Cosmos Labs Admits Misjudgment in $5.7M Six-Chain Hack Post-Mortem
What happened: Cosmos Labs acknowledged it "wrongly cleared" a critical integer-underflow bug in Cosmos EVM, which was reported in April and silently patched in May but not flagged as a live risk.
What happened: Cosmos Labs acknowledged it "wrongly cleared" a critical integer-underflow bug in Cosmos EVM, which was reported in April and silently patched in May but not flagged as a live risk. The flaw enabled attackers to drain $5.7 million across six Cosmos EVM chains—including $3.6 million from MANTRA—within 20 hours of a public patch release on August 19. Attackers exploited the bug to inflate balances and siphon assets, cashing out via DEXs and CEXs. MANTRA and other affected networks criticized Cosmos Labs for insufficient disclosure and patch lead time.
Why it matters: The incident highlights the challenges of vulnerability triage and disclosure in multi-chain environments, where silent patches and ambiguous communication can leave networks exposed. The recurrence of similar bugs (as seen in the earlier $7M Saga exploit) points to systemic issues in EVM implementations. The episode is likely to intensify calls for more transparent and coordinated security practices across the Cosmos ecosystem.
Source: The Block