Cosmos Labs Says It Wrongly Signed Off on Bug Later Used in $5.7M Six-Chain Exploit

AI Market Summary
Cosmos Labs' postmortem says it mistakenly cleared a Cosmos EVM integer-underflow bug later exploited to steal $5.7M across six chains, with significant losses at MANTRA, TAC, and KII. The incident highlights patch-disclosure and coordination failures, validator upgrade latency, and cross-venue laundering/freeze dynamics. Near-term, Cosmos EVM-linked tokens face elevated operational and reputational risk as chains reassess security processes and incident response.
Impact level
● High
Affected assets
MANTRA/USDT+1.28%
AI Insight · MANTRA/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Cosmos Labs said it mistakenly cleared a flaw in Cosmos EVM that was later exploited to steal about $5.7 million across six blockchain networks between Aug. 20 and Aug. 25. In a postmortem, the firm said attackers swapped the stolen tokens for roughly $2.87 million in other assets on decentralized exchanges and exchanged about $2.85 million on centralized venues. Cosmos Labs said related centralized exchange accounts have been frozen pending investigations by the relevant authorities. The vulnerability was reported through the Cosmos bug bounty program on April 25. Cosmos Labs said its testers were unable to reproduce the issue against the configuration used by live Cosmos chains and concluded the networks' funds were not at risk. Based on that assessment, the company handled remediation via its silent public patch process rather than its private patch distribution process. The bug involved an integer underflow that could make an attacker's wallet appear to hold effectively infinite tokens. The attacker could then move the inflated balance to a target account and leave the target with nothing. Cosmos Labs said no new tokens were minted and overall supply was effectively unchanged; MANTRA said the exploit shifted its supply by a single base unit. Cosmos Labs said the targets included arbitrary high-balance accounts such as burn addresses and multisignature wallets. The advisory applies to Cosmos EVM releases prior to v0.6.2 and v0.7.2. A fix was merged in May, when Cosmos Labs still believed live chains were unaffected. The firm said it has used the same silent public patch process to address 37 vulnerabilities over the past 13 months. According to the postmortem, independent researchers concluded in early August that the flaw affected all Cosmos EVM chains. Cosmos Labs pushed the patch at 7:01 p.m. ET on Aug. 19, with release notes describing the update only as "important security fixes." The first exploit began about 20 hours later. MANTRA said that window was insufficient to assess, test, and coordinate an upgrade across 38 independent validators. A Push Chain developer publicly detailed the vulnerability and an exploitation path at 3:16 a.m. ET on Aug. 20, crediting an audit by Hacken and listing affected versions. MANTRA said the security report was filed 11 hours and 45 minutes before the attacker's first probe. MANTRA said it lost 720.9 million MANTRA tokens, then valued at about $3.6 million, drained from a burn address and a dormant multisignature wallet. The project halted its chain at 7:13 p.m. ET on Aug. 20 and resumed more than 30 hours later on patched software without a rollback. TAC said it lost nearly 3 billion TAC from its staking pool on Aug. 22, with around 1.2 billion TAC sold on BNB Chain for roughly $950,000. KiiChain reported losing about 148 million KII that same evening; about 64.6 million KII were sold for approximately $1.6 million. Cosmos Labs said about 54% of the KII taken remains recoverable onchain if the network is restored. Cosmos Labs said three additional chains were hit using the same method but did not identify them. Bubblemaps said one may be Nesa, claiming an attacker moved $50 million of NES back to Ethereum after inflating a balance 200-fold, but extreme slippage limited profit to about $60,000. Bubblemaps added the Nesa incident may have involved a separate party. The other two chains have not been publicly identified. MANTRA said no tokens had been recovered as of Aug. 28. KiiChain said Cosmos Labs did not provide advance notice to affected chains or recommend halting until Aug. 22, after MANTRA, TAC, and KiiChain had already been attacked. KiiChain said the exploit required three upstream defects and that only the underflow issue had been publicly patched. MANTRA said the underflow fix closed the attack path. Cosmos Labs said it coordinated with 40 chains during the response, working with 13 additional chains to patch or halt operations before further attacks. The firm also said it identified 11 previously unregistered Cosmos EVM deployments during the incident response.