Cosmos Labs said it wrongly cleared a Cosmos EVM flaw that attackers used to steal $5.7 million across six blockchain networks between Aug. 20 and Aug. 25. Attackers exchanged the stolen tokens for about $2.87 million in other assets on decentralized exchanges. They exchanged $2.85 million on centralized exchanges. The post-mortem states that the attackers' centralized exchange accounts have been frozen pending investigation by relevant authorities. A researcher reported the flaw through the Cosmos bug bounty program on April 25. Cosmos Labs said its testers could not reproduce the attack against the configuration used by live Cosmos chains. Cosmos Labs said it concluded that funds on those networks were not at risk. The firm addressed the vulnerability through its silent public patch process instead of its private patch distribution process. The flaw involved an integer underflow that could make attacking wallets appear to hold effectively infinite tokens. Attackers could then transfer the inflated balance to a target account and leave the target with nothing. The process did not create tokens, and total supply was effectively unchanged. MANTRA said the exploit moved its supply by a single base unit. Cosmos Labs said the targets included arbitrary accounts with large balances, such as burn addresses and multisignature wallets. The critical advisory covers Cosmos EVM releases before v0.6.2 and v0.7.2. Cosmos Labs merged a fix in May while believing that live chains were not affected. The firm said it had patched 37 vulnerabilities through that process over the past 13 months. Independent researchers established in early August that the flaw affected all Cosmos EVM chains, according to the post-mortem. Cosmos Labs released the patch at 7:01 p.m. ET on Aug. 19. The release notes described the changes only as important security fixes. The first attack began about 20 hours later. MANTRA said 20 hours was not enough time to assess, test, and coordinate an upgrade across 38 independent validators. A Push Chain developer publicly described the vulnerability and its exploitation path at 3:16 a.m. ET on Aug. 20. The developer credited an audit by Hacken and listed the affected versions. MANTRA said the security finding was filed 11 hours and 45 minutes before the attacker's first probe. MANTRA lost 720.9 million MANTRA tokens then worth about $3.6 million. The tokens were drained from a burn address and a dormant multisignature wallet. MANTRA halted its chain at 7:13 p.m. ET on Aug. 20. The chain resumed more than 30 hours later on patched software without a rollback. TAC lost nearly 3 billion TAC from its staking pool on Aug. 22. About 1.2 billion TAC were sold on BNB Chain for around $950,000. KiiChain lost about 148 million KII on the same evening. About 64.6 million KII were sold for about $1.6 million. Cosmos Labs said roughly 54% of the KII taken remains recoverable onchain if the network is restored. Three other chains were attacked using the same method, but Cosmos Labs did not name them. Bubblemaps said one of those chains may be Nesa. Bubblemaps said an attacker moved $50 million of NES back to Ethereum after inflating the balance 200-fold. Bubblemaps said extreme slippage left the attacker with only $60,000 in profit. Bubblemaps said the Nesa attack may have involved a separate party. The two remaining chains have not been publicly identified. MANTRA said no tokens had been recovered as of Aug. 28. KiiChain said Cosmos Labs did not give affected chains advance notice or recommend halting until Aug. 22, after MANTRA, TAC, and KiiChain had been attacked. KiiChain said the exploit required three upstream defects and that only the underflow had been publicly patched. MANTRA said the underflow fix closed the attack path. Cosmos Labs said it coordinated with 40 chains during the response. The firm worked with 13 other chains to patch the vulnerability or halt them before further attacks. Cosmos Labs said it discovered 11 previously unregistered Cosmos EVM deployments during the response.
Cosmos Labs Admits Mistakenly Cleared Bug Behind $5.7M Six-Chain Hack
NS3Share
Cosmos Labs confirmed a crypto hack exploited a cleared EVM flaw, draining $5.7 million from six chains between August 20 and 25. The integer underflow vulnerability let attackers inflate token balances and siphon funds from burn addresses and multisig wallets. Reported in April, the flaw was publicly patched without private warnings. MANTRA, TAC, and KiiChain were hit, with stolen tokens appearing on centralized and decentralized exchanges. During the response, Cosmos Labs coordinated with 40 chains and found 11 unknown EVM deployments.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.