Cosmos Labs acknowledged Friday it wrongly cleared a critical vulnerability that attackers exploited to drain $5.7 million across six blockchain networks.
Cosmos Labs acknowledged Friday it wrongly cleared a critical vulnerability that attackers exploited to drain $5.7 million across six blockchain networks.

Cosmos Labs acknowledged Friday it wrongly cleared a critical vulnerability that attackers exploited to drain $5.7 million across six blockchain networks.
Cosmos Labs admitted it misjudged a critical Cosmos EVM vulnerability that enabled attackers to steal $5.7 million across six chains between Aug. 20 and Aug. 25, according to a technical post-mortem published Friday.
"Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds," the firm's report states.
The exploit used an integer underflow bug to inflate token balances to the maximum value of 2^256-1 base units, then reversed the arithmetic to drain target accounts. MANTRA lost 720.9 million tokens worth about $3.6 million from its burn address and a dormant multisig wallet. TAC lost nearly 3 billion TAC from its staking pool, and KiiChain lost about 148 million KII. Attackers converted roughly $2.87 million through decentralized exchanges and $2.85 million through centralized venues, with exchange accounts frozen pending investigation.
The incident has pushed Cosmos Labs to revise its vulnerability triage and disclosure procedures after a flaw initially judged unlikely to threaten production chains reached six networks and forced emergency action across dozens more.
A researcher first reported the flaw through Cosmos's bug bounty program on April 25. Cosmos Labs said its testers could not reproduce the attack against the configuration used by live Cosmos chains, including all known production Cosmos EVM networks, and concluded funds were not at risk. The firm merged a fix in May under its silent patch process, which ships bug fixes without telling chain operators what they address.
Independent researchers in early August established the bug affected all Cosmos EVM chains regardless of decimal configuration. Cosmos Labs released patched versions v0.6.2 and v0.7.2 at 7:01 p.m. ET on Aug. 19. The first attack began at 3:06 p.m. ET on Aug. 20 — about 20 hours later.
"Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory," MANTRA wrote in its own post-mortem. MANTRA said it has formally raised the delay with Cosmos maintainers and is seeking clearer disclosure practices.
A developer at Push Chain filed a public code change at 3:16 a.m. ET on Aug. 20 describing the vulnerability and its exploitation path, crediting the finding to an audit by security firm Hacken. Cosmos Labs called the public disclosure of an exact exploit path by a downstream developer "highly unusual."
KiiChain published its own technical post-mortem on Aug. 23, five days before Cosmos Labs released its report, complaining that Cosmos did not tell affected chains to halt.
"Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later," KiiChain's report states. Cosmos Labs only recommended halting on Aug. 22, after MANTRA, TAC and KiiChain had all been hit.
"A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes," KiiChain wrote. "The only measure that would have contained the risk immediately was a clear instruction to stop producing blocks, and that instruction came after the damage was done."
Cosmos Labs said it coordinated with 40 chains during the response and worked with 13 others to patch or halt before they were attacked. The firm said it does not hold a complete registry of the more than 115 public blockchains in the broader Cosmos ecosystem and discovered 11 previously unregistered Cosmos EVM deployments during the response.
MANTRA traded near $0.0043 on Saturday, down around 70% year-to-date, according to CoinGecko data. No tokens have been recovered as of Aug. 28, MANTRA said. The chain halted at 7:13 p.m. ET on Aug. 20 and resumed about 30 hours later on patched software without a rollback.
This article is for informational purposes only and does not constitute investment advice.