Security Breach Overview
In a troubling security breach that targeted multiple blockchain networks, Cosmos Labs revealed that a serious vulnerability affecting its Ethereum-compatible framework, known as Cosmos EVM, was exploited between August 20 and August 25, resulting in the theft of approximately $5.72 million across six different blockchains. The company shared insights into the incident in a technical review published on Friday.
Details of the Vulnerability
The vulnerability, which stemmed from an integer underflow error, had been identified months earlier through a bug bounty program on April 25. However, initial assessments by Cosmos developers suggested that the risk to user funds was minimal, leading them to implement a silent patch in May rather than conducting press releases or alerts. The developers merged the fix into the code without informing operators about the specific details of the vulnerability it resolved.
This oversight became a point of contention when, just before the attacks began, independent researchers noted that the flaw indeed affected all Cosmos EVM chains. Cosmos Labs had attempted to suppress the exploit details in their communications, yet the first known attack was executed merely 20 hours after the security patch was made available. In a concerning timeline, the initial probing of this vulnerability coincided with a public disclosure by a Push Chain developer who detailed the flaw about 11 hours before the attacks commenced.
Execution of the Exploit
To carry out the exploit, attackers would create accounts with locked tokens, then delegate sums beyond what their balances permitted, causing the totals to wrap around into significantly inflated figures. This manipulated balance could be transferred to other accounts, affecting their value and effectively swindling assets without increasing the overall token supply.
Impact on Victims
Among the victims, MANTRA suffered notable losses, with around 720.9 million MANTRA tokens valued at $3.6 million siphoned from two accounts, including a burn address that was inadequately monitored by the network’s systems. The blocked transactions went undetected for about four hours, allowing the assailants ample time to exploit vulnerabilities in dormant wallets from previous campaign incentives. After the attack was discovered, MANTRA swiftly halted its network, which remained immobilized for approximately 30 hours while defenses were reviewed and bolstered.
Other networks targeted in these cross-chain attacks included TAC and KiiChain, with TAC losing nearly 3 billion tokens from its staking pool and KiiChain experiencing a breach resulting in the loss of approximately 148 million KII tokens. Notably, KiiChain highlighted deficiencies in how Cosmos communicated the vulnerability, stating that adequate warnings and instructions were lacking, which impeded their ability to respond effectively.
Recovery Efforts and Broader Implications
As part of ongoing recovery efforts, Cosmos Labs collaborated with numerous networks and facilitated patch deployments after the fact. However, some networks reported several additional chains had been compromised similarly without prior warning from Cosmos. A blockchain analytics firm, Bubblemaps, further identified Nesa as another potential victim, emphasizing a pattern of exploitation that exploited the same underlying vulnerabilities.
In a broader context, this incident sheds light on the need for better communication and security practices within the blockchain ecosystem. The ripples of this security breach extend beyond immediate financial losses, as they raise questions regarding the efficacy of vulnerability disclosures and the protocols that should be in place to protect users across these interconnected networks. Amidst the turmoil, MANTRA is notably undergoing an acquisition by Inveniam Capital Partners, with plans for continued operation of its infrastructure going forward.
Overall, these events underscore the critical importance of vigilance in network security and comprehensive notification systems to secure funds in the rapidly evolving blockchain environment.