Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
Cosmos Labs Faces Criticism Over Disclosure Bug Issue, Leading to Recommendations for EVM Chains to Halt Operations
A serious security flaw has been discovered in the shared modules that make up the Cosmos EVM infrastructure, resulting in multiple blockchain networks being affected by attacks that exploited this vulnerability.
Specifically, it is believed that vulnerabilities arose from a combination of several upstream defects, including calculation errors in staking processes, such as underflows. Among the affected networks, MANTRA and Nesa were able to prevent direct impacts on user funds through proactive chain halting measures.
On the other hand, KiiChain suffered a loss of approximately 150 million KII, equivalent to about $9 million at the time's theoretical price (around 1.43 billion yen), leading to a collapse in token prices. Additionally, around 3 billion TAC, worth approximately $7.5 million (about 1.19 billion yen), was withdrawn from staking contracts, resulting in significant losses being reported.
Growing Criticism from the Community Regarding Disclosure Practices
In this series of incidents, the most strongly criticized aspect by the security community in the cryptocurrency industry and the affected projects is the information-sharing process of Cosmos Labs, the module developer.
After the situation was revealed, Cosmos Labs urgently recommended the halting of EVM chain operations for the affected networks. However, the disclosure of vulnerability fixes that occurred prior to this was handled in a manner close to a silent patch model (post-fix without public disclosure), which has been criticized as extremely inadequate.
Delayed Response and Future Challenges
According to a verification report published by KiiChain, when a critical patch was made public in mid-August, individual notifications were not sent to the affected chains in advance, and there was insufficient warning regarding the importance of the update. As a result, attackers were able to exploit the vulnerability before the patch was applied, having analyzed the code updates.
It has been pointed out that if clear emergency halting measures had been communicated after prior non-public notifications, the damage could have been minimized. Cosmos Labs plans to submit a detailed incident report, but this case has left significant challenges regarding the coordination and disclosure processes of vulnerability information among infrastructure providers in the industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

NES token trading resumes on Binance Alpha and Kraken after $286M exploit

NESA Shifts from Opposition to Neutral on CLARITY Act, Clearing a Major Obstacle for Voting

Attacker Steals $50 Million in NES, Only Profits $60,000

Cosmos EVM Module Faces Security Incident, Multiple Chains Affected

What is PCE and Why September 30 is Important for Cryptocurrencies

Cryptocurrency Bill Fails, Fed Raises Rates, Yet Bitcoin Rises?

2026: The Year of Polarization in Virtual Assets

Bitcoin: JPMorgan Sees BTC Outperforming Gold

Important News from Last Night and This Morning (September 19 - September 20)

Why the Robinhood Chain Boom Has Not Led to Growth in the Ethereum Mainnet

Why Trump backed a crypto ethics rule that stopped at the family business

Circle wants you to love USDC a little like you love Chelsea

How the Clarity Act's Defeat Handed the SEC and CFTC the Wheel on Crypto

Grayscale Is Making Its Red-Hot Zcash ETF More Affordable

Speeding Up Without Sacrificing Decentralization? Ethereum EIP-8198 Adjusts Timing Before Reducing Block Size

Ethereum and Base Abandon Common Standard for Crypto Wallets

Banning stablecoin yields barely boosts bank credit

Bitcoin faces an October 18 test as Trump prepares new Russia tariffs

Wyoming: LayerZero Loses State Stablecoin, Chainlink Takes Over

Circle's Enterprise-Level Stablecoin Blockchain Arc Sees Most Traffic from Meme Tokens, with Only About 624,000 USDC Transfers

Avalanche Treasury Warning: Large-scale Entry of AI Agents into Financial Markets Will Severely Deplete L1 Blockchain Capacity

Hyperliquid's Path to the U.S. Revealed: Kraken's Parent Company Accesses via HIP-3, Restrictions Remain Stringent

SEC Holds All-Day Trading Symposium! Paul Atkins: Discussing Extending US Stock Trading to 24 Hours to Align with Cryptocurrency Market

European Stock Exchanges: Tokenized Stocks Disrupt an Already Fragmented Market

HotShort to present short-drama RWA model at GWDC Korea 2026

AI Model Gemini Exits Testing and Attacks Three Real Companies

BlackRock Executive: Bitcoin Volatility Halved, Shifting from 'Get-Rich Narrative' to 'Collateral Narrative'

Lemon exits Brazil over crypto licensing costs

Brazil blocks stablecoins from key cross-border payment rail as $1.1 trillion market faces new limits





