Cosmos Labs Misread Bug Before $5.7M Six-Chain Hack

Key Takeaways Six Cosmos EVM networks were exploited. Attackers converted about $5.72 million in assets. Cosmos Labs underestimated the reported vulnerability. Operators must upgrade or halt affected chains. The Cosmos Hub was not hacked The incident did not compromise the Cosmos Hub or every blockchain in the wider Cosmos ecosystem. The flaw sat in cosmos/evm, shared software that lets independent Cosmos-based networks run Ethereum-compatible applications. Six networks using that software were exploited between August 20 and August 25, according to the Cosmos Labs post-mortem. MANTRA, TAC and KiiChain were named in the detailed timeline; the document did not identify the other three publicly. That distinction prevents a shared-software failure from becoming a misleading “Cosmos hack” headline. The same scope rule applied to The Sandbox bridge exploit: a compromised integration did not mean the entire underlying protocol had been hacked. Attackers converted $5.72M through two routes Cosmos Labs estimated that attackers exchanged roughly $2.87 million through decentralized venues, based on August 19 prices. It described that figure as an estimate that had not been independently audited. A further $2.85 million was reportedly sold through centralized exchanges, bringing the amount converted or sold to about $5.72 million. Cosmos Labs said affected chains reported that the centralized-exchange accounts had been frozen while police investigations continued. The $5.72 million conversion total will not change, but recovery of frozen exchange balances could reduce the final net loss. The response also limited the damage. Cosmos Labs worked with 13 other potentially exposed networks to patch, halt or otherwise protect them without further reported incidents. It coordinated with 40 chains overall. How an accounting mismatch exposed valid balances The vulnerability began with two parts of the software calculating balances differently. Cosmos EVM’s StateDB tracked only the amount an account could spend immediately. A Cosmos vesting account, however, could hold both spendable and locked tokens, and the staking system allowed locked tokens to be delegated. When the software subtracted the full delegated amount from the smaller spendable balance, an unchecked arithmetic underflow could wrap the result to a number close to 2256. An attacker could then pair that underflow with an overflow during a transfer. The sequence did not create a lasting increase in supply. Instead, it could reduce a high-balance victim account to zero and leave the attacker with the balance previously held by that account. That made the flaw a direct fund-theft risk, not merely an inaccurate display or accounting oddity. The warning arrived nearly four months before attacks The theft was the end of a longer sequence. The decisive mistake came during the initial assessment, months before anyone exploited the code. Timeline of the security incident and exploit disclosures.
عنوان اصلی (انگلیسی): Cosmos Labs Misread Bug Before $5.7M Six-Chain Hack
مشاهدهی خبر کامل در منبع ↗ بازگشت به KiiChainاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.