XIYU.NEWS ENTITIES

Cosmos

CryptoBlockchain ecosystemFirst tracked 2026-08-22Last seen 2026-09-24

Entity background

Cosmos is an ecosystem of independent blockchains built with components including Cosmos SDK, consensus software, and the IBC interoperability protocol. Networks operate autonomously but exchange data and assets through IBC, so shared components can make upgrades or vulnerabilities relevant across multiple chains.

Current focus

xiyu.news has tracked 5 related reports since 2026-08-22. The latest focus is “Cosmos Hub Restarts; 1.23 Million ATOM Moved From Neutron Attacker Wallet”. 2 continuing event timelines connect the coverage over time.

Recent developments

5 entries
  1. #01
    CryptoThe Defiant
    8.5

    Cosmos Hub Restarts; 1.23 Million ATOM Moved From Neutron Attacker Wallet

    Cosmos Hub resumed producing blocks after a 24-hour-48-minute halt in block production. Separately, 1.23 million ATOM moved from a Neutron attacker wallet that had purchased voting power for 20,199 USDC and staked it 12 minutes before an expedited Neutron proposal closed. The incident combines a prolonged halt of a major network's block production with a governance attack in which voting power was acquired and staked minutes before an expedited proposal closed, exposing the last-minute mechanics of fast-tracked governance. The Hub produced no blocks for 24 hours and 48 minutes. The attacker spent 20,199 USDC to buy voting power and staked it 12 minutes before the expedited Neutron proposal closed, and 1.23 million ATOM has since moved from that wallet.

    1 SourceOpen event timeline →

  2. #02
    CryptoCryptoTicker
    8.0

    Vulnerability Reported in Six Cosmos EVM Chains

    CryptoTicker has reported a security vulnerability affecting six Cosmos EVM chains. The report highlights a protocol-wide security risk for these EVM-compatible Cosmos networks. This matters because EVM-compatible chains in the Cosmos ecosystem host significant DeFi activity, and a shared vulnerability could expose multiple networks simultaneously. It underscores the systemic risk that arises when multiple chains rely on common infrastructure such as the Cosmos EVM module. The vulnerability affects chains that use the Cosmos EVM module for Ethereum compatibility, meaning the attack surface is shared across those networks. No exploit has been publicly reported so far.

    1 SourceOpen event timeline →

  3. #03
    CryptoThe Block
    7.5

    Cosmos Labs admits fault in clearing bug behind $5.7M six-chain hack

    Cosmos Labs has admitted it mistakenly cleared the critical vulnerability that enabled a $5.7 million exploit across six blockchains, with MANTRA Chain suffering $3.6 million in losses. The admission comes after MANTRA Chain claimed the patch was released only 20 hours before the attack began. This incident exposes a significant flaw in vulnerability review within the Cosmos ecosystem, potentially undermining trust in the security of cross-chain infrastructure. Since the exploit affected user funds across multiple chains, it raises concerns about the safety of IBC-based interoperability and the accountability of core developers. The exploit affected six chains, including an estimated $3.6 million loss for MANTRA Chain. MANTRA Chain said the patch did not identify the flaw it was meant to fix, and was released only 20 hours before the attack began.

    1 SourceOpen event timeline →

  4. #04
    CryptoCryptoSlate
    8.0

    Cosmos misjudged critical EVM bug for 4 months before $6M cross-chain exploit

    On August 28, Cosmos Labs disclosed that a misjudged EVM vulnerability was exploited across six networks, including MANTRA, TAC, and KiiChain, causing nearly $6 million in losses. The flaw was first reported on April 25 but was deemed low-risk due to decimal assumptions; a silent patch was merged on May 15, and the real exploit began on August 20 after the assessment was revised. This incident exposes a months-long triage failure in a shared software layer — Cosmos EVM — that provides Ethereum compatibility to Cosmos SDK chains. With roughly 40 networks potentially affected and 11 previously unknown deployments discovered, it raises urgent questions about security disclosure and patch distribution across the broader Cosmos ecosystem. The exploit combined two accounting failures: an unsigned-integer underflow created an abnormally large balance, which was then used to overflow another account and extract its legitimate balance without increasing total token supply. Cosmos Labs contacted 40 networks, with 13 potentially exposed chains patching, halting, or applying mitigations; MANTRA suffered the largest disclosed hit, with about 720.9 million tokens moved from two unauthorized addresses.

    1 SourceOpen event timeline →

  5. #05
    CryptoThe Block
    8.5

    MANTRA halts network over Cosmos EVM module incident

    On August 21, 2026, MANTRA Chain halted all transactions, transfers, and staking after an attacker exploited a vulnerability in an upstream dependency linked to its Cosmos EVM module. The patched release v8.4.0 is being tested on the DuKong testnet before a coordinated mainnet restart can occur. This is a high-impact security event for MANTRA users and the broader Cosmos ecosystem, as the network-wide freeze silences all onchain activity and raises questions about the security of third-party dependencies. The incident could affect trust in Cosmos-based EVM chains and in the safety of upstream open-source components. The MANTRA team says the halt itself did not affect user funds, but the full asset impact of the attacker's activity remains unconfirmed and fund movements are being traced. Validators are instructed to keep mainnet nodes offline until a coordinated restart is announced, with DuKong testnet testing serving as the gate for the patched release.

    5 SourceOpen event timeline →

All entities · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.