7 hours ago
Cosmos Labs says it wrongly cleared bug behind $5.7 million six-chain hack
Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack
The Block

Cosmos Labs said it wrongly cleared a Cosmos EVM flaw that attackers used to steal $5.7 million across six blockchain networks between Aug. 20 and Aug. 25. Attackers exchanged the stolen tokens for about $2.87 million in other assets on decentralized exchanges. They exchanged $2.85 million on centralized exchanges. The post-mortem states that the attackers' centralized exchange accounts have been frozen pending investigation by relevant authorities. A researcher reported the flaw through the Cosmos bug bounty program on April 25. Cosmos Labs said its testers could not reproduce the attack against the configuration used by live Cosmos chains. Cosmos Labs said it concluded that funds on those networks were not at risk. The firm addressed the vulnerability through its silent public patch process instead of its private patch distribution process. The flaw involved an integer underflow that could make attacking wallets appear to hold effectively infinite tokens. Attackers could then transfer the inflated balance to a target account and leave the target with nothing. The process did not create tokens, and total supply was effectively unchanged. MANTRA said the exploit moved its supply by a single base unit. Cosmos Labs said the targets included arbitrary accounts with large balances, such as burn addresses and multisignature wallets. The critical advisory covers Cosmos EVM releases before v0.6.2 and v0.7.2. Cosmos Labs merged a fix in May while believing that live chains were not affected. The firm said it had patched 37 vulnerabilities through that process over the past 13 months. Independent researchers established in early August that the flaw affected all Cosmos EVM chains, according to the post-mortem. Cosmos Labs released the patch at 7:01 p.m. ET on Aug. 19. The release notes described the changes only as important security fixes. The first attack began about 20 hours later. MANTRA said 20 hours was not enough time to assess, test, and coordinate an upgrade across 38 independent validators. A Push Chain developer publicly described the vulnerability and its exploitation path at 3:16 a.m. ET on Aug. 20. The developer credited an audit by Hacken and listed the affected versions. MANTRA said the security finding was filed 11 hours and 45 minutes before the attacker's first probe. MANTRA lost 720.9 million MANTRA tokens then worth about $3.6 million. The tokens were drained from a burn address and a dormant multisignature wallet. MANTRA halted its chain at 7:13 p.m. ET on Aug. 20. The chain resumed more than 30 hours later on patched software without a rollback. TAC lost nearly 3 billion TAC from its staking pool on Aug. 22. About 1.2 billion TAC were sold on BNB Chain for around $950,000. KiiChain lost about 148 million KII on the same evening. About 64.6 million KII were sold for about $1.6 million. Cosmos Labs said roughly 54% of the KII taken remains recoverable onchain if the network is restored. Three other chains were attacked using the same method, but Cosmos Labs did not name them. Bubblemaps said one of those chains may be Nesa. Bubblemaps said an attacker moved $50 million of NES back to Ethereum after inflating the balance 200-fold. Bubblemaps said extreme slippage left the attacker with only $60,000 in profit. Bubblemaps said the Nesa attack may have involved a separate party. The two remaining chains have not been publicly identified. MANTRA said no tokens had been recovered as of Aug. 28. KiiChain said Cosmos Labs did not give affected chains advance notice or recommend halting until Aug. 22, after MANTRA, TAC, and KiiChain had been attacked. KiiChain said the exploit required three upstream defects and that only the underflow had been publicly patched. MANTRA said the underflow fix closed the attack path. Cosmos Labs said it coordinated with 40 chains during the response. The firm worked with 13 other chains to patch the vulnerability or halt them before further attacks. Cosmos Labs said it discovered 11 previously unregistered Cosmos EVM deployments during the response.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.