Cosmos Labs cleared the underflow in April after testers could not reproduce it on live configurations. The fix finally shipped on 19 August, under a release note that named nothing, and validators had twenty hours.
Cosmos Labs has admitted it misjudged the severity of a bug that attackers then used to strip roughly $5.7 million from six blockchains over five days in August.
The flaw sat in Cosmos EVM, the shared framework that lets Cosmos chains run Ethereum-style smart contracts. A researcher reported it through the bug bounty programme on 25 April. Cosmos Labs' testers tried to reproduce the attack against the configurations that live networks actually ran, could not manage it, and on that basis concluded no user funds were at risk. The fix went out through what the firm calls its silent patch process: ship the code, say nothing about what it addresses. According to the post-mortem published on Friday, Cosmos Labs has handled 37 vulnerabilities that way in the past 13 months.
The bug was an integer underflow. An attacker set up an account holding locked tokens, then delegated more of them to a validator than the account could actually spend. The balance subtracted past zero and wrapped around to 2^256-1 base units, a 78-digit number the chain read as perfectly legitimate. Sending that inflated balance to a target account ran the same arithmetic in reverse: the recipient overflowed the same ceiling, wrapped back down, and the attacker was left holding the target's tokens while the target held nothing. No new supply was created at any point. MANTRA, which lost the most, found its total supply had moved by a single base unit.
Cosmos Labs merged the fix in May. Independent researchers established in early August that the bug did affect every Cosmos EVM chain after all. The firm then obscured the patch to slow anyone trying to reverse-engineer it and released it at 7.01pm New York time on 19 August, with release notes that referred to "important" security fixes and named nothing. The first attack transaction landed at 3.06pm the following day.
"Twenty hours was not a realistic window in which to assess, build, test and coordinate a state-breaking upgrade across 38 independent validators, particularly without a vulnerability-specific advisory," MANTRA wrote in its own post-mortem, published the same day as Cosmos Labs'. It has formally raised the delay with the Cosmos maintainers and is asking for defined backport expectations on security-relevant fixes.
There was a second leak, and it came from inside the tent. At 3.16am on 20 August, about 12 hours before the first theft, a developer at Push Chain filed a public code change that described the vulnerability, laid out its exploitation path, credited the finding to an audit by the security firm Hacken and listed the affected versions. The version table omitted the two releases published eight hours earlier that contained the fix. Cosmos Labs called a downstream developer publishing an exact exploit path "highly unusual". MANTRA noted that the attacker's wallet had been funded almost four hours before that filing, then stated the timing as fact and pointedly declined to draw a conclusion from it.
MANTRA lost 720.9 million tokens, worth about $3.6 million at the time, from two addresses: the network's burn address and a dormant multisig left over from an old incentive campaign. Nothing alerted. The burn address is treated as immovable, so monitoring never covered transfers out of it, and the theft ran undetected for close to four hours while the attacker emptied the multisig as well. The chain halted at 7.13pm and came back roughly 30 hours later on patched software, without a rollback, freezing 38 million MANTRA in the attacker's wallet. The other 94.7 per cent had already gone to a single exchange deposit address across 15 transfers.
TAC, which brings DeFi applications to TON and Telegram users, lost nearly three billion tokens from its staking pool on 22 August; about 1.2 billion of those sold on BNB Chain for around $950,000. KiiChain lost roughly 148 million KII the same evening, of which 64.6 million sold for about $1.6 million, and Cosmos Labs reckons 54 per cent of the KII taken is still recoverable onchain if the network is restored. Three further chains were hit by the same method. Cosmos Labs has not named them.
KiiChain's complaint is the sharpest of the three. "A patch takes days to review, build, test and roll out across a validator set. A halt takes minutes," its report states. "The only measure that would have contained the risk immediately was a clear instruction to stop producing blocks, and that instruction came after the damage was done." Cosmos Labs recommended halting on 22 August, by which point MANTRA, TAC and KiiChain had all been drained. Halting is not a free action, and the alternative can be terminal: BounceBit killed its layer-1 outright in August after a $3 million exploit it could not patch, and Ravencoin's chain broke this month over a header field nobody had verified.
Cosmos Labs coordinated with 40 chains during the response and helped a further 13 patch or halt before attackers reached them, which is a creditable piece of incident management. Further down the same document sits the sentence that should worry every validator running the framework: the firm does not hold a complete registry of the 115-plus public blockchains built on Cosmos, and it found 11 previously unregistered Cosmos EVM deployments while it was firefighting. A disclosure process that depends on privately warning operators cannot function when the maintainer is unable to say who the operators are. Silent patching only works if the silence is temporary and the notification is real.
The wider month was already ugly. Term Finance lost $8.5 million to two ETH routed through Tornado Cash on 23 August, in an unrelated governance attack.
No tokens had been recovered as of 28 August. Attackers moved about $2.87 million of the proceeds through decentralised exchanges and $2.85 million through centralised ones, where Cosmos Labs says the accounts have been frozen pending investigation. MANTRA's circulating supply, meanwhile, has risen by 720.9 million tokens, because the balances that were taken had been excluded from supply reporting as permanently unspendable and are now sitting in somebody's wallet, entirely tradable.