Crypto World
Ripple’s (XRP) Sharpe Ratio Just Did Something It Hasn’t Done In a Year
XRP has seen a notable improvement in its risk-adjusted returns. The Ripple token’s Sharpe Ratio on Binance has now reached its highest level since August 2025.
The indicator is currently stabilizing at around 0.207, according to CryptoQuant, while the price hovers close to $1.40.
Risk-Reward Profile
Over the past few months, XRP’s Sharpe Ratio stayed around negative or neutral levels and fell significantly during the crypto asset’s broader price decline. The recent increase suggests that returns have improved relative to the amount of volatility investors are facing.
The sharp rise in the Sharpe Ratio also occurred alongside the recovery in XRP’s price, which is up by almost 30% over the past month. This indicates that the recent move was accompanied by stronger risk-adjusted performance rather than being only an isolated price increase, CryptoQuant explained.
However, the indicator’s move to its highest level in a year does not confirm that XRP has entered a steady uptrend. The Sharpe Ratio could reverse quickly if market volatility rises or the token undergoes a significant correction.
Zooming out, institutional demand for XRP-linked investment products was also hard to miss. Last week, US-based spot ETFs pulled in $110.49 million in five days.
CryptoPotato reported that it was the first weekly inflow above $110 million since early December 2025. All five sessions ended in positive territory, and each attracted more than $10 million. Monday saw $13.82 million come in, followed by $23.87 million on Tuesday. Wednesday led the week with $28.14 million, the funds’ strongest single-day showing since January 5.
Another $18.47 million arrived on Thursday, while Friday brought $26.2 million. The latest figures pushed total net inflows across the five ETFs to a record $1.66 billion. Bitwise remains ahead of the other issuers; its ETF now holds slightly more than $600 million in cumulative inflows.
What’s Next?
Regardless of how promising XRP’s setup may appear, a move toward $1.80 or $2 could remain out of reach until the token reclaims $1.54, according to crypto analyst ChartNerd. That level represents both a six-month resistance wall and the weekly 50 EMA. He further explained,
“Just to be clear, and to reaffirm. I am not suggesting XRP can’t push up towards $1.80/$2. I am suggesting we are under resistance, and if we do get the follow through, it will likely open up an even deeper retrace than what we would witness rejecting the weekly 50 EMA at $1.54.”
The post Ripple’s (XRP) Sharpe Ratio Just Did Something It Hasn’t Done In a Year appeared first on CryptoPotato.
Crypto World
Live updates: Bitcoin holds $78,000 as yen breaks 160 and rate-hike bets lift the dollar

Bitcoin is holding just under $78,000 as August closes. The dollar strength that pushed the yen past its intervention line is the same force capping crypto.
Crypto World
More Markets Lending Reserve Drained for $9.3M: Blockaid
Decentralized finance (DeFi) vault infrastructure protocol More Markets had a lending reserve drained of about $9.3 million in digital assets on Flow EVM, according to Web3 security platform Blockaid.
The attacker drained about 15.5 million Wrapped Flow (WFLOW) tokens, valued by Blockaid at approximately $9.3 million, from the mFlowWFLOW lending reserve, according to blockchain data shared by Blockaid in a Monday X post.
Blockaid said the attacker used Ankr Staked FLOW (ankrFLOW), a liquid staking token, alongside E-mode to overborrow from the reserve.
E-mode, short for efficiency mode, is an Aave V3 feature that increases borrowing power for assets whose prices are expected to move together, such as a liquid staking token and its underlying asset.
The exploit pushed total losses from cryptocurrency hacks to $139.7 million for August, making it the third-largest month by value stolen so far in 2026. However, it marks a significant decrease from $254 million stolen during July, according to DefiLlama data.
On Sunday, Cronos halted its blockchain network after a reported $75 million exploit targeting DeFi lending protocol Tectonic.
More Markets had not publicly confirmed the incident or disclosed whether users suffered losses at the time of publication. Cointelegraph contacted Blockaid for more details but did not receive a response by publication and was unable to reach More Markets for comment.
Related: Humanity Protocol to prioritize operational security following $36M hack
Crypto World
U.S. jobs report, Russia’s digital ruble rollout: Crypto Week Ahead

Your look at what’s coming in the week starting Aug. 31.
Crypto World
Ripple mints 11M RLUSD as supply tops $2.3B
Ripple recorded another round of RLUSD treasury activity on Aug. 31, including an 11 million-token mint and a separate 11 million-token burn.
Summary
- 11 million RLUSD was minted and 11 million burned at treasury addresses on August 31.
- CoinGecko placed RLUSD’s circulating supply and market capitalization near $2.37 billion on August 31.
- Ripple reported $1.87 billion circulating against $1.98 billion in reserves as of August 20.
- Treasury mints create tokens but do not independently confirm circulation, customer demand or completed issuance.
- Ethereum and XRP Ledger remain RLUSD’s main networks, although Ripple supports several additional blockchain deployments.
The transactions were reported by the Ripple Stablecoin Tracker. They followed several large operations on the XRP Ledger and Ethereum during the final days of August.
CoinGecko placed RLUSD’s circulating supply and market capitalization at approximately $2.37 billion on Aug. 31. The stablecoin continued trading close to its intended $1 peg, meaning supply growth rather than price appreciation drove the higher valuation.
RLUSD minting does not necessarily show net demand
A stablecoin mint creates tokens at an issuer-controlled address. Those tokens may remain in treasury, move to an institutional customer or support transfers between networks.
A mint therefore does not prove that an equivalent amount entered public circulation. Likewise, a burn removes tokens from supply and can accompany customer redemptions, treasury management or network rebalancing.
The matching 11 million-token mint and burn on Aug. 31 illustrate that distinction. Viewed separately, the mint suggests expansion. Considered together, the two transactions produced no net increase from those specific operations.
Ripple did not identify the customer, purpose or economic relationship behind either transaction. The ledger records establish that the transactions occurred, but they do not establish new institutional demand.
As crypto.news previously reported, Ripple minted another 10 million RLUSD on XRPL on Aug. 17. Ripple also did not disclose the receiving customer or intended use of that issuance.
RLUSD supply moved above $2 billion in August
RLUSD crossed $2 billion in market capitalization during August, less than two years after its December 2024 launch. Ripple confirmed the milestone on Aug. 25 and said close to $1 billion had been issued on the XRP Ledger.
In related coverage, RLUSD approached an even split between XRPL and Ethereum when it crossed the threshold. Ethereum held a modestly larger amount at that time.
Available data now show continued supply expansion. CoinGecko reported approximately 2.37 billion circulating tokens on Aug. 31. XRP Ledger trackers placed the network’s portion above 1 billion tokens after several late-August mints.
Ethereum remains another major venue for RLUSD. Ripple has also extended the stablecoin to Base, Ink, Optimism, Unichain and the XRPL EVM sidechain. Public dashboards do not always provide synchronized supply totals for every network, which can produce differences between data providers.
Ripple’s reserve report trails the latest mints
Ripple’s transparency page reported $1.866 billion in circulating RLUSD and $1.981 billion in reserve funds as of Aug. 20. That official snapshot predates the latest issuance and the $2 billion milestone.
Standard Custody & Trust Company, a Ripple subsidiary supervised by the New York State Department of Financial Services, issues RLUSD. Ripple says reserves consist of cash and permitted cash equivalents held in segregated accounts.
Deloitte prepares monthly attestations covering the reported circulation and reserve balances. However, those reports are retrospective. They do not provide real-time confirmation of reserve changes after every mint or burn.
The next attestation should offer a clearer view of whether reserve assets increased alongside the late-August supply expansion.
What happens next for RLUSD
Further treasury transactions will show whether the latest mints move into circulation or are offset by additional burns. Transfers from treasury accounts to exchanges, custodians or institutional counterparties could provide more context, although wallet movements alone may not reveal their purpose.
The next reserve report will be the more important disclosure. It should show whether Ripple maintained reserve assets above circulating liabilities as RLUSD moved beyond $2 billion.
No verified XRP price movement could be directly attributed to the RLUSD transactions. RLUSD growth may add dollar liquidity to the XRP Ledger, but it does not automatically create equivalent demand for XRP.
Crypto World
Navigating the Noise: HTX Turns 13 with Resilience in Action
Amid recent discussions in the crypto space, HTX has drawn significant attention.
Like many other exchanges, regulatory scrutiny has become subjects of discussion on this exchange.
However, activity on the HTX platform presents a contrasting picture.
The HTX 13th Anniversary Carnival is now well into its second half, with more than 120,000 rewards already distributed.
Every day, users set their alarms for 13:13 (UTC+8) to make sure they don’t miss the anniversary red packets. Some are lighting up 9, 11, or 13 Future Gems to unlock rewards, while others have already received their $HTX rewards and shared their wins on social media.
The market has also begun to warm up. Amid price movements in major assets such as BTC, trading activity across both spot and futures markets on the platform has surged.
Furthermore, the 13th Anniversary celebration extends far beyond a single Carnival Month.
Futures traders can participate in the HTX Trading Championship, spot traders can join the Spot Trading Carnival, and users seeking yield opportunities can take part in the HTX Earn Bonanza. In addition, a series of campaigns focused on $HTX, referrals, P2P, and margin trading are being launched in rapid succession.
For users, one way to assess whether an anniversary event is truly engaging is to look beyond its headline prize pool.
Prize pool figures may attract attention, but actual reward distribution is a much more direct measure of the true user experience.
To date, more than 120,000 rewards have been distributed to users.
The anniversary celebration has only just passed its midpoint.
01 | How Are 120,000 Rewards Being Distributed?
For its 13th anniversary, HTX designed a distinctly crypto-native interactive framework.
Thirteen Future Gems correspond to 13 specific tasks.
Rather than forcing users to complete every challenge at once, they can progress step by step, starting with the simplest tasks.
Posting a 13th Anniversary wish, completing a Learn & Earn quiz, and purchasing 50 USDT worth of $HTX are among the early-stage milestones. As users progress, the tasks gradually extend into core areas such as spot and futures trading, Earn, fiat deposits, margin trading, and TradFi.
The second half of the progression introduces higher-tier incentives.
At 9 Gems, you can start drawing rewards and receive up to 130 USDT worth of $HTX. At 11 Gems, you can claim an anniversary red packet every day at 13:13 (UTC+8). Light up all 13 Gems for a chance to win up to 1,300 USDT worth of $HTX and unlock the grand prize.
02 | A Particular 13th Anniversary Period
HTX’s 13th anniversary coincides with a notable period of market and operational backdrop.
There’s a lot of noise in the industry.
Like many other exchanges, HTX is subject to public discussion and scrutiny regarding issues such as regulation and compliance. However, beyond social media commentary, underlying operational metrics provide a far clearer view of the platform’s performance.
According to recent operational statistics disclosed by HTX, the daily average number of deposit and withdrawal orders has remained at tens of thousands since August 23. HTX stated that core services, including spot, futures, deposits, and withdrawals, continue to operate normally.
In addressing market questions, HTX has maintained open communication regarding its operations and platform stability while encouraging continued public observation. Thus far, these external developments have not interrupted the platform’s operations. User trading activity, capital flows, and anniversary events have continued during this period. These operational indicators provide a more concrete basis for assessing the platform.
03|For an Exchange, Money Is More Honest Than a Tweet
A week ago, Justin Sun, Advisor to HTX, responded to external inquiries with a concise statement:
“Everything is fine.”
This is very much in line with his style of expression.
However, whether an exchange holding user assets is genuinely operating normally cannot be determined by a single tweet alone.
Money is more honest than a tweet. Operational data provides a more substantive basis for assessment than statements alone.
Key operational metrics provide a more substantive view: whether deposits and withdrawals proceed smoothly; whether trading activity and liquidity remain stable; and whether platform infrastructure can support increased trading volume when market opportunities emerge. These are the core indicators of an exchange’s operational resilience.
Against this backdrop, the theme of HTX’s 13th anniversary—”Resilience Reveals the Future”—takes on greater significance.
Without recent events, “resilience” might have been nothing more than an anniversary tagline.
Industry narratives frequently reference 13 years of experience, multiple bull and bear cycles, the ability to weather market cycles, and a long-term approach.
Yet operational resilience for an exchange relies on clear fundamentals.
Operational resilience means keeping systems stable during periods of high market volatility, maintaining seamless deposit and withdrawal processing amid external turbulence, addressing issues promptly as they arise, and maintaining system capacity as market volumes recover.
True resilience is not the absence of problems, but the ability to maintain momentum when problems arise.
Routine deposit and withdrawal processing, together with the distribution of 120,000 rewards, does not imply the absence of operational risk, nor does it replace long-term regulatory resolution.
HTX still needs to address the relevant issues and consistently provide verifiable data to users and market participants.
Resilience can help a company navigate periods of uncertainty, but it should not substitute for addressing underlying issues.
At least for now, these external developments have not interrupted the platform’s operations.
The post Navigating the Noise: HTX Turns 13 with Resilience in Action appeared first on BeInCrypto.
Crypto World
Alphabet: Five Months of Consolidation Reach Their Breaking Point
Alphabet just had a genuinely turbulent month, and the whiplash tells its own story. Despite beating earnings expectations with profits of $9.11 per share, roughly triple what analysts had forecast, the stock actually sold off in the days following the report, weighed down by mounting concerns over AI spending. That mood shifted decisively on Monday, when shares jumped over 5% after Morgan Stanley reassured investors, highlighting Alphabet’s still-robust $53.3 billion in free cash flow over the past twelve months, even as cloud capital expenditure could exceed $1.2 trillion in 2027.
The underlying business remains genuinely strong: Google Cloud revenue surged 82% year-over-year to $24.8 billion in Q2, and the company has been actively defending its position, launching more budget-friendly AI pricing to compete directly with rivals. That said, not everything has gone smoothly. Alphabet agreed to pay £260 million to settle a UK class-action lawsuit this week, and a leadership shakeup within its AI division, including the departure of key figures, has added a layer of organizational uncertainty investors are still digesting.
The result: a company delivering genuinely impressive growth, but one whose massive AI bet keeps testing investors’ patience with every headline.
Technical Analysis of Alphabet (GOOGL)

As the GOOGL chart shows, the stock has been compressing into a symmetrical triangle since April, with a descending trendline from the 400 highs converging with an ascending trendline off the 269 low, both meeting right at the current price near 340–346, exactly where the 0.5 Fibonacci retracement and the 200-period EMA also sit.
Bullish Scenario
Should buyers defend this trendline-EMA confluence and break decisively above the descending trendline, the path would open toward the 0.382 retracement near 356.79, with a stronger move potentially targeting the 0 level at 382.88, the origin of the entire pullback.
Bearish Scenario
Conversely, a break below the ascending trendline and the 0.618 retracement near 340.66 would expose the 0.786 level near 329.19, with a deeper slide risking a retest of the 314.57 low that anchored this five-month structure.
With price coiled right at the apex of this triangle, sitting exactly on the 200-period EMA, Alphabet’s next move looks set to be decisive. Will the AI spending story finally translate into a genuine breakout, or does the stock settle back into its earlier range?
Buy and sell stocks of the world’s biggest publicly-listed companies with CFDs on FXOpen’s trading platform. Open your FXOpen account now or learn more about trading share CFDs with FXOpen.
This article represents the opinion of the Companies operating under the FXOpen brand only. It is not to be construed as an offer, solicitation, or recommendation with respect to products and services provided by the Companies operating under the FXOpen brand, nor is it to be considered financial advice.
Crypto World
Elon Musk Warns AI Hacking Will Go Superhuman by End of 2027
Elon Musk expects artificial intelligence to beat humans at hacking by the end of 2027. He put AI hacking first among the digital tasks machines will dominate.
The forecast followed a fresh security scare. The software company JFrog disclosed a critical flaw in Artifactory, the package registry that many software teams use to store and distribute code.
The Flaw That Reopened the AI Hacking Debate
JFrog published CVE-2026-82329 on August 28. The vulnerability scores 9.8 out of 10 on the standard scale. The company has since shipped patched builds.
Attackers need no password and no user interaction. Default configurations sit exposed. Because Artifactory holds build files, a single break can poison everything downstream. Such supply chain attacks spread through trusted downloads rather than direct break-ins.
Vercel Chief Executive Guillermo Rauch speculated that autonomous agents found and exploited the bug. The public record says otherwise.
OpenAI models discovered nine Artifactory zero-days during a July evaluation. JFrog patched those in version 7.161.15. The new flaw still affects later builds, so the two sets look separate. The July episode joined other cases of AI models breaching systems.
Musk Puts a Deadline on Machine Superiority
Rauch argued that 2026 keeps erasing the things AI supposedly cannot do. Musk agreed and went further.
Musk also credited Google co-founder Larry Page, who warned him a decade ago that AI hacking would outclass human experts. Musk has sharpened his AI growth predictions repeatedly this year.
Vercel Chief Technology Officer Malte Ubl reported a similar result. An open-weight model he tested wrote its own fuzzer while probing the company’s sandbox. Fuzzers hunt software bugs by flooding a program with malformed input.
Rauch draws a blunt conclusion for customers.
Our guidance for this new world: assume everything hackable will get hacked. And it will get hacked autonomously. You must also defend yourself autonomously, because your surface of attack is likely bigger and your code more vulnerable than you expect.
Guillermo Rauch, X
Coinbase CEO Brian Armstrong expects a rogue AI event within two years. Separately, OpenAI already ships a cyber-focused defense model to approved defenders.
Liability still lags the technology, however, and accountability for AI agents remains unsettled. Musk’s deadline leaves security teams roughly 16 months. The harder question is whether defenses scale as fast as AI hacking.
The post Elon Musk Warns AI Hacking Will Go Superhuman by End of 2027 appeared first on BeInCrypto.
Crypto World
GCSA Agent Achieves 91.3% on CyberGym, Ranking Among the World’s Leading AI Cybersecurity Agents
GCSA Agent demonstrates autonomous vulnerability analysis and PoC generation capabilities on a highly challenging real-world vulnerability benchmark
The Global Cybersecurity Alliance (GCSA) today announced that GCSA Agent achieved a 91.3% success rate on the CyberGym benchmark, placing it within CyberGym’s “Leading Systems Above 90%” category.
CyberGym is a large-scale, real-world cybersecurity evaluation framework developed by a research team at the University of California, Berkeley. It contains 1,507 historical real-world vulnerability test cases across 188 major software projects and is designed to evaluate the practical capabilities of AI agents in real-world vulnerability analysis scenarios.
Unlike traditional AI benchmarks that primarily assess code understanding, knowledge-based question answering, or static analysis, CyberGym requires AI agents to work directly within real-world vulnerable code environments.
In its core Level 1 evaluation, an AI agent is provided only with a vulnerability description and an unpatched code repository. It must then autonomously perform code analysis, locate the vulnerability, reason about potential attack paths, construct a PoC, and execute it for validation. A task is considered successful only if the generated PoC successfully triggers the target vulnerability in the vulnerable version while failing to reproduce the issue in the patched version.
CyberGym therefore measures more than whether an AI system can simply “understand code.” It evaluates whether the AI can complete the full process from security analysis to vulnerability reproduction and validation.
From Large Language Models to Security Agents
In this CyberGym evaluation, GCSA Agent operated on Grok 4.5 and Grok 4.6 models and achieved a final success rate of 91.3%.
The result also reflects an important shift taking place in AI cybersecurity:
The underlying large language model alone no longer determines the system’s ultimate security capabilities.
Real-world vulnerability research typically requires a continuous sequence of tasks, including understanding vulnerability descriptions, searching large codebases, identifying attack surfaces, formulating vulnerability hypotheses, generating test inputs, executing programs, analyzing feedback, and repeatedly iterating on PoCs.
GCSA Agent is built around an agentic security workflow designed to support this end-to-end process.
Its objective is not simply to use a large language model for code analysis, but to enable AI to operate within real execution environments, autonomously formulate hypotheses around security issues, collect runtime evidence, execute tests, and ultimately validate security findings through reproducible results.
The CyberGym evaluation provides a quantitative external benchmark for these capabilities.
Vulnerability Research Capabilities for the Real World
A core value of CyberGym lies in narrowing the gap between traditional AI testing and real-world cybersecurity research.
Its evaluation environment restores software projects to their pre-patch vulnerable states. An AI agent may need to autonomously identify an issue within a large codebase containing thousands of files and millions of lines of code, and ultimately generate a PoC capable of actually triggering the vulnerability.
More importantly, further CyberGym research has shown that such agentic security capabilities are not limited to reproducing known vulnerabilities.
In open-ended vulnerability research experiments, AI agents have identified multiple previously unknown zero-day vulnerabilities as well as historical security patches that did not fully resolve the underlying vulnerabilities. These findings demonstrate the potential for autonomous vulnerability analysis technologies to evolve from reproducing known vulnerabilities toward discovering real-world security flaws.
For GCSA, this represents an even more important direction of development.
Benchmark performance is not the end goal.
GCSA aims to further develop AI Security Agents capable of operating in real-world cybersecurity environments and gradually participating across the full security lifecycle, from vulnerability discovery and analysis to validation and subsequent remediation.
Building AI-Native Cybersecurity Capabilities
As artificial intelligence accelerates software development, AI is also transforming the way vulnerabilities are researched and cyber threats are addressed.
As software systems continue to grow in scale and complexity, the next generation of cybersecurity will increasingly depend on collaboration between human security experts and autonomous AI agents.
AI Security Agents have the potential to help security teams:
- Identify software vulnerabilities with genuine exploitation potential at an earlier stage;
- Automatically analyse complex attack paths across large codebases;
- Automatically generate PoCs and perform execution-level vulnerability validation;
- Reduce false positives in traditional security detection through real execution results;
- Accelerate vulnerability assessment, validation, and remediation;
- Expand the scale of software and systems that specialised security teams are able to cover.
GCSA Agent’s 91.3% score on CyberGym represents an important milestone in GCSA’s development of AI-native cybersecurity capabilities.
Going forward, GCSA will continue advancing research into autonomous vulnerability analysis, AI Security Agents, and intelligent cybersecurity technologies, further translating frontier AI capabilities into real-world security capabilities and providing technical support for a safer, more trustworthy, and more resilient digital environment.
Source: GCSA Global Cybersecurity Alliance
Official Website: www.gcsa.org
The post GCSA Agent Achieves 91.3% on CyberGym, Ranking Among the World’s Leading AI Cybersecurity Agents appeared first on BeInCrypto.
Crypto World
Luke Dashjr exits mining pool Ocean after split over Bitcoin mining’s future

The split was mutual, with both parties citing differing views on the future of Bitcoin mining and recent protocol developments.
Crypto World
Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks
Cosmos Labs has disclosed that attackers exploited a critical Cosmos EVM vulnerability across six blockchain networks between Aug. 20 and Aug. 25, converting stolen tokens into about $5.72 million in assets through decentralized and centralized exchanges.
Summary
- Attackers exploited a critical Cosmos EVM flaw across six networks between Aug. 20 and Aug. 25, converting stolen tokens into about $5.72 million in other assets.
- Cosmos Labs first received the vulnerability report in April but initially concluded that production networks were not at risk and handled the fix through its silent patch process.
- MANTRA lost 720.9 million tokens worth about $3.6 million, while TAC and KiiChain later suffered separate attacks using the same method.
- The first attack began about 20 hours after patched Cosmos EVM versions were released without a vulnerability specific advisory to network operators.
- Cosmos Labs coordinated with 40 chains during the response and helped 13 networks patch or halt before they could be attacked.
Cosmos Labs said in a technical post-mortem published Friday that the flaw had first been reported through its bug bounty program on April 25, nearly four months before the attacks began. Its testers were unable to reproduce the exploit against configurations used by known production Cosmos EVM networks and concluded at the time that live user funds were not at risk.
Based on that assessment, developers handled the vulnerability through a silent public patch instead of privately distributing a security fix to affected chains. Cosmos Labs merged the fix in May without telling network operators which vulnerability it addressed.
The assessment later proved incorrect after independent researchers established in early August that the bug affected all Cosmos EVM chains. Cosmos Labs then obscured the fix to make reverse engineering more difficult and released patched versions at 7:01 p.m. ET on Aug. 19.
Release notes referred to “important” security fixes without describing the vulnerability. The first known attack began at 3:06 p.m. ET on Aug. 20, about 20 hours after the patched software became available.
Cosmos EVM flaw allowed attackers to drain large accounts
The vulnerability involved an integer underflow in Cosmos EVM, the ecosystem’s Ethereum-compatible framework built from the open-source Evmos codebase.
An attacker could first create an account containing locked tokens and delegate more tokens to a validator than the account was able to spend. Subtracting the delegated amount caused the balance to fall below zero, making the value wrap around to the maximum possible figure of 2^256-1 base units.
The attacker could then use the inflated balance against another account. Sending the amount to a target pushed its recorded balance past the same numerical ceiling, causing an overflow that wrapped the value back down and left the attacker holding the target’s tokens.
No additional tokens were created through the process, according to Cosmos Labs, and total token supply remained effectively unchanged. MANTRA said the exploit changed its supply by only one base unit, the smallest divisible denomination of the token.
Cosmos Labs said attackers targeted accounts holding large balances, including burn addresses and multisignature wallets created when networks launched. Its advisory classified the flaw as critical and identified Cosmos EVM releases before v0.6.2 and v0.7.2 as vulnerable.
The incident followed another security disclosure involving Cosmos software earlier this year. Crypto.news previously reported that a researcher had disclosed a CometBFT flaw in April that could cause nodes to stall during block synchronization. The CVSS 7.1 issue did not allow direct asset theft.
Networks had about 20 hours after the patch
Once independent researchers confirmed the Cosmos EVM flaw could affect production chains, Cosmos Labs prepared the security releases that went live on Aug. 19.
Network operators were not given a vulnerability-specific warning explaining what the upgrade fixed. MANTRA later said 20 hours was not enough to assess, build, test and coordinate a state-breaking upgrade across its 38 independent validators.
“Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory,” MANTRA wrote in its post-mortem.
Another disclosure occurred before the first theft. At 3:16 a.m. ET on Aug. 20, a Push Chain developer publicly submitted a code change describing the vulnerability and its exploitation path. The filing credited the finding to an audit by security firm Hacken and listed versions considered vulnerable.
The submission said no released version contained the fix, though its version table omitted v0.6.2 and v0.7.2, which Cosmos Labs had published roughly eight hours earlier.
Cosmos Labs described publication of an exact exploitation path by a downstream developer as “highly unusual” and said such disclosures can raise the risk that a vulnerability will be exploited.
MANTRA placed the public security finding 11 hours and 45 minutes before the attacker’s first probe. However, the attacker’s wallet had been funded almost four hours before the finding was filed.
“We state the timing as fact and draw no conclusion from it,” MANTRA said.
A withdrawal of 472.70 MANTRA from a customer account at a centralized exchange funded the gas fees used throughout the attack, according to the network.
MANTRA lost $3.6 million before halting its chain
MANTRA suffered the largest publicly disclosed loss from the attacks, with 720.9 million MANTRA tokens then valued at about $3.6 million taken from two addresses.
One was the network’s burn address. The second was a dormant multisignature wallet left from an earlier incentive campaign.
No automated warning was generated when tokens first moved from the burn address because MANTRA’s monitoring systems treated the address as immovable and did not watch it for outgoing transactions.
The attack remained undetected for almost four hours, giving the attacker time to drain the dormant multisig wallet.
MANTRA halted the network at 7:13 p.m. ET on Aug. 20. About 38 million stolen MANTRA remained frozen in the attacker’s wallet, but 94.7% of the stolen tokens had already been transferred to one centralized exchange deposit address through 15 transactions.
The chain remained unable to process transactions for roughly 30 hours. Crypto.news reported during the interruption that MANTRA halted transactions while engineering and security teams investigated the incident and exchanges suspended deposits and withdrawals.
Validators later deployed patched software and resumed block production without rolling back the chain or altering user balances. Version 8.4.0 included the Cosmos EVM security fix.
MANTRA had added native EVM support to its mainnet in September 2025 alongside CosmWasm compatibility, allowing Solidity applications and Cosmos-native smart contracts to operate on the network.
No stolen MANTRA tokens had been recovered as of Aug. 28, according to the project.
Its circulating supply increased by about 720.9 million tokens because assets held in accounts previously classified as unspendable, including the burn address, became tradable after being moved by the attacker.
TAC and KiiChain were hit after MANTRA
The same method was used against TAC on Aug. 22, according to Cosmos Labs. Nearly 3 billion TAC were taken from the network’s staking pool.
TAC is designed to bring decentralized finance applications to TON and Telegram users. Around 1.2 billion of the stolen tokens were sold on BNB Chain for roughly $950,000.
KiiChain was attacked that evening, losing approximately 148 million KII. About 64.6 million tokens were sold for roughly $1.6 million.
Cosmos Labs estimated that around 54% of the stolen KII remains recoverable onchain if the network is restored.
In its Aug. 23 technical post-mortem, KiiChain criticized how the vulnerability had been communicated to downstream networks. The project said Cosmos Labs did not provide advance notice, identify the release as security critical or initially tell affected chains to halt.
“A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes,” KiiChain wrote. “The only measure that would have contained the risk immediately was a clear instruction to stop producing blocks, and that instruction came after the damage was done.”
Cosmos Labs recommended that vulnerable networks halt on Aug. 22, after MANTRA, TAC and KiiChain had already been hit.
KiiChain disputed part of the technical assessment as well, saying three upstream defects were needed to carry out the exploit and that only the underflow had been publicly patched.
MANTRA reached a different conclusion after testing the fix against a working reproduction of the exploit. Its post-mortem described the underflow repair as “the control that closes this attack path.”
Cosmos Labs described two chained vulnerabilities but did not address KiiChain’s claim that another upstream defect remains unresolved.
Three other Cosmos EVM networks were attacked
Three further chains were exploited with the same method, though Cosmos Labs did not identify them in its report.
Nesa may have been one of the affected networks. Bitvavo suspended NES deposits and withdrawals on Aug. 24, citing a critical consensus vulnerability that had been exploited to make vulnerable nodes accept invalid blocks.
Blockchain analytics firm Bubblemaps identified Nesa as one of the affected chains in an Aug. 26 analysis. The firm said an attacker bought about $250,000 worth of NES, bridged it to Nesa, used the flaw to increase the balance about 200-fold and transferred roughly $50 million in NES back to Ethereum.
Most attempted swaps suffered extreme slippage as liquidity was removed from trading pools, leaving the attacker with about $60,000 in profit, according to Bubblemaps.
The wallet had originally been funded through Monero. Bubblemaps said differences in the funding method and the attacker’s behavior meant a separate party may have been responsible for the Nesa exploit.
The remaining two affected chains have not been publicly identified.
Cosmos Labs said it coordinated with 40 networks during its response and worked with 13 others to patch the vulnerability or halt before they were attacked.
The firm said it does not maintain a complete registry of the more than 115 public blockchains operating across the Cosmos ecosystem. Its response uncovered 11 Cosmos EVM deployments that had not previously been registered with the team.
MANTRA, meanwhile, is being acquired by existing backer Inveniam Capital Partners, which had made a $20 million strategic investment in the project in August 2025. The transaction is expected to close in the third quarter of 2026, with MANTRA Chain, its token and related infrastructure set to continue operating under Inveniam’s ownership.
-
Crypto World5 days agoSpaceX stock could rise 75% to $240, JPMorgan says
-
Fashion3 days agoWeekend Open Thread: Maeve – Corporette.com
-
Crypto World3 days agoBitcoin’s 22% rally now needs real demand to outlast Treasury liquidity boost
-
Crypto World5 days agoWarsh Jackson Hole keynote puts financial innovation first
-
Crypto World6 days agoA $30 Billion AI Fund Implodes, Now the SEC Is Investigating Wall Street’s Role
-
Business3 days agoSalesforce Stock Soars 19% as Blowout Earnings and Agentforce AI Growth Silence Software Skeptics
-
Crypto World5 days agoDid Trump Just Move SpaceX Stock With One Truth Social Post?
-
Crypto World4 days agoElon Musk Grok Bot Promise: We Will Make You Whole if AI Loses Your Money
-
Business3 days agoApple Confirms September 9 Keynote and Reveals Its Full Pre-Order Schedule
-
Business5 days agoWalmart takes aim at younger shoppers with new fashion brand
-
NewsBeat5 days agoLindsay Clancy jury braces for closing arguments as judge tells court: ‘You’ve heard all the evidence’ – Live updates
-
Crypto World2 days agoBitcoin price tests $82K resistance as Brandt stays long
-
Business5 days agoThailand’s Eastern Economic Corridor Capital City (EECiti): Key Developments and Investment Opportunities
-
Business2 days agoOnto Innovation Stock: AI’s Next Bottleneck Is Yield (NYSE:ONTO)
-
Crypto World4 days agoNVIDIA revenue hits $96.2B as AI demand doubles
-
Business7 days agoModerna CEO warns China is pouring state money into mRNA technology
-
Business6 days agoNVIDIA Stock Drops Nearly 2 Percent to $210 on Seventh Losing Day Ahead of Critical AI Earnings
-
Business3 days agoiPhone 18 Pro Pre-Orders Could Shift to Saturday as Apple Reportedly Avoids September 11 Anniversary
-
NewsBeat5 days agoTrump’s trade truce with China faces test with Iran effort
-
Crypto World5 days agoNvidia Q2 Earnings Reveal $96.2 Billion Beat, So Why Is NVDA Falling?

You must be logged in to post a comment Login