BTC $78,720.89 +1.37%
ETH $2,466.37 +1.30%
BNB $697.06 +1.29%
XRP $1.40 +0.92%
SOL $106.35 +2.52%
TRX $0.3406 +0.65%
DOGE $0.0853 +0.60%
ADA $0.2030 +1.47%
BCH $251.62 +2.67%
LINK $11.49 +1.51%
HYPE $83.65 +2.64%
AAVE $126.12 +3.05%
SUI $0.7458 +1.23%
XLM $0.1807 +1.82%
ZEC $846.11 +4.22%
BTC $78,720.89 +1.37%
ETH $2,466.37 +1.30%
BNB $697.06 +1.29%
XRP $1.40 +0.92%
SOL $106.35 +2.52%
TRX $0.3406 +0.65%
DOGE $0.0853 +0.60%
ADA $0.2030 +1.47%
BCH $251.62 +2.67%
LINK $11.49 +1.51%
HYPE $83.65 +2.64%
AAVE $126.12 +3.05%
SUI $0.7458 +1.23%
XLM $0.1807 +1.82%
ZEC $846.11 +4.22%

ltin

All
Article
Flash

first_img Cosmos Labs admits to misjudging a vulnerability, resulting in an attack on six chains with a loss of 5.7 million dollars

Cosmos Labs released a technical report, admitting that it previously misjudged an integer underflow vulnerability in the Cosmos EVM, which led to attacks on six blockchain networks between August 20 and 25, resulting in a total theft of approximately $5.7 million in tokens. The attacker exploited the vulnerability to underflow account balances to the maximum value of 2^256-1, then performed a reverse operation to transfer the inflated balance out, thereby stealing tokens from the target accounts without creating tokens out of thin air.The report shows that researchers submitted the defect through a bug bounty program on April 25, but testers were unable to reproduce it on the existing Cosmos chain configuration, so Cosmos Labs silently patched it in May. Independent researchers confirmed in early August that the vulnerability affected all Cosmos EVM chains, and Cosmos Labs released a patch on August 19, but the first attack occurred about 20 hours later.In terms of specific losses, MANTRA lost 720.9 million tokens (approximately $3.6 million), TAC lost nearly 3 billion TAC, and KiiChain lost about 148 million KII. Both MANTRA and KiiChain criticized Cosmos Labs for not notifying the affected chains in advance and suggesting a shutdown, with KiiChain stating that the patch would take several days to deploy while a shutdown would only take a few minutes. Cosmos Labs stated that it has coordinated responses with 40 chains and assisted 13 chains in completing repairs or shutdowns before being attacked.

first_img Term Finance permanently closes Meta Vaults after governance attack, resulting in a loss of approximately 8.5 million USD

The development team of Term Finance, Term Labs, announced that after the governance attack incident, all Term Meta Vaults have been permanently closed, DAO governance rights have been revoked, but the withdrawal channel remains open. In an update on August 23, Term stated that this closure is irreversible and permanently prevents subsequent deposits, but did not disclose the scale of the remaining assets in the vault, only indicating that it will "explore pathways" to address any gaps, and the amount that depositors can recover remains undecided.Blockchain security company PeckShield estimates that the attacker stole approximately 2,843 ETH (worth about $6.87 million at the time) and 1.68 million USDC (which was later exchanged for about 1.68 million DAI), with total losses estimated at around $8.5 million. On-chain records confirm the related transfers: one transaction transferred 2,841.74 WETH to an address labeled "Term Finance Exploiter 1" by Etherscan, while another transaction transferred 1.68 million USDC to an address labeled "Term Finance Exploiter 2".Yearn stated that Term's vault contract uses its V3 architecture, but the attack occurred on Term's custom governance wrapper, which is not applicable to standard Yearn vaults. Term indicated that, according to the current investigation, its underlying protocol and direct lending market were not affected and is working with external security teams for remediation and recovery, but did not provide any compensation commitments or timelines.
app_icon
ChainCatcher Building the Web3 world with innovations.