EX
EXBASI.COMLive Crypto Intelligence
⌘K
Back to News

Cosmos Labs Admits Misjudging Cosmos EVM Integer Underflow Bug After $5.7 Million Theft

By Exbasi Intelligence
Sourced from Binance News
Cosmos Labs Admits Misjudging Cosmos EVM Integer Underflow Bug After $5.7 Million Theft
Cosmos Labs published a technical report saying it had previously misjudged an integer underflow vulnerability in Cosmos EVM, which led to attacks on six blockchain networks between August 20 and August 25 and the theft of about $5.7 million in tokens. According to ChainCatcher, the attacker used the flaw to underflow account balances to the maximum value of 2^256-1, then reversed the process to transfer the inflated balance and steal tokens from target accounts without minting new tokens.The report said researchers submitted the bug through a bounty program on April 25, but testers could not reproduce it on existing Cosmos chain configurations, so Cosmos Labs applied a silent fix in May. After an independent researcher confirmed in early August that the issue affected all Cosmos EVM chains, Cosmos Labs released a patch on August 19, but the first attack occurred about 20 hours later.MANTRA said it lost 720.9 million tokens, or about $3.6 million, while TAC lost nearly 3 billion TAC and KiiChain lost about 148 million KII. MANTRA and KiiChain criticized Cosmos Labs for not notifying affected chains in advance and recommended shutting down operations, with KiiChain saying the patch would take days to deploy while a shutdown would take only minutes. Cosmos Labs said it coordinated with 40 chains and helped 13 chains fix the issue or shut down before they were attacked.

AI Market Prediction