Cosmos EVM Flaw Exploited Across Six Chains in $5.7 Million…

How Did The Cosmos EVM Exploit Work? Attackers exploited a critical flaw in shared Cosmos software across six blockchains between Aug. 20 and Aug. 25, converting stolen tokens into about $5.7 million of other assets and exposing weaknesses in how security fixes were communicated to networks using Cosmos EVM. Cosmos Labs said approximately $2.87 million of the proceeds were exchanged through decentralized exchanges and another $2.85 million through centralized exchanges. Accounts linked to the attackers at centralized exchanges have since been frozen pending investigations by authorities. The vulnerability was an integer underflow in Cosmos EVM, the framework that allows Cosmos-based blockchains to run Ethereum-compatible applications. It affected Cosmos EVM versions before v0.6.2 and v0.7.2. The exploit involved creating an account with locked tokens and delegating more tokens than the account could actually spend. Instead of rejecting the transaction, the software allowed the balance calculation to fall below zero and wrap around to approximately 2^256-1 base units, effectively producing an enormous balance inside the accounting system. The attacker could then use the inflated balance to manipulate another account and extract its tokens. No new tokens were actually minted, meaning the attack exploited accounting logic rather than directly increasing the underlying token supply. Why Was The Vulnerability Not Fixed Earlier? The most important issue may be the disclosure timeline. A researcher originally reported the vulnerability through the Cosmos bug bounty program on April 25. Cosmos Labs attempted to reproduce the attack against configurations used by production networks but concluded that live chains were not vulnerable. A fix was merged into the main Cosmos EVM codebase in May through what Cosmos Labs calls its silent public patch process. The change was not immediately added to production release branches because it required a state-breaking upgrade that chain operators would need to coordinate with validators. Independent researchers provided additional information in early August that allowed Cosmos Labs to determine that all Cosmos EVM chains were vulnerable. The fix was then backported and released in versions v0.6.2 and v0.7.2 at 11:01 p.m. UTC on Aug. 19. The first known attack against MANTRA began approximately 20 hours later. “Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory,” MANTRA said in its post-mortem. Investor Takeaway The financial loss is relatively contained compared with major crypto exploits, but the incident exposes a larger infrastructure risk: dozens of independent blockchains can inherit the same vulnerability from shared software while relying on separate validator groups to deploy emergency upgrades. Which Cosmos Chains Were Hit? MANTRA suffered the largest publicly disclosed loss.
عنوان اصلی (انگلیسی): Cosmos EVM Flaw Exploited Across Six Chains in $5.7 Million…
مشاهدهی خبر کامل در منبع ↗ بازگشت به KiiChainاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.