خبری درباره‌ی KiiChain (KII)

Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks

crypto.news ۱۶ روز پیش خلاصه‌ی فارسی · ۴۴۹ کلمه
Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks

Cosmos Labs has disclosed that attackers exploited a critical Cosmos EVM vulnerability across six blockchain networks between Aug. 20 and Aug. 25, converting stolen tokens into about $5.72 million in assets through decentralized and centralized exchanges. Summary Attackers exploited a critical Cosmos EVM flaw across six networks between Aug. 20 and Aug. 25, converting stolen tokens into about $5.72 million in other assets. Cosmos Labs first received the vulnerability report in April but initially concluded that production networks were not at risk and handled the fix through its silent patch process. MANTRA lost 720.9 million tokens worth about $3.6 million, while TAC and KiiChain later suffered separate attacks using the same method. The first attack began about 20 hours after patched Cosmos EVM versions were released without a vulnerability specific advisory to network operators. Cosmos Labs coordinated with 40 chains during the response and helped 13 networks patch or halt before they could be attacked. Cosmos Labs said in a technical post-mortem published Friday that the flaw had first been reported through its bug bounty program on April 25, nearly four months before the attacks began. Its testers were unable to reproduce the exploit against configurations used by known production Cosmos EVM networks and concluded at the time that live user funds were not at risk. Based on that assessment, developers handled the vulnerability through a silent public patch instead of privately distributing a security fix to affected chains. Cosmos Labs merged the fix in May without telling network operators which vulnerability it addressed. The assessment later proved incorrect after independent researchers established in early August that the bug affected all Cosmos EVM chains. Cosmos Labs then obscured the fix to make reverse engineering more difficult and released patched versions at 7:01 p.m. ET on Aug. 19. Release notes referred to “important” security fixes without describing the vulnerability. The first known attack began at 3:06 p.m. ET on Aug. 20, about 20 hours after the patched software became available. Cosmos EVM flaw allowed attackers to drain large accounts The vulnerability involved an integer underflow in Cosmos EVM, the ecosystem’s Ethereum-compatible framework built from the open-source Evmos codebase. An attacker could first create an account containing locked tokens and delegate more tokens to a validator than the account was able to spend. Subtracting the delegated amount caused the balance to fall below zero, making the value wrap around to the maximum possible figure of 2^256-1 base units. The attacker could then use the inflated balance against another account. Sending the amount to a target pushed its recorded balance past the same numerical ceiling, causing an overflow that wrapped the value back down and left the attacker holding the target’s tokens.

عنوان اصلی (انگلیسی): Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به KiiChain

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.