Outrageous! Cosmos publicly released a high-risk patch without prior notification, and hackers took the opportunity to "drain" the project's treasury
Author: Gu Yu, ChainCatcher
In the past few days, the Cosmos ecosystem has experienced a "security disaster" that could have been avoided. Blockchains such as MANTRA, TAC, KiiChain, and Nesa that use the Cosmos EVM module were successively attacked, resulting in the protocol reserve tokens in the treasury wallets of each chain being stolen in bulk by hackers and quickly sold off, causing tokens like KII, TAC, and NES to plummet over 90% within hours, leading to significant losses for many holders.
Initially, the market did not pay attention to the common factors behind this series of incidents—after all, they are all Cosmos-based blockchains, and hacking incidents in the crypto market have long been commonplace. However, it was only yesterday that the market noticed that this series of incidents originated from the v0.7.2 version upgrade code released by Cosmos Labs on GitHub on August 19.

Cosmos Labs wrote on the GitHub page: "This version contains important security fixes. We recommend all chains upgrade to this patch version as soon as possible using a coordinated upgrade approach. This release is of disruptive significance." The urgency reflected in the wording indicates the severity of the vulnerability.
However, Cosmos Labs' actions are puzzling: they made the security patch completely public but did not send any private warnings or mandatory upgrade notifications to the project teams relying on that module. This is akin to hanging the treasury keys in a public square and labeling it "please take freely," giving ill-intentioned individuals ample time to research and implement attacks.
"If attackers can read GitHub, downstream teams need something better than GitHub. Vulnerabilities will always occur. The criteria for evaluating enterprise infrastructure are all the things that happen after a vulnerability occurs: who was exposed, who got warned, who got the patch, and whether the customer or the attacker acted first. We need a complete post-mortem analysis report from Cosmos Labs. But this cannot be glossed over: the coordination failure is very serious," developer @justde stated.
The attacked KiiChain also publicly accused Cosmos Labs of irresponsible behavior and stated that this incident "could have been avoided."
KiiChain indicated that when Cosmos Labs released the announcement on Friday, they bundled the fix with a batch of unrelated issues that had been handled privately before. At that time, it was not treated as an extremely urgent matter, as if it were a serious vulnerability that could lead to permanent loss of funds. They also did not suggest pausing all chains.
KiiChain also disclosed the specific attack principles of the vulnerability. The attack requires the simultaneous occurrence of three upstream defects in the Cosmos EVM module: an underflow when writing back the balance after delegation during staking precompilation, along with two other undisclosed vulnerabilities. KiiChain's specific code was not involved in this attack. All Cosmos EVM chains that have enabled attributed accounts face the same risk.
Even more lamentable is that such attacks were still ongoing as of the evening of the 24th, prompting the Nesa project team to immediately issue an announcement and take measures to suspend the blockchain. "We have detected malicious behavior exploiting the Cosmos EVM vulnerability on L1 and are taking measures to contain the impact. We have acted swiftly and will restore service after applying software fixes and further remedial measures to ensure safe operation."

At this point, the Nesa token had already plummeted over 94%, dropping from $0.22 to $0.011. Very few projects can recover normal operations after such a sharp decline.
However, the project team still did not take proactive measures to mitigate risks even after multiple Cosmos EVM security incidents and the issues being exposed for at least two days, indicating a serious lack of risk and responsibility awareness within the project's technical team.
As early as the 21st, MANTRA publicly stated that it had identified the root cause of the incident, limited to the Cosmos EVM module of MANTRA Chain.

As discussions continued to escalate, Cosmos Labs' public response statement was delayed: "The ongoing security incident affects users of the Cosmos EVM module. The security and engineering teams at Cosmos Labs have proactively responded to this incident. We have advised Cosmos EVM chains that have contacted us to request validators to pause their chains."
However, it was too late; criticism and disappointment from various parties flooded social media. "They maintain a shared EVM module relied upon by dozens of chains, but when a critical precompilation vulnerability arose, they did not proactively release a patch to the main channel, did not provide a clear PoC, nor coordinated deployment guidance. These chains are downstream of your code. Your job is to quickly release security patches + ready-to-deploy PoCs so that the entire ecosystem can upgrade cleanly. Instead, what we got was silent destruction from upstream, leaving each team to struggle alone," developer @justde stated.
According to RootData, the current market capitalization of the Cosmos token ATOM is still $800 million, ranking 68th among all tokens, but down over 95% from its peak.
Its ecological development has also faced continuous setbacks over the past few years. In the past six months alone, Cosmos ecosystem projects such as Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation have announced the cessation of operations, while projects like Secret Network and Noble have announced their abandonment of the Cosmos ecosystem, choosing to build their own Layer 1 or migrate to the Ethereum ecosystem.
This series of thefts undoubtedly amplifies the deep-seated flaws in Cosmos regarding underlying code security audits, cross-chain coordination mechanisms, and emergency response systems.
While security vulnerabilities may be inevitable, the absurd logic of "publicly releasing patches without notifying downstream" and various "makeshift" performances are enough to chill the hearts of all builders.


Popular articles











