Cosmos Releases Critical Security Patch Without Notification, Projects Lose Funds to Hackers

icon MarsBit
Share
AI summary iconSummary
A security breach affected multiple Cosmos-based blockchains after Cosmos Labs released a high-risk patch on August 19 without notifying dependent projects. MANTRA, TAC, KiiChain, and Nesa all experienced major on-chain incidents as hackers exploited unpatched vulnerabilities. The patch, posted on GitHub, contained urgent fixes for the Cosmos EVM module but left downstream teams unprepared. KiiChain and others criticized the lack of emergency coordination and clear deployment guidance. Attacks continued until at least August 24, with Nesa being the most recent to suspend operations and address the breach.

Author: Gu Yu, ChainCatcher

Over the past several days, the Cosmos ecosystem experienced a preventable "security disaster." Blockchains utilizing the Cosmos EVM module, including MANTRA, TAC, KiiChain, and Nesa, were sequentially attacked, with hackers bulk-stealing protocol reserve tokens from treasury wallets and rapidly selling them off. As a result, tokens such as KII, TAC, and NES plummeted over 90% within hours, causing significant losses for numerous holders.

Initially, the market did not notice the common factor behind this series of incidents—all were Cosmos-based blockchains, as hacking incidents in the crypto market had become commonplace. However, only yesterday did the market realize that all these incidents originated from the v0.7.2 upgrade code released by Cosmos Labs on GitHub on August 19.

Insane! Cosmos publicly released a critical patch without prior notice, allowing hackers to抢先 "empty" the project's treasury

Cosmos Labs wrote on this GitHub page: "This release contains critical security fixes. We recommend that all chains upgrade to this patch version via coordinated upgrades as soon as possible. This release is breaking." The urgency in the wording reflects the severity of the vulnerability.

However, Cosmos Labs' actions are perplexing: they publicly disclosed the security patch without simultaneously sending any private warnings or mandatory upgrade notifications to project teams relying on the module. This is akin to hanging the vault key on a public square with a sign saying “Please take immediately,” giving malicious actors ample time to study and execute an attack.

“If attackers can read GitHub, downstream teams need something better than GitHub. Vulnerabilities will happen. The standard for enterprise infrastructure is everything that happens after a vulnerability: who was exposed, who was warned, who received a patch, and whether customers or attackers acted first. We need Cosmos Labs’s full post-mortem report. But this can’t be sugarcoated: the coordination failure was severe,” said developer @justde.

KiiChain, which was attacked, also posted a statement directly accusing Cosmos Labs of irresponsible behavior, stating that the incident "could have been avoided."

KiiChain stated that when Cosmos Labs issued the announcement on Friday, it bundled the fix with a set of unrelated issues that had previously been handled privately. At the time, the issue was not treated as an urgent priority, as if it involved a critical vulnerability that could lead to permanent loss of funds. They also did not recommend pausing all chains.

KiiChain also disclosed the specific attack principles of this vulnerability. The attack requires three upstream defects in the Cosmos EVM module to occur simultaneously: an underflow when writing back the delegated balance to the EVM during staking precompilation, along with two other undisclosed vulnerabilities. KiiChain’s specific code was not involved in this attack. All Cosmos EVM chains with bonded accounts enabled are subject to the same risk.

More troublingly, such attacks were still ongoing as of the evening of the 24th, prompting the Nesa project team to immediately issue a notice and take measures to pause the blockchain. “We have identified malicious activity exploiting the Cosmos EVM vulnerability on L1 and are currently taking steps to contain the impact. We have acted swiftly and will restore services once software patches and additional remediation measures are in place to ensure secure operation.”

Insane! Cosmos publicly released a critical patch without prior notice, allowing hackers to抢先 "empty" the project's treasury

At this point, the Nesa token has plummeted over 94%, dropping from $0.22 to $0.011. Very few projects recover from such a steep decline.

However, the project team still did not proactively take measures to mitigate the risk even after multiple Cosmos EVM security incidents occurred and the issues were exposed for at least two days, indicating a serious lack of awareness regarding risk and responsibility within the project’s technical team.

As early as the 21st, MANTRA publicly stated that it had identified the root cause of the incident, which was limited to the Cosmos EVM module of MANTRA Chain.

Insane! Cosmos publicly released a critical patch without prior notice, allowing hackers to抢先 "empty" the project's treasury

As more discussions emerged, Cosmos Labs issued a delayed public response: “A security incident is affecting users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have proactively responded to this event. We have advised Cosmos EVM chains that contacted us to request that their validators pause their chains.”

But it was too late—criticism and disappointment flooded social media from all sides. “They maintain the shared EVM module that dozens of chains depend on, yet when a critical precompile vulnerability emerged, they failed to proactively release patches through official channels, provided no clear PoC, and offered no coordinated deployment guidance. These chains are downstream from your code. Your job is to rapidly release security patches alongside ready-to-deploy PoCs so the entire ecosystem can upgrade cleanly. Instead, we got silent sabotage from upstream, leaving every team to struggle on its own,” said developer @justde.

Currently, the Cosmos token ATOM has a market capitalization of $800 million, ranking 68th among all tokens, but is down more than 95% from its peak.

Its ecosystem development has also faced ongoing setbacks over the past several years; in the last six months alone, Cosmos ecosystem projects such as Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation have announced the cessation of operations, while Secret Network, Noble, and others have declared their departure from the Cosmos ecosystem to either build their own Layer 1 or migrate to the Ethereum ecosystem.

This series of thefts has undoubtedly highlighted the underlying deficiencies in Cosmos’s code security audits, cross-chain coordination mechanisms, and emergency response systems.

Security vulnerabilities may be inevitable, but the absurd logic of publicly patching without informing downstream parties, along with various “amateurish” behaviors, are enough to leave all builders feeling chilled.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.