A critical Cosmos EVM balance-reconciliation flaw, tracked as GHSA-7g4w-cg88-2cq2, was exploited to drain assets from six Cosmos-based chains. The bug allows an unchecked underflow in a vesting account’s delegated balance to wrap to roughly 2^256, corrupting reconciliation between EVM state and the Cosmos SDK x/bank module and enabling unauthorized minting or burning. Attackers reportedly sold about $5.72 million in affected assets through decentralized and centralized exchanges; KiiChain alone reported the theft of 148 million KII, valued at about $9.7 million at the cited price, while an attacker moved 2.99 billion TAC from a TAC account.
Cosmos Labs released fixes in Cosmos EVM v0.6.2 and v0.7.2 and urged operators of affected public chains to coordinate upgrades or halt block production, as no configuration-only mitigation exists. MANTRA resumed operations using a patched v8.4.0 binary, while TAC and KiiChain remained halted; KiiChain alleged that public availability of the state-breaking patch before private operator notification created an exploitable window and said two of three upstream defects were still unpatched. Blocking permissionless creation of vesting accounts removes the exploit precondition, but operators still need to deploy the patched releases.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
Warden Protocol blocked vesting-account creation because vesting accounts were its only source of locked balances, removing a prerequisite for the exploit.
TAC halted at block 24,671,475 at 23:58 UTC after an attacker exploited a Cosmos EVM precompile-layer vulnerability and moved 2,985,651,403 TAC between accounts. TAC said the amount represented about 62% of circulating supply, while total supply was unchanged.
An attacker used the vesting-account technique against 18 KiiChain targets, draining 148 million KII, valued by KiiChain at about $9.7 million. KiiChain halted at block 9,355,723 at 22:50:58 UTC; it said 67.6 million KII was bridged to BNB Smart Chain and 64.6 million was sold for about 1.61 million BUSD.
MANTRA resumed block production around 05:30 UTC using a patched v8.4.0 binary. It said it had no indication that user, exchange, or partner funds were affected.
KiiChain alleged that Cosmos Labs did not notify affected chains of the public fix until this date, after the patched releases were already available.
The first reported exploitation of GHSA-7g4w-cg88-2cq2 targeted MANTRA at 19:06 UTC. MANTRA halted block production late that day after two MANTRA-managed wallets were affected.
A public pull request in Push Chain's Cosmos EVM fork described the vulnerability and exploitation path at 07:16 UTC, roughly eight hours after the patched releases were issued.
Cosmos Labs released Cosmos EVM v0.6.2 and v0.7.2, containing state-breaking security fixes for the critical balance-reconciliation flaw. KiiChain later alleged that the public release occurred without advance notification or a security advisory to downstream chains.
Cosmos Labs confirmed that the vulnerability affected Cosmos EVM chains regardless of decimal configuration, reversing its earlier assessment that live-network funds were not at risk on 18-decimal networks. The underflow-guard fix was also backported on this date.
The critical Cosmos EVM flaw was exploited against six blockchains over the period from August 20 through August 25. Cosmos Labs estimated attackers sold approximately $2.87 million in affected assets on decentralized exchanges and $2.85 million on centralized exchanges.
Cosmos Labs merged pull request #1176, adding a SubBalance underflow guard intended to prevent the vulnerable balance subtraction.
The vesting-account balance-reconciliation vulnerability later tracked as GHSA-7g4w-cg88-2cq2 was reported to Cosmos Labs through its bug bounty program.
An attacker stole roughly $7 million from Saga's EVM network through the ICS20 precompile. Cosmos Labs' ASA-2026-002 later attributed the issue to recursive-call state updates not being reflected in the outer execution context, enabling repeated spending in one transaction.
Cosmos Labs acknowledged an ongoing incident affecting Cosmos EVM-module users and advised chains to have validators halt if they could not immediately perform the required coordinated, state-breaking upgrade. It identified versions before 0.6.2 and versions 0.7.0 through before 0.7.2 as affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcethehackernews.com
Open sourcethedefiant.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.