Loading prices…
🩸BEARISH

Cosmos Labs Sat on EVM Bug 4 Months Before $5.7M Drain

Four-month triage miss is the bigger story. Cosmos Labs assumed 18-decimal chains were safe, six networks got drained, and disclosure norms for the $7B Cosmos stack just got rewritten.

Cosmos Labs sat on a critical EVM vulnerability for four months after initially judging it could not threaten production chains. The flaw was reported on April 25, deemed to affect only six-decimal networks, and merged as a silent public patch on May 15. By late August, attackers had exploited it across six networks and moved roughly $5.7 million through a combination of decentralized and centralized exchanges.

Why it matters

The misjudgment sits at the heart of the story. Cosmos Labs' original assessment held that because production Cosmos EVM chains used 18-decimal token configurations rather than six-decimal ones, they were outside the vulnerability's reach. The firm therefore handled the fix through its silent public patch process rather than the private patch distribution reserved for flaws believed to threaten live user funds. By early August, further research showed the decimal distinction did not protect deployments, forcing patched v0.6.2 and v0.7.2 releases on Aug. 19. A public pull request in another project's fork described the exploitation path the next morning, and MANTRA recorded its first unauthorized transaction less than 12 hours later.

Market impact

MANTRA took the largest disclosed hit, with roughly 720.9 million tokens (600 million from a burn address and 120.9 million from a legacy genesis-era multisig) moved by an unprivileged wallet that never compromised validator or governance keys. The project valued the movement at about $3.6 million at the pre-incident price, and MANTRA fell to an all-time low before rebounding roughly 14% to about $0.004744 after the postmortem. Cosmos Labs contacted 40 networks in total, with 13 applying patches or halts before they were exploited, and the response also surfaced 11 Cosmos EVM deployments the security team had not previously tracked. Accounts tied to the centralized-exchange side of the laundering route have been frozen, and Cosmos Labs has committed to revising its triage and disclosure procedures.

Related tokens
$MANTRA

Frequently asked questions

  1. How did attackers exploit the Cosmos EVM bug?

    They triggered an unsigned-integer underflow to create an abnormally large balance, then used that state to overflow another account and extract its legitimate balance without increasing total token supply.

  2. Why did Cosmos Labs initially believe production chains were safe?

    The firm judged the flaw affected only six-decimal networks, while production Cosmos EVM chains used 18 decimals, so they handled the fix as a silent public patch instead of an emergency security release.

  3. How were the stolen funds laundered across the affected chains?

    Attackers moved roughly $2.87 million through DEXs and an estimated $2.85 million through centralized exchanges; accounts tied to the CEX side have since been frozen, with MANTRA taking the largest disclosed hit at about $3.6 million.

  4. What was MANTRA's monitoring failure during the attack?

    MANTRA's monitoring treated the burn address as incapable of moving funds, so the first unauthorized transaction was not flagged for almost four hours, and the chain halted 14 minutes after a second debit.

  5. How is Cosmos Labs changing its vulnerability response after the incident?

    The firm has committed to revising its triage and disclosure procedures after a flaw initially judged unlikely to threaten production chains ultimately reached six networks and forced emergency coordination across roughly 40 networks.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →