Cosmos Labs Postmortem on EVM Flaw Exploited Across Six Networks
Named facts from the Cosmos Labs postmortem: April report, May patch, August releases, MANTRA incident details, and network response counts.

Cosmos Labs issued a postmortem on an EVM accounting flaw that allowed unauthorized transfers across six networks. The vulnerability was first reported on April 25 and initially judged non-critical because testing assumed six-decimal token configurations.
A silent public patch was merged on May 15. Backporting to older branches was delayed because the change was state-breaking. Reassessment in early August showed the flaw affected 18-decimal chains regardless of the earlier assumption. Releases v0.6.2 and v0.7.2 were published on the evening of August 19.
Scope and response
MANTRA was the first network exploited on August 20. An unprivileged wallet moved roughly 720.9 million tokens, valued at about $3.6 million using the pre-incident price, from a burn address and a legacy genesis-era address. No validator, administrator, governance, or multisig keys were compromised.
Across the six affected networks, attackers converted approximately $2.87 million through decentralized exchanges and $2.85 million through centralized venues. Some centralized-exchange accounts connected to the activity have been frozen. Cosmos Labs contacted 40 networks after the incidents; 13 additional chains applied mitigations before exploitation, and 11 previously unknown deployments were identified.
Remaining unknowns
Exact loss figures per chain beyond MANTRA remain incomplete. Recovery status of tokens beyond the 38 million still immobilized is unknown. The full scope of exposure across the broader Cosmos ecosystem valued above $7 billion has not been quantified.