Crypto
Home›Crypto›Regulation›Cosmos Labs disputes claims about the bug behind a $5.…
Cosmos Labs disputes claims about the bug behind a $5.7M hack
Cosmos Labs said the flaw was submitted via its bug bounty program on April 25, and that it could not be reproduced on live Cosmos EVM production networks before a silent patch was issued.
Cosmos Labs said it handled the software issue behind a six-chain hack that netted about $5.7 million in token proceeds by using a shared Cosmos component, known as Cosmos EVM, to credit an attacker with effectively infinite tokens. According to a post-mortem cited by The Block, the company said a researcher reported the flaw through Cosmos Labs’ bug bounty program on April 25, and its internal testers concluded live Cosmos EVM networks were not vulnerable, prompting a “silent, public” patch process rather than private patch distribution. The Block reports that the attacker exploited an integer underflow bug in Cosmos EVM arithmetic to make balances wrap around to 2^256-1 base units, a massive 78-digit number, and then used the inflated balance to move funds that were ultimately sold for tokens worth about $5.7 million between Aug. 20 and Aug. 25. Cosmos Labs’ account conflicts with a post-mortem from MANTRA Chain, which lost $3.6 million, saying the patch was released only 20 hours before the attack began and did not identify the flaw it fixed, according to The Block.