Loading prices…
🩸BEARISH

Cosmos Labs Admits Botched Review Enabled $5.7M Hack

A researcher flagged the integer-underflow flaw on April 25 under Cosmos Labs' bounty program, but testers ruled live chains safe, a patch shipped silent, and within 20 hours of a public code change…

Cosmos Labs disclosed on Friday that a flaw in Cosmos EVM, the shared stack that lets Cosmos chains run Ethereum-style applications, let attackers drain roughly $5.7 million from six blockchain networks between Aug. 20 and Aug. 25. The firm acknowledged that a researcher had filed the bug through its bug bounty program on April 25, but that Cosmos Labs testers could not reproduce the attack against live-mainnet configurations and concluded user funds were not at risk, shipping the fix through its silent patch process rather than a private security distribution.

Why it matters

The exploit hinges on an integer-underflow bug. By delegating more tokens than an account held and then flipping the arithmetic, the attacker wrapped a balance past zero to 2^256-1, a 78-digit figure, inflated a target account in reverse and walked away with its tokens, all while total supply stayed unchanged. Cosmos Labs' advisory, rated critical, covers Cosmos EVM releases before v0.6.2 and v0.7.2 and affects every Cosmos EVM deployment that had not yet moved to the patched versions when the public code change dropped.

The chain of disclosure failures is unusually detailed. A patch merged in May under the silent process, then at 7:01 p.m. ET on Aug. 19 Cosmos Labs released v0.6.2 and v0.7.2, with release notes referencing "important" security fixes. About 20 hours later the first attack landed. MANTRA's post-mortem puts the window bluntly: "Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators." About 12 hours before the first theft, a developer at Push Chain publicly filed a code change describing the exploit path, a disclosure Cosmos Labs called "highly unusual."

Market impact

MANTRA lost 720.9 million MANTRA tokens, then worth about $3.6 million, drained from its burn address and a dormant multisig wallet, and its supply reporting rose by the same amount because those balances had been excluded as unspendable. The chain halted about four hours after the first theft and resumed roughly 30 hours later on the patched software, without a rollback, freezing about 38 million MANTRA still in the attacker's wallet. MANTRA traded near $0.0043 over the weekend, down roughly 70% year-to-date, and had been undergoing a restructuring cut short by an acquisition deal with backer Inveniam.

TAC lost nearly 3 billion tokens on Aug. 22, of which roughly 1.2 billion were swapped on BNB Chain for about $950,000.

Related tokens
$MANTRA $TAC $KII $NES

Frequently asked questions

  1. What bug let the attacker drain funds across six Cosmos EVM chains?

    An integer-underflow flaw in Cosmos EVM. Delegating more tokens than an account held, then running the arithmetic in reverse, wrapped a balance past zero to 2^256-1 and let the attacker walk away with a target account's tokens while total supply was unchanged.

  2. How much was stolen and which chains were hit?

    Cosmos Labs puts total losses at about $5.7 million across six networks. Named victims include MANTRA (~$3.6M), TAC (~$950K liquidated plus more unsold), and KiiChain (~$1.6M liquidated). One additional chain is likely Nesa; the other two remain unnamed.

  3. Why did Cosmos Labs' bug bounty process fail to prevent the exploit?

    A researcher filed the flaw through the Cosmos bug bounty program on Apr. 25. Cosmos Labs testers said they could not reproduce it against live-mainnet configurations and concluded user funds were not at risk, so the fix went out through its silent, public patch process rather than a private security distribution.

  4. What triggered the attacks after the patch shipped?

    Cosmos Labs released v0.6.2 and v0.7.2 at 7:01 p.m. ET on Aug. 19 with generic release notes. About 12 hours later a Push Chain developer publicly filed a code change describing the exploit path, and about 20 hours after the patch the first attack began.

  5. What is the broader fallout for the Cosmos ecosystem?

    MANTRA is trading near $0.0043, down roughly 70% year-to-date, and is still working through a staff restructuring and an acquisition by backer Inveniam. Cosmos Labs conceded it does not hold a full registry of the 115+ public Cosmos blockchains and discovered 11 unregistered Cosmos EVM deployments only during incident…

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 1h ago
Open original →