Cosmos has been dealing with issues over the past couple of days.
The vulnerability was reported under a bounty program back in April. Cosmos Labs tested it themselves at the time and concluded that the mainnet was safe. They quietly applied a patch without issuing any public notice. In early August, external researchers confirmed that all chains running Cosmos EVM were affected. The patch was only released during the night of August 19, and the first wave of attacks arrived in the afternoon of August 20.
In five days, six chains were drained, totaling roughly $5.7 million. MANTRA ($OM) was the worst hit: about 360 million tokens—around 360 million—were taken from the burn address and an early multisig wallet, worth about $3.6 million at the time. TAC and KiiChain were also hit. The attackers exploited an integer underflow vulnerability—wrapping balances to an extremely large value, then reversing the action to move coins from other users’ accounts.
The most baffling part is the disclosure process. The patch went out 20 hours before the attacks began, and the 40 validator nodes simply didn’t have enough time to coordinate an upgrade. Accounts on relevant transaction platforms have been frozen, but whether the funds can be recovered is still uncertain.
After this incident, all Cosmos EVM chains must upgrade to v0.6.2 or higher to be considered compliant. Open-source collaboration and transparency are good things, but silent patches that bury the risk inside them really do make your spine tingle.
#Cosmos #安全事件 #DeFi $ATOM $OM