Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
A serious security flaw has been discovered in the shared modules that make up the Cosmos EVM infrastructure, resulting in multiple blockchain networks being affected by attacks that exploited this vulnerability.
Specifically, it is believed that vulnerabilities arose from a combination of several upstream defects, including calculation errors in staking processes, such as underflows. Among the affected networks, MANTRA and Nesa were able to prevent direct impacts on user funds through proactive chain halting measures.
On the other hand, KiiChain suffered a loss of approximately 150 million KII, equivalent to about $9 million at the time's theoretical price (around 1.43 billion yen), leading to a collapse in token prices. Additionally, around 3 billion TAC, worth approximately $7.5 million (about 1.19 billion yen), was withdrawn from staking contracts, resulting in significant losses being reported.
Growing Criticism from the Community Regarding Disclosure Practices
In this series of incidents, the most strongly criticized aspect by the security community in the cryptocurrency industry and the affected projects is the information-sharing process of Cosmos Labs, the module developer.
After the situation was revealed, Cosmos Labs urgently recommended the halting of EVM chain operations for the affected networks. However, the disclosure of vulnerability fixes that occurred prior to this was handled in a manner close to a silent patch model (post-fix without public disclosure), which has been criticized as extremely inadequate.
Delayed Response and Future Challenges
According to a verification report published by KiiChain, when a critical patch was made public in mid-August, individual notifications were not sent to the affected chains in advance, and there was insufficient warning regarding the importance of the update. As a result, attackers were able to exploit the vulnerability before the patch was applied, having analyzed the code updates.
It has been pointed out that if clear emergency halting measures had been communicated after prior non-public notifications, the damage could have been minimized. Cosmos Labs plans to submit a detailed incident report, but this case has left significant challenges regarding the coordination and disclosure processes of vulnerability information among infrastructure providers in the industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Attacker Steals $50 Million in NES, Only Profits $60,000

Cosmos EVM Module Faces Security Incident, Multiple Chains Affected

Coincheck Completes Registration for Electronic Payment Services, Becomes Second Company in Japan

Will Token Be the New Dollar for Stripe?

Revolut Launches First Euro Stablecoin 'EURR' on Ethereum via Stripe's Bridge

Crypto: Tax Rules Miss the Core of Flow

CZ: AI and Crypto Integration Will Start with Stablecoins, AI Trading Takes Priority Over AI Payments

Osaka Prefecture Approves Funding for Four Financial Demonstration Projects, Three Involving JPYC and USDC Payments

The Witcher 3 to Receive a Free Remaster with Xbox Play Anywhere

HYPE whale adds $24M as a16z link remains unverified

Ethereum Deposit Contract Draft Allows for Quantum-Resistant Keys

CZ: Global Compliance Adoption of Cryptocurrency is Challenging but Progressing

Not Selling to Coinbase: We Might Achieve More Than Fomo

BlackRock may eventually launch altcoin ETFs: Geraci

39 US state banking groups form BankChain Alliance for 2027 blockchain launch

A Founder’s Reflection: With the Same Starting Point, Why Does FOMO Run Further Than Us?

Global Debt Cycle May Enter 'Debt Cancellation' Phase

Impact of Bitcoin Contract Analysis on BitVM Bridge by 唐华斑竹

DeFi Wasn't Made for You, It Was Made for AI

Connecticut sues Kalshi over unlicensed sports event contracts

Wall Street Speculates: What’s Scott Bessent’s Next Move to 'Rescue' U.S. Debt?

"The largest cyberattack in its history": Norway targeted by pro-Russian hackers paid in crypto

Are 200 AI Trading Products Useless? A Unique Take from a Former Co-Founder of Foresight Ventures

CFTC Warns About Cryptocurrency ATMs as U.S. Losses Reach Approximately $617 Million by 2025

What is Bubblemaps (BMT)? Insights from On-Chain Analysis

What is Bitlayer (BTR)? What Happened with Bitcoin Bridge?

Chainalysis Leads 'Operation Lighthouse', Identifies Over 7,700 Suspicious Accounts

The Digitalization of Real Estate Ownership: What Happens to Your Rights, Risks, and Liquidity?

Hedge Funds Bet Massively Against the Dollar







