Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
A serious security flaw has been discovered in the shared modules that make up the Cosmos EVM infrastructure, resulting in multiple blockchain networks being affected by attacks that exploited this vulnerability.
Specifically, it is believed that vulnerabilities arose from a combination of several upstream defects, including calculation errors in staking processes, such as underflows. Among the affected networks, MANTRA and Nesa were able to prevent direct impacts on user funds through proactive chain halting measures.
On the other hand, KiiChain suffered a loss of approximately 150 million KII, equivalent to about $9 million at the time's theoretical price (around 1.43 billion yen), leading to a collapse in token prices. Additionally, around 3 billion TAC, worth approximately $7.5 million (about 1.19 billion yen), was withdrawn from staking contracts, resulting in significant losses being reported.
Growing Criticism from the Community Regarding Disclosure Practices
In this series of incidents, the most strongly criticized aspect by the security community in the cryptocurrency industry and the affected projects is the information-sharing process of Cosmos Labs, the module developer.
After the situation was revealed, Cosmos Labs urgently recommended the halting of EVM chain operations for the affected networks. However, the disclosure of vulnerability fixes that occurred prior to this was handled in a manner close to a silent patch model (post-fix without public disclosure), which has been criticized as extremely inadequate.
Delayed Response and Future Challenges
According to a verification report published by KiiChain, when a critical patch was made public in mid-August, individual notifications were not sent to the affected chains in advance, and there was insufficient warning regarding the importance of the update. As a result, attackers were able to exploit the vulnerability before the patch was applied, having analyzed the code updates.
It has been pointed out that if clear emergency halting measures had been communicated after prior non-public notifications, the damage could have been minimized. Cosmos Labs plans to submit a detailed incident report, but this case has left significant challenges regarding the coordination and disclosure processes of vulnerability information among infrastructure providers in the industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Attacker Steals $50 Million in NES, Only Profits $60,000

Cosmos EVM Module Faces Security Incident, Multiple Chains Affected

DefiLlama and Forgd introduce institutional token grades, but warn that AAA does not mean risk-free

21-bank stablecoin has global backing, but can it rival USDT and USDC?

Bitcoin faces a two-week Fed trap as inflation rewrite threatens to upend rate cuts

The source on Naura and 3D DRAM memory is unavailable

Ubuntu 26.10 Releases Snapshot 3 for Testing Ahead of October Launch

Kalshi faces $500,000 daily fines as Michigan forces sports event contracts offline

30-Year Bond Yield Hits 4.079%, Raising Funding Costs for MetaPlanet's Bitcoin Purchases

Quantum Memory: The Device That Breaks Bitcoin and Replaces It

Japan’s 4% bond yield spike threatens the low-cost borrowing strategy behind corporate Bitcoin buying

Anthropic's Mea Culpa: A Complete Autopsy of Claude's Missteps

Arthur Hayes calls EUR/JPY prices crypto’s smoke alarm, but the Fed’s plumbing still shows no fire

Debate Over $300 Bitcoin Tax Exemption and Estimated Revenue Increase

Copy Trading: How Does It Work in 2026?

PL Deputy Proposes Gun Carrying Rights for Cryptocurrency Investors and Industry Executives

The Executive Who Anticipates a New Era for Cryptocurrencies: "We Are Just Getting Started"

Why GENIUS could leave digital dollars vulnerable to sudden blockchain network ‘bank runs’

Robinhood Chain Down for 14 Minutes: The Blockchain That Was Supposed to Tokenize Wall Street First Blocked Itself

Netflix Hits British Wallets with Up to 33.4% Price Increase on Plans

Cracking 1.33 Trillion Daily Tokens: B.AI Powers the “AI Grid” with Full-Stack Infrastructure to Fuel the Agentic Era

Hyperliquid vs Drift Protocol Whitepaper Comparison (2026): Technology, Tokenomics, and Trading Infrastructure

Cybercrime, Child Gambling, and Underground Banking

PostGREShell: flaw in PostgreSQL turned backup accounts into backdoors

Fomo Earns $1.2 Million Daily, Why Are Two Major Exchanges Nervous?

Stocks, Bonds, Funds: Seoul Prepares for Their Arrival on the Blockchain

A7A5: The number of transactions with the ruble stablecoin increased by 4.4 times

US Employment Surprises Threefold, Renewing Tightening Concerns... Dollar and Interest Rates Rise Together

Shen Yu: Knowledge and Action in the Age of AI









