AI · The Block
Cosmos Labs confirms it wrongly cleared the flaw behind a $5.7 million six-chain hack
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Cosmos Labs said attackers stole funds across six blockchain networks between Aug. 20 and Aug. 25 using a flaw in Cosmos EVM, the shared software that lets Cosmos chains run Ethereum-style applications, according to a technical post-mortem published Friday.
Key facts
- KiiChain, which deals in foreign exchange infrastructure, lost about 148 million KII the same evening. 64.6 million KII tokens were sold for about $1.6 million, according to the report
- TAC, which brings DeFi applications to TON and Telegram users, lost nearly 3 billion TAC from its staking pool on Aug. 22, Cosmos Labs said
- MANTRA traded near $0.0043 on Saturday, according to CoinGecko data, down around 70% year-to-date
- Attackers exchanged the stolen tokens for about $2.87 million in other assets on decentralized exchanges and $2.85 million on centralized exchanges, per the report, which also states the attacker's
Summary
Attackers exchanged the stolen tokens for about $2.87 million in other assets on decentralized exchanges and $2.85 million on centralized exchanges, per the report, which also states the attacker's centralized exchange accounts "have been frozen pending investigation by the relevant authorities. Cosmos Labs notably disclosed that a researcher had identified the flaw and submitted a report through the Cosmos bug bounty program on April 25, according to the post-mortem. "Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds," the report states.