Morning Edition · Saturday, August 29, 2026Published at 1:48 AM EDT · New York
The bug let a token transfer execute while the ledger recorded no movement, allowing the same balance to be spent more than once, and MANTRA says none of the stolen tokens have been recovered.

Cosmos Labs has acknowledged that a defect its engineers triaged as low severity in March was later used to drain funds from six networks that share the same Cosmos EVM module. The total taken is just under $6 million, spread across chains including MANTRA, TAC and KiiChain.
The root cause was an accounting mismatch in the ICS20 precompile, the component that handles token transfers under the Inter-Blockchain Communication (IBC) framework. Under certain nested calls, the transfer executed while the state record showed that no tokens had moved. That gap let an attacker spend the same balance repeatedly. The vector was neither an oracle manipulation nor a stolen key. It was a state-accounting bug in shared infrastructure that many independent chains inherit without auditing it themselves.
The timing is the part the ecosystem is arguing about. An upstream fix reached release branches only hours before the incidents began, and MANTRA halted its chain for roughly 30 hours between August 20 and 22 while emergency patches were applied. MANTRA has valued the tokens taken from it at about $3.6 million using the pre-incident price and says none have been recovered. Analysts tracking the stolen funds estimate roughly $2.87 million was converted through decentralized exchanges and about $2.85 million through centralized venues, which means part of the proceeds passed through platforms that can freeze balances if they choose to act.
Cosmos Labs says it is revising its security triage and disclosure process after learning the true blast radius of the flaw shortly before the attacks. The wider point is structural. A single module maintained by one team sits under many sovereign chains, and the severity rating assigned by that team effectively sets the patch urgency for all of them. The public incident library maintained by DeFiHackLabs, which reconciled its running count past 862 logged incidents this week, continues to fill with cases of this shape.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
Competing layer-1 ecosystems and standalone-chain vendors gain from the framing that shared modular infrastructure carries correlated failure, while Cosmos Labs benefits from locating the fault in a triage process it can now revise rather than in the module's design.
The bug and the patch are documented in Cosmos Labs' own advisory ASA-2026-002, and multiple outlets confirm the roughly $6 million total, but MANTRA has publicly said no user funds were affected even as its own treasury addresses were drained, Cosmos Labs counts one chain as exploited among the 15 it identified rather than six, and the same precompile reportedly cost Saga about $7 million in January, which means the March triage decision was made with a prior incident already on the record.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Application-specific chains sold sovereignty, but they buy their transfer logic from a common upstream repository, so one team's severity rating decides how fast dozens of validator sets patch. The exposed parties are holders of tokens on small Cosmos EVM chains, whose losses are concentrated and unlikely to be reimbursed, and the validators who must halt production to apply fixes. For the modular-chain thesis, the cost is credibility: shared code means correlated failure, and the market prices correlated failure into the tokens of every chain in the family, not just the ones drained.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · DeFiHackLabs
Comments
0No comments yet.