Crypto
Home›Crypto›Regulation›Cosmos EVM bug exploited across six networks, attacker…
Cosmos EVM bug exploited across six networks, attackers stole nearly $6M
A Cosmos security postmortem said attackers converted about $2.9 million via decentralized exchanges and about $2.9 million via centralized venues, with CEX-linked accounts frozen afterward.
Cosmos EVM vulnerability exploited across six networks, including MANTRA, exposed a security gap spanning around 40 blockchains, according to a Cosmos Labs postmortem cited by CryptoSlate. The firm said it had discovered and reported the issue months earlier, but a fix was not backported to older branches because the change was state-breaking and required coordinated upgrades.
Cosmos Labs estimated attackers converted about $2.87 million through decentralized exchanges and about $2.85 million through centralized venues. The postmortem said accounts connected to the centralized-exchange activity have since been frozen.
MANTRA suffered the largest publicly detailed hit, after an unprivileged wallet moved about 720.9 million tokens from two addresses that had not authorized transactions dated Aug. 20, without compromising validator, administrator, governance, or multisig keys. Cosmos Labs said it contacted 40 networks after the attacks began, and that 13 other potentially exposed chains patched, halted, or applied mitigations before they were exploited.
CryptoSlate reported that Cosmos Labs said the upstream vulnerability had been merged into the main codebase on May 15 and later releases, patched v0.6.2 and v0.7.2, arrived late on Aug. 19, after further research showed Cosmos EVM deployments were vulnerable regardless of decimal configuration.