Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
A serious security flaw has been discovered in the shared modules that make up the Cosmos EVM infrastructure, resulting in multiple blockchain networks being affected by attacks that exploited this vulnerability.
Specifically, it is believed that vulnerabilities arose from a combination of several upstream defects, including calculation errors in staking processes, such as underflows. Among the affected networks, MANTRA and Nesa were able to prevent direct impacts on user funds through proactive chain halting measures.
On the other hand, KiiChain suffered a loss of approximately 150 million KII, equivalent to about $9 million at the time's theoretical price (around 1.43 billion yen), leading to a collapse in token prices. Additionally, around 3 billion TAC, worth approximately $7.5 million (about 1.19 billion yen), was withdrawn from staking contracts, resulting in significant losses being reported.
Growing Criticism from the Community Regarding Disclosure Practices
In this series of incidents, the most strongly criticized aspect by the security community in the cryptocurrency industry and the affected projects is the information-sharing process of Cosmos Labs, the module developer.
After the situation was revealed, Cosmos Labs urgently recommended the halting of EVM chain operations for the affected networks. However, the disclosure of vulnerability fixes that occurred prior to this was handled in a manner close to a silent patch model (post-fix without public disclosure), which has been criticized as extremely inadequate.
Delayed Response and Future Challenges
According to a verification report published by KiiChain, when a critical patch was made public in mid-August, individual notifications were not sent to the affected chains in advance, and there was insufficient warning regarding the importance of the update. As a result, attackers were able to exploit the vulnerability before the patch was applied, having analyzed the code updates.
It has been pointed out that if clear emergency halting measures had been communicated after prior non-public notifications, the damage could have been minimized. Cosmos Labs plans to submit a detailed incident report, but this case has left significant challenges regarding the coordination and disclosure processes of vulnerability information among infrastructure providers in the industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

NES token trading resumes on Binance Alpha and Kraken after $286M exploit

NESA Shifts from Opposition to Neutral on CLARITY Act, Clearing a Major Obstacle for Voting

Attacker Steals $50 Million in NES, Only Profits $60,000

Cosmos EVM Module Faces Security Incident, Multiple Chains Affected

Justin Sun Shares AI and Quantum Vision at TOKEN2049 Singapore and Blockworks DAS Asia

Being right about Bitcoin won’t save your 3x leveraged ETF position

Token $EWZ, from the iShares MSCI Brazil ETF, is now available on Solana via Sunrise

Bitcoin: One Year After Massive Liquidations, the Market Remains Under Pressure

New Brazilian brokerage emerges at the same address as Brasil Bitcoin, with the same partners and holds key domain: understand the tension involving the exchange's leadership

Luxor’s reported 6–13% annualized Bitcoin yield depends on mining delivery

Crypto: Solana Overtakes Ethereum in dApps

Coinbase’s Texas move gets a shareholder suit dismissed over Delaware-era claims

Ethereum: Vitalik Buterin entrusts his ENS to an AI agent and sets a two-year goal

L2 Cools Down, PoW+AI Rises? Analyzing TOKEN2049's Focus Project Pearl

Stealing $1.5B in crypto is easy, cashing out is the trap

Chainlink CCIP Vault Adapters: Aave, Lombard, and Maple adopt one-click cross-chain deposits

Crypto Market Maker DWF Labs' Subsidiary Sues Custodian Giant BitGo: Early Token Sell-off Triggers Market Crash

Krugman Warns France Could Collapse or Be Rescued: Eurozone Crisis Alert

Web3: What Really Remains Five Years After the Hype?

Is Ethereum's Liquidity Moat Disappearing? 10 Core Arguments Against Bearish Claims

US Treasury Yields at 6% Signal Credit Crisis... Concerns of 20% Plunge in New York Stock Market – Bloomberg

Crypto VC funding: Spiko and Nous Research raise $90m each

Inflation target of 2% may not stop the next Fed rate freeze
![[Next Ethereum II] Token Securities and Stablecoins Must Be Connected to Create a Market](/public-static/16_c530d6305c.png?format=avif)
[Next Ethereum II] Token Securities and Stablecoins Must Be Connected to Create a Market

AI vs Bitcoin: Google Secures 890 MW of Nuclear Power

Ripple co-founder donates approximately 3.6 billion yen for U.S. midterm elections amid backlash against cryptocurrency organization

Successful Conclusion of GMA AI & Gaming Nexus Singapore: Focusing on the Future of AI and Gaming

Cryptography Doomsday Warning: How Should Blockchain Save Itself When AI Targets Your Private Keys?
![[Next Ethereum ①] Reasons Wall Street Chooses Ethereum](/public-static/072_03aa81ca45.png?format=avif)
[Next Ethereum ①] Reasons Wall Street Chooses Ethereum










