$5.7M Hack Exposed by Cosmos Labs' Critical Mistake with EVM Vulnerability
Cosmos Labs has admitted that it made a critical mistake in handling a vulnerability in its Cosmos EVM software, which led to a $5.7 million hack across six blockchain networks.
The attack, which occurred between August 20 and 25, exploited an integer underflow bug that allowed the attacker to trick the systems into crediting their wallets with effectively infinite tokens.
Cosmos Labs had previously disclosed that a researcher had identified the flaw in April through its bug bounty program, but incorrectly assessed that it did not affect live chains.
The company then merged a fix for the vulnerability using its silent patch process in May, which does not inform chain operators about the patches. However, reports from independent researchers in early August revealed that the bug affected all Cosmos EVM chains.