Morning Edition · Friday, September 11, 2026Published at 1:49 AM EDT · New York
Attackers hit MANTRA, TAC, KiiChain and Nesa between 20 and 25 August using the same module defect that Cosmos Labs had received in April and fixed quietly.

A single defect in the shared Cosmos EVM (Ethereum Virtual Machine) module, reported to sit in the token-transfer precompile (a built-in shortcut function coded directly into the blockchain software) and in how the module handles vesting accounts, staking operations and balances, produced four separate chain drains in six days. Rekt News has now documented the cluster: MANTRA lost 720.9 million tokens worth roughly $3.6 million, KiiChain saw 148.3 million KII bridged out through Hyperlane to BNB Smart Chain across 18 transactions, TAC froze its chain, and on 24 August an attacker moved 257,703,733 NES, about a quarter of Nesa's stated supply, across Hyperlane to Ethereum.
The disclosure sequence is the contested part. Cosmos Labs received the vulnerability report in April, concluded that production networks were not at risk, and handled the fix through a silent patch. The first attack began roughly 20 hours after the patched versions shipped without a vulnerability-specific advisory to network operators. Silent patching protects unupgraded chains from opportunistic attackers reading the commit log. It also leaves operators unaware that upgrading is urgent.
Smaller incidents this week landed in the DeFiHackLabs reproduction repository. Contributors published proofs of concept for Ajna Finance's liquidation accounting manipulation, which drained about $775,000 from seven Ethereum pools in an immutable protocol with no treasury to reimburse anyone, for an Enso Finance vault that priced a deposit off a mis-set Uniswap V3 observation window close to spot, and for arbitrary call injection through an unverified call in the Unistreet launchpad.
The affected chains, for whom a maintainer-disclosure failure explains losses better than their own upgrade practices, and security researchers arguing for mandatory severity advisories.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
Independent reporting counts six chains and roughly $5.7 million converted, not four, MANTRA's 720.9 million tokens came from a burn address and a dormant multisig rather than user wallets, and Cosmos Labs says it secured or halted 13 further chains before any attack reached them.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Shared middleware turns one bug into a multi-chain incident, and the appchain model concentrates that risk rather than spreading it. Holders of tokens on small Cosmos EVM networks are exposed through bridge routes, because attackers convert stolen supply into liquid assets on Ethereum and BNB Smart Chain before the source chain can halt. The disclosure question now facing framework maintainers is whether a silent patch without an operator advisory is defensible when downstream teams cannot tell an urgent release from a routine one. Ajna is the cleaner lesson for depositors: immutability removes governance risk and also removes any mechanism to make users whole.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Rekt News (Nesan) · Rekt News (Mantra) · Rekt News (Total Exposure) · DeFiHackLabs (Ajna) · DeFiHackLabs (Enso) · DeFiHackLabs (Unistreet)
Comments
0No comments yet.