Cosmos EVM bug exploited to steal nearly $5.7M

Cosmos Labs misclassified an accounting bug reported in April; attackers exploited it in August to steal about $5.7 million across six Cosmos EVM networks.

An accounting bug reported on April 25 and patched in May was later exploited to drain about $5.7 million from six Cosmos EVM networks, according to a postmortem by Cosmos Labs. Engineers merged a fix into the main codebase on May 15 after concluding the issue affected six-decimal token deployments, and treated the change as a silent public patch rather than an emergency release.

Further analysis in early August showed deployments were vulnerable regardless of token decimal setting. Patched releases v0.6.2 and v0.7.2 were published late on Aug. 19. The morning after those patches, a public pull request in a fork described the vulnerability and the exploitation path. Less than 12 hours later, unauthorized transactions began on MANTRA on Aug. 20. TAC was exploited about 45 hours after MANTRA, with KiiChain affected soon after. Cosmos Labs contacted 40 networks and 13 potentially exposed chains patched, halted or applied mitigations before exploitation. The incident also revealed 11 Cosmos EVM deployments that the firm had not previously known about.

Attackers converted roughly $2.87 million through decentralized exchanges and an estimated $2.85 million through centralized venues. Accounts tied to the centralized-exchange activity have been frozen and funds traced to exchange routes were referred to platforms and law enforcement.

Cosmos engineers attribute the exploit to two accounting errors. An unsigned-integer underflow created an abnormally large balance that an attacker used to overflow another account and withdraw its legitimate balance without increasing total token supply. On MANTRA, an unprivileged wallet moved about 600 million tokens from a burn address and about 120.9 million from a legacy genesis-era multisig, increasing circulating supply by roughly 720.9 million MANTRA. The project valued the transfers at approximately $3.6 million at pre-incident prices. No new tokens were minted.

Monitoring failed to flag the first unauthorized MANTRA transfer for almost four hours because the burn address was treated as incapable of moving funds. The chain halted 14 minutes after a second unauthorized debit, producing an outage of roughly 30 hours. As of Aug. 28, about 38 million MANTRA remained immobilized in the attacker account and no tokens had been recovered.

Cosmos Labs said the initial assessment led it to use the silent patch process rather than private patch distribution reserved for vulnerabilities believed to threaten live funds. The postmortem added: “Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds.” The firm is revising vulnerability triage and disclosure procedures following the incident.

Cosmos EVM provides Ethereum-compatible functionality to Cosmos SDK chains. Market data places the broader Cosmos ecosystem at more than $7 billion, a figure that includes projects that may not have used the vulnerable software and does not equal the amount exposed by the bug.

Articles by this author