Flaw, is a critical-severity software vulnerability, first published 2026-08-28. It has no confirmed attribution, affects Cosmos Labs Cosmos EVM module (cosmos/evm), maps to 9 MITRE ATT&CK techniques (T1036, T1190, T1485), and is covered by 9 detection rules and 14 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-2194
- Threat ID
- TL-2026-2194
- Also known as
- Cosmos EVM Balance-Handling Flaw, GHSA-7g4w-cg88-2cq2
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, cryptocurrency, blockchain-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
How Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) works
A critical integer-underflow flaw in the shared Cosmos EVM module's StateDB SubBalance write-back let an attacker deploy a contract disguised as a vesting account, delegate one wei more than its spendable balance, and wrap the resulting balance to roughly 2^256. Cosmos Labs silently patched the bug (v0.6.2 / v0.7.2) on August 19, 2026 without private notification to downstream chains; attackers began exploiting MANTRA on August 20, then TAC, KiiChain, and Nesa, liquidating roughly $5.72 million across six blockchains by August 25, 2026.
In April 2026, a researcher reported a balance-reconciliation bug in the Cosmos EVM module — the shared EVM-compatibility layer used by dozens of independent Cosmos SDK blockchains — through Cosmos Labs' bug bounty program. Cosmos Labs initially assessed the report as low-risk, reasoning it only affected chains using six-decimal token configurations rather than the 18-decimal configuration used by most production Cosmos EVM chains. A fix was merged silently into the main codebase around May 15, 2026 (PR #1176), without a security advisory. On August 13, 2026, Cosmos Labs' own further review confirmed the flaw actually affected all Cosmos EVM chains regardless of decimal configuration, but the team still elected to ship the fix as a standard public release rather than a coordinated private disclosure.
The root defect (GHSA-7g4w-cg88-2cq2, no CVE assigned) is an unsigned-integer underflow in the EVM StateDB's `SubBalance` write-back, which is invoked via the Cosmos EVM staking precompile's post-delegation accounting. The StateDB maintains only a spendable-balance view, while vesting accounts hold both a spendable and a locked balance component; when a vesting account delegates more than its spendable balance (a delegation the `x/staking` module and staking precompile otherwise permit), `SubBalance` subtracts the full delegated amount from the smaller spendable figure with no bounds check, wrapping the account's mirrored EVM balance to approximately 2^256. Because permissionless vesting-account creation was allowed, an attacker did not need a pre-existing vesting account: they computed the deterministic address a to-be-deployed contract would occupy, converted that address into a vesting account, then deployed the exploit contract onto it — inheriting vesting status and unlocking the vulnerable delegation code path. This underflow supported two distinct exploitation paths: (1) delegate one wei beyond the spendable balance to wrap the attacker's own account to ~2^256, then withdraw far more than was ever legitimately owned, or (2) — the more destructive variant — direct a victim account to receive an amount equal to 2^256 minus its existing balance, forcing the same reconciliation logic to burn that victim's real holdings. Both paths extract or destroy value without inflating the chain's total token supply, chaining the underflow on one account against a corresponding overflow effect on another. Cosmos Labs' eventual fix (PRs #1176, #1253, #1254) added an explicit underflow guard directly to the StateDB `SubBalance` write-back.
Cosmos Labs published the patched releases (v0.6.2 for the <0.6.2 branch, v0.7.2 for the >=0.7.0 <0.7.2 branch) on GitHub on August 19, 2026, with no advance private notice to downstream chain teams, no security-critical labeling in the release notes, and — per post-incident reporting — the underlying security backports omitted from the v0.6.2/v0.7.2 changelogs entirely. This silent-patch pattern was not new: an estimated 37 other vulnerabilities in the module had reportedly been patched without public advisories over the preceding 13 months. On August 20, 2026 at 07:16 UTC, a public pull request against a fork of the code (attributed in early reporting to the Push Chain project) disclosed enough detail about the vulnerability and its exploitation path that an attacker began the first unauthorized transaction against MANTRA Chain roughly 11 hours 50 minutes later, at 19:06 UTC. MANTRA detected the anomalous activity on two of its own project-controlled wallets — reported at approximately $3.6 million / 720.9 million tokens moved — and halted block production at block 17,449,398 (23:13 UTC) the same day, roughly 14 minutes after the second debit; the team maintains no third-party user funds were exploited. Cosmos Labs did not send its first private notification to affected operators until 03:36 UTC on August 21 — after the exploitation had already begun.
MANTRA resumed block production around 05:30 UTC on August 22, 2026 (a roughly 30-hour outage) after a coordinated validator upgrade to v8.4.0. In the same window, roughly 45 hours after the MANTRA attack, the same class of exploit hit TAC (halted at block 24,671,475 after a single large account was drained of an amount equal to roughly 62% of circulating TAC supply) and KiiChain, where an attacker repeated the technique 18 times before validators halted the chain at block 9,355,723, draining 148,326,583.15 KII. The attacker bridged a portion of the KiiChain proceeds to BNB Smart Chain via the Hyperlane cross-chain messaging protocol and began liquidating; post-incident reporting on recovered/frozen amounts varied by source, with one tally citing roughly 54.4% of KiiChain-denominated proceeds still frozen in attacker-linked addresses and another aggregate figure citing on the order of 38 million tokens immobilized across the exploited chains pending exchange or law-enforcement action. Nesa, a separate Cosmos EVM chain, also suspended operations on August 24, 2026 after being hit; its native NES token fell more than 94%, and KII and TAC also lost over 90% of value within hours of their respective incidents. Cosmos Labs' original Hacker News-reported disclosure additionally names ZetaChain, Warden Protocol, and Push Chain-derived forks among the six blockchains affected by the incident window, though public reporting to date has published exploitation specifics only for MANTRA, TAC, KiiChain, and Nesa.
By August 25, 2026, Cosmos Labs was urging every Cosmos EVM chain operator it could reach — ultimately around 40 networks, 13 of which were found to be potentially exposed and patched, halted, or otherwise mitigated in response — to halt validators pending confirmed patch deployment, and had discovered 11 previously unknown/unregistered Cosmos EVM deployments in the process. Total confirmed losses across the six exploited chains reached approximately $5.72 million (roughly $2.87M liquidated via DEX routes and $2.85M via centralized-exchange routes) by the close of the exploitation window on August 25, 2026. This is the second Cosmos EVM shared-module incident of 2026: a related but distinct flaw in the ICS20 precompile (ASA-2026-002 / GHSA-54gx-3cgr-7mfm, involving incorrect state handling during nested EVM execution) had already cost the Saga EVM network approximately $7 million in January 2026, underscoring a pattern of shared-dependency risk across the Cosmos EVM ecosystem.
MITRE ATT&CK techniques used in TL-2026-2194
Defense Evasion
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1485 Data Destruction; T1565.001 Stored Data Manipulation; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1587.004 Exploits; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2)
- Cosmos Labs — Cosmos EVM module (cosmos/evm)
Vulnerable versions: <0.6.2; >=0.7.0 <0.7.2
Fixed in: 0.6.2; 0.7.2 - MANTRA Chain — MANTRA Chain (Cosmos EVM-based RWA L1)
Vulnerable versions: pre-v8.4.0 Cosmos EVM deployment
Fixed in: v8.4.0 - TAC — TAC (TON network Cosmos EVM extension chain)
Vulnerable versions: pre-patch Cosmos EVM deployment
Fixed in: patched Cosmos EVM module (0.6.2/0.7.2 line) - KiiChain — KiiChain (on-chain forex Cosmos EVM L1)
Vulnerable versions: pre-patch Cosmos EVM deployment
Fixed in: patched Cosmos EVM module (0.6.2/0.7.2 line) - Nesa — Nesa (lightweight Cosmos EVM L1)
Vulnerable versions: pre-patch Cosmos EVM deployment
Fixed in: patched Cosmos EVM module (0.6.2/0.7.2 line)
Remediation for Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2)
Patches
- cosmos/evm v0.6.2 (for deployments on the <0.6.2 branch)
- cosmos/evm v0.7.2 (for deployments on the >=0.7.0 <0.7.2 branch)
- cosmos/evm PR #1176 (initial underflow-guard merge, May 15, 2026)
- cosmos/evm PR #1253 and PR #1254 (backported StateDB SubBalance underflow-guard fixes)
- MANTRA Chain v8.4.0 coordinated validator upgrade
Immediate actions
- Upgrade every Cosmos EVM deployment to v0.6.2 (for the <0.6.2 branch) or v0.7.2 (for the >=0.7.0 <0.7.2 branch) via a coordinated, state-breaking network upgrade
- Halt validator block production on any Cosmos EVM chain that cannot complete the upgrade immediately, rather than continuing to produce blocks on vulnerable code
- Reject vesting-account creation messages at the ante-handler level as an interim mitigation on chains that cannot immediately upgrade, closing off the permissionless-vesting-account precondition the exploit relies on
- Audit vesting-account creation events and staking-precompile delegation records since April 2026 for anomalous balance deltas or underflow/overflow patterns
- Verify the underflow-guard fix is present in the actual live StateDB SubBalance code path exercised at runtime, not merely in exported/library helper functions
- Contact security@cosmoslabs.io to confirm exposure status and coordinate patch deployment for any previously unregistered Cosmos EVM fork or deployment
Workarounds
- Halt validator/block production on the affected chain until the coordinated network upgrade can be applied
- Reject vesting-account creation messages via the ante handler to remove the precondition the exploit chain depends on
- Freeze or blacklist attacker-linked addresses holding unrecovered funds pending bridge-level or law-enforcement intervention
Longer-term hardening
- Move to coordinated, embargoed private security-advisory distribution for shared-dependency vulnerabilities across the Cosmos EVM ecosystem instead of silent public patches merged straight to a public branch — a practice reportedly used for 37 other vulnerabilities in the module over the preceding 13 months
- Add bounds/invariant checks on every balance-mutating precompile code path (staking, ICS20, x/bank reconciliation) so a write that would underflow or overflow a spendable balance is rejected rather than wrapped
- Build fleet-wide, automated version and exposure tracking across the ~40+ networks running the shared Cosmos EVM module, including mandatory security-contact registration, so future patches can be pushed with full downstream visibility
- Deploy anomaly-based transaction monitoring and automatic circuit breakers on validator infrastructure to auto-halt block production on abnormal balance deltas
Weaknesses (CWE) in Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2)
Timeline of Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2)
- Vulnerability in the Cosmos EVM balance-reconciliation logic reported to Cosmos Labs via its bug bounty program; internally assessed as low-risk to live networks based on a six-decimal-vs-eighteen-decimal token configuration assumption.
- Fix (PR #1176) merged into the cosmos/evm main codebase without a public security advisory or coordinated notification to downstream chains.
- Cosmos Labs' further review confirmed the flaw affected all Cosmos EVM chains regardless of token decimal configuration, contradicting the original low-risk assessment.
- Cosmos Labs publicly released patched versions v0.6.2 and v0.7.2 (backporting PRs #1253/#1254) on GitHub with no advance private notice, no security-critical labeling, and the security backports omitted from the changelogs entirely.
- MANTRA Chain halted block production at block 17,449,398 (23:13 UTC), roughly 14 minutes after the second debit, after detecting anomalous activity on the two project-controlled wallets.
- First unauthorized exploitation transaction executed against MANTRA Chain at 19:06 UTC, roughly 11h50m after the public exploit-path disclosure; two project-controlled wallets were debited approximately $3.6 million / 720.9 million tokens.
- A public pull request (07:16 UTC), attributed in early reporting to the Push Chain project, disclosed enough detail on the vulnerability and its exploitation path to enable attackers to reverse-engineer the exploit.
- Cosmos Labs sent its first private notification to affected chain operators at 03:36 UTC, after exploitation had already begun.
- TAC and KiiChain exploited roughly 45 hours after the MANTRA attack; KiiChain's attacker repeated the technique 18 times before validators halted the chain at block 9,355,723, draining 148,326,583.15 KII, while TAC halted at block 24,671,475 after a single account was drained of roughly 62% of circulating supply.
- MANTRA resumed block production around 05:30 UTC, roughly 30 hours after the halt, following a coordinated validator upgrade to v8.4.0.
- Nesa suspended chain operations after being hit by the same exploit class; its NES token fell more than 94%.
- Cosmos Labs urged validators across all reachable Cosmos EVM chains to halt pending confirmed patch deployment, contacting roughly 40 networks and identifying 13 as potentially exposed; exploitation window closed with total losses near $5.72 million across six chains, and 11 previously unregistered Cosmos EVM deployments were discovered in the process.
- Post-incident technical reporting detailed the exact StateDB SubBalance underflow mechanism, the silent-patch history (37 other vulnerabilities patched without advisories over the preceding 13 months), and mixed recovery figures for stolen funds across the affected chains.
Sources cited for Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2)
- Cosmos EVM Flaw Exploited After Cosmos Labs Downplayed Bug Bounty Report
- Cosmos EVM Balance-Handling Flaw Advisory - GHSA-7g4w-cg88-2cq2
- Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains
- Cosmos EVM Chains Ordered to Halt as Security Incident Spreads Across Shared Blockchain Stack
- MANTRA Freezes Its Chain and Falls to a Record Low After Exploit
- Cosmos Labs Urges Cosmos EVM Chains to Halt Validators, Three Now Offline
- Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks
- Cosmos EVM chains told to halt after security incident
- Cosmos Releases Critical Security Patch Without Notification, Projects Lose Funds to Hackers
- ASA-2026-002 (prior, related): ICS20 Precompile Nested-Execution Flaw - GHSA-54gx-3cgr-7mfm
Detection coverage for TL-2026-2194
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2194 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.