Crypto insigtX

Cosmos Labs Admits Misjudging Vulnerability, Six Chains Hit by Attacks Losing $5.7 Million

Cosmos Labs released a technical report, admitting it had previously misjudged an integer underflow vulnerability in Cosmos EVM, which led to attacks on six blockchain networks between August…

Published
Market
Crypto
Source
insigtX

Cosmos Labs released a technical report, admitting it had previously misjudged an integer underflow vulnerability in Cosmos EVM, which led to attacks on six blockchain networks between August 20 and 25, with stolen tokens totaling approximately $5.7 million. Attackers exploited the vulnerability to underflow account balances to the maximum value of 2^256-1, then reversed the operation to transfer out the inflated balances, thereby stealing tokens from target accounts without minting new tokens in the process. The report shows that a researcher submitted the flaw via a bug bounty program on April 25, but testers could not reproduce it on existing Cosmos chain configurations, so Cosmos Labs fixed it with a silent patch in May. After an independent researcher confirmed in early August that the vulnerability affected all Cosmos EVM chains, Cosmos Labs released a patch on August 19, but the first attack occurred about 20 hours later. In terms of specific losses, MANTRA lost 720.9 million tokens (approximately $3.6 million), TAC lost nearly 3 billion TAC, and KiiChain lost approximately 148 million KII. Both MANTRA and KiiChain criticized Cosmos Labs for not notifying affected chains in advance and recommending downtime, with KiiChain stating that deploying the patch took days while downtime would have taken only minutes. Cosmos Labs said it has coordinated responses with 40 chains and assisted 13 chains in completing fixes or downtime before the attacks.

insigtX content is informational and educational, not investment advice.