Cosmos Labs Slammed for Neglecting Critical Vulnerability Disclosure
A series of high-profile attacks on Cosmos-based blockchain projects has left investors reeling. Projects such as MANTRA, TAC, KiiChain, and Nesa were hit with a coordinated attack, resulting in the theft of millions of dollars worth of tokens.
The attacks were made possible by a critical vulnerability in the Cosmos EVM module, which was publicly disclosed on GitHub but not communicated to downstream projects. This oversight has sparked widespread criticism, with some accusing Cosmos Labs of negligence and incompetence.
KiiChain has released a detailed explanation of the attack vector, highlighting three upstream vulnerabilities that needed to be exploited simultaneously. The project's developers have taken swift action to mitigate the damage, but not before significant losses were incurred.
The incident has raised concerns about the security and coordination within the Cosmos ecosystem. As one developer noted, 'If attackers can read GitHub, downstream teams need something better.' The community is calling for greater transparency and accountability from Cosmos Labs.