Incident case file
Sign in to watchTAC Cosmos EVM Balance-Handling Underflow Exploit — $7.5M Nominal / ~$1M Realized
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn August 22, 2026 at approximately 19:46 UTC, an attacker exploited a shared vulnerability in the Cosmos EVM module (tracked as GHSA-7g4w-cg88-2cq2) against TAC, a Cosmos EVM-based chain. The bug allowed an attacker to precompute a deployment address, convert it into a vesting account, deploy a contract inheriting vesting status, then delegate 1 wei more than the available balance — triggering an integer underflow that wrapped the mirrored EVM balance toward the maximum representable value, which could then be transferred out as if it were a legitimate balance. The nominal/notional exposure reported was approximately $7.5M, though realized value converted to spendable assets was roughly $1,005,774 (reported by Cosmos Labs' official post-mortem, which does not break out a separate confirmed figure per chain beyond the $5.72M total across the combined cluster). Stolen TAC tokens were bridged out to BNB Chain and TON. The chain was halted at block 24,671,475; no rollback was performed (a state edit was used instead). This is the same vulnerability class that had first been reported via HackerOne bug bounty in April 2026 and misjudged as not causing fund loss on production configurations, and the same class that first hit MANTRA on August 20 (one day before this window opens) before spreading to TAC, KiiChain and Nesa within the window.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)