Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
A serious security flaw has been discovered in the shared modules that make up the Cosmos EVM infrastructure, resulting in multiple blockchain networks being affected by attacks that exploited this vulnerability.
Specifically, it is believed that vulnerabilities arose from a combination of several upstream defects, including calculation errors in staking processes, such as underflows. Among the affected networks, MANTRA and Nesa were able to prevent direct impacts on user funds through proactive chain halting measures.
On the other hand, KiiChain suffered a loss of approximately 150 million KII, equivalent to about $9 million at the time's theoretical price (around 1.43 billion yen), leading to a collapse in token prices. Additionally, around 3 billion TAC, worth approximately $7.5 million (about 1.19 billion yen), was withdrawn from staking contracts, resulting in significant losses being reported.
Growing Criticism from the Community Regarding Disclosure Practices
In this series of incidents, the most strongly criticized aspect by the security community in the cryptocurrency industry and the affected projects is the information-sharing process of Cosmos Labs, the module developer.
After the situation was revealed, Cosmos Labs urgently recommended the halting of EVM chain operations for the affected networks. However, the disclosure of vulnerability fixes that occurred prior to this was handled in a manner close to a silent patch model (post-fix without public disclosure), which has been criticized as extremely inadequate.
Delayed Response and Future Challenges
According to a verification report published by KiiChain, when a critical patch was made public in mid-August, individual notifications were not sent to the affected chains in advance, and there was insufficient warning regarding the importance of the update. As a result, attackers were able to exploit the vulnerability before the patch was applied, having analyzed the code updates.
It has been pointed out that if clear emergency halting measures had been communicated after prior non-public notifications, the damage could have been minimized. Cosmos Labs plans to submit a detailed incident report, but this case has left significant challenges regarding the coordination and disclosure processes of vulnerability information among infrastructure providers in the industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

NESA Shifts from Opposition to Neutral on CLARITY Act, Clearing a Major Obstacle for Voting

Attacker Steals $50 Million in NES, Only Profits $60,000

Cosmos EVM Module Faces Security Incident, Multiple Chains Affected

Zamanat Targets GCC’s $250 Billion SME Financing Gap With Up to $100 Million Tokenized Private Credit Fund

CoinFactory Founder Rasoul Rezvani Unveils the Vision Behind RZ Oasis

What You Thought Was a Safe Compliance Check Actually Handed Your Assets to Hackers

When Bitcoin's Unsolved Mystery Meets a New Meme

DEEPCOIN Completes System Penetration Testing with HackenProof to Strengthen Asset Security

In the 17th Year of the Crypto Era, Where is Solana's Path to Survival?

Oil Crisis: 5 Reasons Why the Surge Won't Stop

SEC Reveals Progress on Key Measures to Drive Quality in Thailand's Investment Market

Real Review of World.xyz: Millisecond Trading and Betting Against Market Makers

Trump's Poll Numbers Decline, Bond Market Out of Control: Is Walsh's Independent Space Opening Up?

ESMA Warns of Growing Links Between Crypto and Finance

How to Calculate Bitcoin Profit for Beginners Easily - Fintech World
![[Full Text] Solana Foundation: "Korean STOs Should Start Within Regulations and Expand Globally"](/public-static/10_5acc261b9b.png?format=avif)
[Full Text] Solana Foundation: "Korean STOs Should Start Within Regulations and Expand Globally"

Can Bitcoin Be Bought with Rp50,000? Here's How - Fintech World

Bab el-Mandeb: Oil, Bitcoin, or... what are the consequences for the economy?

Anthropic: The Report That Implicates Claude, Between Missiles, Espionage in Mali, and Chinese Pillaging

Financial Services Agency Reports 1,961 Cases of Fraudulent Investment Solicitation from April to June, Over 80% Resulted in Losses

724 Eggs Cracked, 11,348 Traders Joined: WEEX TradFi Lucky Egg Campaign Hits 10M+ USDT in Trading Volume

JPMorgan Bullish on Meta: Muse, Model API, and Subscriptions Support $820 Target Price

Pump.fun Analysis: Is It Severely Undervalued, and What Should Its Target Price Be?

Bitget Wallet joins BCCC to take part in Japan’s self custody debate

Blockstream Refuses Ransom to Liquid Attackers; 4,000 Bitcoins Stolen, Over 80% Already Returned

Kalshi plans 24/7 Tesla, Apple and Nvidia perps

Russia to require tax IDs for opening crypto depository accounts

How to Raise iPhone Prices Without Hurting Sales? JPMorgan Analyzes Apple's 'Installment Strategy'

Robinhood is Trading Fruit Flies, Solana is Trading Cats






