# Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchains

> A critical integer-underflow flaw in the shared Cosmos EVM module's StateDB SubBalance write-back let an attacker deploy a contract disguised as a vesting account, delegate one wei more than its spendable balance, and wrap the resulting balance to roughly 2^256. Cosmos Labs silently patched the bug (v0.6.2 / v0.7.2) on August 19, 2026 without private notification to downstream chains; attackers began exploiting MANTRA on August 20, then TAC, KiiChain, and Nesa, liquidating roughly $5.72 million across six blockchains by August 25, 2026.

- **Published:** 2026-08-28T00:00:00Z
- **Last reviewed:** 2026-08-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2194
- **ID:** TL-2026-2194
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In April 2026, a researcher reported a balance-reconciliation bug in the Cosmos EVM module — the shared EVM-compatibility layer used by dozens of independent Cosmos SDK blockchains — through Cosmos Labs' bug bounty program. Cosmos Labs initially assessed the report as low-risk, reasoning it only affected chains using six-decimal token configurations rather than the 18-decimal configuration used by most production Cosmos EVM chains. A fix was merged silently into the main codebase around May 15, 2026 (PR #1176), without a security advisory. On August 13, 2026, Cosmos Labs' own further review confirmed the flaw actually affected all Cosmos EVM chains regardless of decimal configuration, but the team still elected to ship the fix as a standard public release rather than a coordinated private disclosure.

The root defect (GHSA-7g4w-cg88-2cq2, no CVE assigned) is an unsigned-integer underflow in the EVM StateDB's `SubBalance` write-back, which is invoked via the Cosmos EVM staking precompile's post-delegation accounting. The StateDB maintains only a spendable-balance view, while vesting accounts hold both a spendable and a locked balance component; when a vesting account delegates more than its spendable balance (a delegation the `x/staking` module and staking precompile otherwise permit), `SubBalance` subtracts the full delegated amount from the smaller spendable figure with no bounds check, wrapping the account's mirrored EVM balance to approximately 2^256. Because permissionless vesting-account creation was allowed, an attacker did not need a pre-existing vesting account: they computed the deterministic address a to-be-deployed contract would occupy, converted that address into a vesting account, then deployed the exploit contract onto it — inheriting vesting status and unlocking the vulnerable delegation code path. This underflow supported two distinct exploitation paths: (1) delegate one wei beyond the spendable balance to wrap the attacker's own account to ~2^256, then withdraw far more than was ever legitimately owned, or (2) — the more destructive variant — direct a victim account to receive an amount equal to 2^256 minus its existing balance, forcing the same reconciliation logic to burn that victim's real holdings. Both paths extract or destroy value without inflating the chain's total token supply, chaining the underflow on one account against a corresponding overflow effect on another. Cosmos Labs' eventual fix (PRs #1176, #1253, #1254) added an explicit underflow guard directly to the StateDB `SubBalance` write-back.

Cosmos Labs published the patched releases (v0.6.2 for the <0.6.2 branch, v0.7.2 for the >=0.7.0 <0.7.2 branch) on GitHub on August 19, 2026, with no advance private notice to downstream chain teams, no security-critical labeling in the release notes, and — per post-incident reporting — the underlying security backports omitted from the v0.6.2/v0.7.2 changelogs entirely. This silent-patch pattern was not new: an estimated 37 other vulnerabilities in the module had reportedly been patched without public advisories over the preceding 13 months. On August 20, 2026 at 07:16 UTC, a public pull request against a fork of the code (attributed in early reporting to the Push Chain project) disclosed enough detail about the vulnerability and its exploitation path that an attacker began the first unauthorized transaction against MANTRA Chain roughly 11 hours 50 minutes later, at 19:06 UTC. MANTRA detected the anomalous activity on two of its own project-controlled wallets — reported at approximately $3.6 million / 720.9 million tokens moved — and halted block production at block 17,449,398 (23:13 UTC) the same day, roughly 14 minutes after the second debit; the team maintains no third-party user funds were exploited. Cosmos Labs did not send its first private notification to affected operators until 03:36 UTC on August 21 — after the exploitation had already begun.

MANTRA resumed block production around 05:30 UTC on August 22, 2026 (a roughly 30-hour outage) after a coordinated validator upgrade to v8.4.0. In the same window, roughly 45 hours after the MANTRA attack, the same class of exploit hit TAC (halted at block 24,671,475 after a single large account was drained of an amount equal to roughly 62% of circulating TAC supply) and KiiChain, where an attacker repeated the technique 18 times before validators halted the chain at block 9,355,723, draining 148,326,583.15 KII. The attacker bridged a portion of the KiiChain proceeds to BNB Smart Chain via the Hyperlane cross-chain messaging protocol and began liquidating; post-incident reporting on recovered/frozen amounts varied by source, with one tally citing roughly 54.4% of KiiChain-denominated proceeds still frozen in attacker-linked addresses and another aggregate figure citing on the order of 38 million tokens immobilized across the exploited chains pending exchange or law-enforcement action. Nesa, a separate Cosmos EVM chain, also suspended operations on August 24, 2026 after being hit; its native NES token fell more than 94%, and KII and TAC also lost over 90% of value within hours of their respective incidents. Cosmos Labs' original Hacker News-reported disclosure additionally names ZetaChain, Warden Protocol, and Push Chain-derived forks among the six blockchains affected by the incident window, though public reporting to date has published exploitation specifics only for MANTRA, TAC, KiiChain, and Nesa.

By August 25, 2026, Cosmos Labs was urging every Cosmos EVM chain operator it could reach — ultimately around 40 networks, 13 of which were found to be potentially exposed and patched, halted, or otherwise mitigated in response — to halt validators pending confirmed patch deployment, and had discovered 11 previously unknown/unregistered Cosmos EVM deployments in the process. Total confirmed losses across the six exploited chains reached approximately $5.72 million (roughly $2.87M liquidated via DEX routes and $2.85M via centralized-exchange routes) by the close of the exploitation window on August 25, 2026. This is the second Cosmos EVM shared-module incident of 2026: a related but distinct flaw in the ICS20 precompile (ASA-2026-002 / GHSA-54gx-3cgr-7mfm, involving incorrect state handling during nested EVM execution) had already cost the Saga EVM network approximately $7 million in January 2026, underscoring a pattern of shared-dependency risk across the Cosmos EVM ecosystem.

## MITRE ATT&CK

- T1593.003 Code Repositories
- T1588.006 Vulnerabilities
- T1587.004 Exploits
- T1190 Exploit Public-Facing Application
- T1036 Masquerading
- T1567 Exfiltration Over Web Service
- T1565.001 Stored Data Manipulation
- T1485 Data Destruction
- T1657 Financial Theft

## Sources

- [Cosmos EVM Flaw Exploited After Cosmos Labs Downplayed Bug Bounty Report](https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html)
- [Cosmos EVM Balance-Handling Flaw Advisory - GHSA-7g4w-cg88-2cq2](https://github.com/cosmos/evm/security/advisories/GHSA-7g4w-cg88-2cq2)
- [Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains](https://cryptoslate.com/cosmos-misjudged-a-critical-bug-for-4-months-before-hackers-stole-nearly-6-million-across-6-chains/)
- [Cosmos EVM Chains Ordered to Halt as Security Incident Spreads Across Shared Blockchain Stack](https://www.cryptometer.io/news/cosmos-evm-chains-ordered-to-halt-as-security-incident-spreads-across-shared-blockchain-stack/)
- [MANTRA Freezes Its Chain and Falls to a Record Low After Exploit](https://coinpaprika.com/news/mantra-freezes-chain-falls-record-low-exploit/)
- [Cosmos Labs Urges Cosmos EVM Chains to Halt Validators, Three Now Offline](https://www.cryptotimes.io/2026/08/25/cosmos-labs-urges-evm-chains-to-halt-amid-security-incident/)
- [Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks](https://thedefiant.io/news/blockchains/cosmos-labs-urges-evm-chains-halt-shared-bug-drains-three-networks)
- [Cosmos EVM chains told to halt after security incident](https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-incident/)
- [Cosmos Releases Critical Security Patch Without Notification, Projects Lose Funds to Hackers](https://www.kucoin.com/news/flash/cosmos-publishes-critical-security-patch-without-notification-projects-lose-funds-to-hackers)
- [ASA-2026-002 (prior, related): ICS20 Precompile Nested-Execution Flaw - GHSA-54gx-3cgr-7mfm](https://github.com/cosmos/evm/security/advisories/GHSA-54gx-3cgr-7mfm)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2194
