Ridiculous! Cosmos publicly released a high-risk patch but did not notify in advance, hackers preemptively "emptied" the project's treasury.

CN
链捕手
Follow
2 hours ago

Author: Gu Yu, ChainCatcher

In the past few days, the Cosmos ecosystem has witnessed a security disaster that could have been avoided. Blockchains such as MANTRA, TAC, KiiChain, and Nesa, which adopted the Cosmos EVM module, were successively attacked. The protocol reserve tokens in each chain's treasury wallet were stolen in bulk by hackers and quickly sold off, leading to a plunge of over 90% in tokens such as KII, TAC, and NES within just a few hours, causing substantial losses for many holders.

Initially, the market did not pay attention to the common factor behind this series of incidents—these were all Cosmos ecosystem blockchains. After all, hacking incidents in the crypto market are already commonplace, but it was not until yesterday that the market noticed that this series of incidents originated from the v0.7.2 version upgrade code released by Cosmos Labs on August 19 on GitHub.

Outrageous! Cosmos publicly disclosed high-risk patches without prior notification, hackers preemptively ‘emptied’ project treasuries

Cosmos Labs wrote on that GitHub page: “This version contains important security fixes. We recommend that all chains upgrade to this patched version as soon as possible using a coordinated upgrade method. This release is of disruptive significance.” The urgency reflected in the wording indicates the severity of the vulnerability.

However, Cosmos Labs' actions are puzzling: they fully disclosed the security patch but did not send any private warnings or mandatory upgrade notifications to the project teams reliant on that module. This is akin to hanging the treasury key in a public square and labeling it “please take it quickly,” giving malicious actors ample time to research and carry out the attack.

“If attackers can read GitHub, downstream teams need something better than GitHub. Vulnerabilities will always happen. The measure of corporate infrastructure is everything that happens after a vulnerability occurs: who was exposed, who received a warning, who received the patch, and who acted first, the customer or the attacker. We need a complete post-mortem analysis report from Cosmos Labs. But this is unspinnable: coordination failed very severely,” developer @justde said.

KiiChain, which was attacked, also published a statement directly blaming Cosmos Labs for their irresponsible behavior, stating that this incident “could have been avoided.”

KiiChain stated that when Cosmos Labs released the announcement on Friday, they bundled the fix with a batch of unrelated issues that had been privately handled before. At that time, the matter was not treated as extremely urgent, as if it were a severe vulnerability that could lead to permanent loss of funds. They also did not recommend pausing all chains.

KiiChain also disclosed the specific attack principles of the vulnerability. The attack required the simultaneous occurrence of three upstream defects in the Cosmos EVM module: underflow when writing back the balance after delegation during staking precompilation, along with two other undisclosed vulnerabilities. KiiChain's specific code was not involved in this attack. All Cosmos EVM chains with enabled attributed accounts are at the same risk.

Even more lamentable is that such attacks continued until the evening of the 24th. The Nesa project team immediately issued an announcement and took measures to suspend the blockchain. “We have detected malicious behavior utilizing the Cosmos EVM vulnerability on L1 and are currently taking steps to contain the impact. We have acted swiftly, and after applying software fixes and further remedial measures to ensure safe operation, we will restore service online.”

Outrageous! Cosmos publicly disclosed high-risk patches without prior notification, hackers preemptively ‘emptied’ project treasuries

At this point, Nesa tokens have already plunged over 94%, from a previous $0.22 to $0.011. Very few projects can recover from such a steep decline.

However, despite multiple Cosmos EVM security incidents and issues being exposed at least two days prior, the project team still did not take proactive measures to mitigate risks, demonstrating a serious deficiency in the technical team’s awareness of risks and responsibilities.

As early as the 21st, MANTRA publicly stated that it had identified the root cause of the incident, limited to the Cosmos EVM module of MANTRA Chain.

Outrageous! Cosmos publicly disclosed high-risk patches without prior notification, hackers preemptively ‘emptied’ project treasuries

As discussions continue to escalate, Cosmos Labs' public response has come late: “The ongoing security incident has affected users of the Cosmos EVM module. The security and engineering teams of Cosmos Labs have proactively addressed this incident. We have advised Cosmos EVM chains that have contacted us to request validators to pause their chains.”

However, it is too late; criticism and disappointment from all sides flood social media. “They maintain a shared EVM module that dozens of chains rely on, but when a critical precompilation vulnerability arose, they did not proactively issue a patch to the main channel, there was no clear PoC, and no coordinated deployment guidance. These chains are the downstream of your code. Your job is to quickly release security patches + ready-to-deploy PoC so the entire ecosystem can upgrade cleanly. Instead, we received silence from upstream destruction, and each team can only struggle alone,” developer @justde stated.

Currently, the market capitalization of Cosmos token ATOM is still $800 million, ranking 68th among all tokens, but it has fallen over 95% from its peak.

Its ecosystem development has also faced setbacks in recent years, with several Cosmos ecosystem projects such as Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation announcing the cessation of operations in the past six months. Projects like Secret Network and Noble announced their abandonment of the Cosmos ecosystem, choosing to build their Layer 1 or migrate to the Ethereum ecosystem.

This series of thefts undoubtedly amplifies the deep flaws in Cosmos's underlying code security auditing, cross-chain coordination mechanisms, and emergency response systems.

Security vulnerabilities may be unavoidable, but the outrageous logic of “disclosing patches without notifying downstream” and various “makeshift performances” are enough to send chills down the spine of all builders.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink