Cosmos Labs said in a technical report that it had previously misjudged an integer underflow vulnerability in Cosmos EVM, a flaw later exploited across six blockchain networks between Aug. 20 and Aug. 25. The attacks resulted in roughly $5.7 million in stolen tokens, according to the report.
The company said attackers used the bug to push an account balance down to the maximum value of 2^256-1 through underflow, then reversed the operation and transferred out the inflated balance. The report added that the exploit did not mint tokens out of thin air.
A researcher first submitted the flaw through a bug bounty program on April 25, but testers could not reproduce it under the existing Cosmos chain configuration. Cosmos Labs said it issued a silent patch in May. After an independent researcher confirmed in early August that the issue affected all Cosmos EVM chains, Cosmos Labs released a patch on Aug. 19. The first attack followed about 20 hours later.
Among the disclosed losses, MANTRA lost 720.9 million tokens, worth about $3.6 million. TAC lost nearly 3 billion TAC, while KiiChain lost about 148 million KII. MANTRA and KiiChain criticized Cosmos Labs for not notifying affected chains in advance and not recommending a shutdown.
Cosmos Labs has acknowledged in a technical report that it previously misjudged an integer underflow vulnerability in Cosmos EVM, a mistake that led to attacks on six blockchain networks between Aug. 20 and Aug. 25 and about $5.7 million in stolen tokens.
The report said attackers exploited the flaw by forcing an account balance to underflow to the maximum value of 2^256-1, then reversing the operation and transferring out the inflated balance to steal tokens from target accounts. It said the process did not involve minting tokens out of thin air.
Bug report and patch timeline
According to the report, a researcher submitted the flaw through a bug bounty program on April 25, but testers were unable to reproduce it under the existing Cosmos chain configuration. Cosmos Labs then fixed the issue in May through a silent patch.
In early August, an independent researcher confirmed that the vulnerability affected all Cosmos EVM chains. Cosmos Labs released a patch on Aug. 19, but the first attack took place about 20 hours later.
Losses disclosed by affected chains
MANTRA lost 720.9 million tokens, worth about $3.6 million. TAC lost nearly 3 billion TAC. KiiChain lost about 148 million KII.
Criticism from projects and response from Cosmos Labs
MANTRA and KiiChain both criticized Cosmos Labs for failing to notify affected chains in advance and for not recommending a shutdown. KiiChain said the patch required several days to deploy, while a shutdown would have taken only minutes.
Cosmos Labs said it coordinated the response with 40 chains and helped 13 of them complete fixes or shut down before they were attacked.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.