Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
A serious security flaw has been discovered in the shared modules that make up the Cosmos EVM infrastructure, resulting in multiple blockchain networks being affected by attacks that exploited this vulnerability.
Specifically, it is believed that vulnerabilities arose from a combination of several upstream defects, including calculation errors in staking processes, such as underflows. Among the affected networks, MANTRA and Nesa were able to prevent direct impacts on user funds through proactive chain halting measures.
On the other hand, KiiChain suffered a loss of approximately 150 million KII, equivalent to about $9 million at the time's theoretical price (around 1.43 billion yen), leading to a collapse in token prices. Additionally, around 3 billion TAC, worth approximately $7.5 million (about 1.19 billion yen), was withdrawn from staking contracts, resulting in significant losses being reported.
Growing Criticism from the Community Regarding Disclosure Practices
In this series of incidents, the most strongly criticized aspect by the security community in the cryptocurrency industry and the affected projects is the information-sharing process of Cosmos Labs, the module developer.
After the situation was revealed, Cosmos Labs urgently recommended the halting of EVM chain operations for the affected networks. However, the disclosure of vulnerability fixes that occurred prior to this was handled in a manner close to a silent patch model (post-fix without public disclosure), which has been criticized as extremely inadequate.
Delayed Response and Future Challenges
According to a verification report published by KiiChain, when a critical patch was made public in mid-August, individual notifications were not sent to the affected chains in advance, and there was insufficient warning regarding the importance of the update. As a result, attackers were able to exploit the vulnerability before the patch was applied, having analyzed the code updates.
It has been pointed out that if clear emergency halting measures had been communicated after prior non-public notifications, the damage could have been minimized. Cosmos Labs plans to submit a detailed incident report, but this case has left significant challenges regarding the coordination and disclosure processes of vulnerability information among infrastructure providers in the industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Attacker Steals $50 Million in NES, Only Profits $60,000

Cosmos EVM Module Faces Security Incident, Multiple Chains Affected

Consolidation in Ranges and Rate Reevaluation: Trader Assesses Bitcoin and Ethereum Movement Scenarios

Action Strategy (MSTR): Is the bottom behind us now? Analysis by Vincent Ganne

The Government Officialized a New Salary Increase for Military, Security Forces, and Public Employees: How Much Will It Be

Alipay's Stance: Stablecoins Enter AI

Ontology halts mainnet block production over potential security concern

Digital Ruble Fails to Generate Significant Interest Among Russians, Says Sberbank

AI Scam Hits $3.2 Million Per Incident, Crypto Security Battlefield Shifts from 'Code' to 'Scams'

Matt Damon to Keynote at Ripple Swell 2026 in New York

XRP Ledger lending vote: What XRP holders should know

WEEX Trade to Earn Series 6: How Futures Trading Fees Relate to Market Volatility

How Paintings Could Have Become Part of the Digital Economy, but Didn't

Shein's IPO and China's PMI: What Changes for Markets

From Pay to One-Stop Asset Management, BiyaPay Expands Global Diverse Financial Services Boundaries

Trump's Cryptocurrency Scheme Rakes in $1.4 Billion While Investors Lose $4.7 Billion

Zcash private transactions could fall below 200ms

Behind the Surge of Robinhood Chain: Real Prosperity or Emotional Premium?
![[Block Media 1st Term 6th Reader Committee Meeting] "In-depth Articles Needed for Differentiation ⋯ Impressive Critique of Altcoin Listings by Chairperson Park Hyun-joo"](/public-static/9_8dc682caea.png?format=avif)
[Block Media 1st Term 6th Reader Committee Meeting] "In-depth Articles Needed for Differentiation ⋯ Impressive Critique of Altcoin Listings by Chairperson Park Hyun-joo"

A 36-day staking bottleneck is costing Ethereum depositors over $350,000 in lost rewards daily

AI Creates Abundance, BTC Creates Scarcity: What Web3 Truly Changes Is Not Production Relations, But Value Relations

Who is Selling Yushu? Large-Scale Transfer of High-Level Shares, 228.7 Million Shares to Be Unlocked Next Year

Ripple Donates $300,000 for Flood Relief in Nepal and Tibet

Cryptocurrency Arbitrage and Price Scanning: How Quants Identify Inefficiencies in Funding Rates and Spreads Using Trading APIs

DRAM Shortage Until 2030: How to Position Yourself on Memory Giants?

Why Stablecoins Can't Serve as Credit Despite Being Transferable and Store of Value?

Revolut begins EURR rollout as ECB details digital euro privacy safeguards

Bernstein Comments on Seven Memory Types: After HBM, DRAM and NAND Compete for the Next Trillion-Dollar Market

RAKIB Council for Financial Institutions Development: Association Prepares Crypto Market for Self-Regulation



