Cosmos Labs faces criticism after security bug affects four blockchains
Cosmos Labs patches bug but faces backlash over disclosure
Cosmos Labs, the developer behind the Cosmos EVM module, has come under fire for how it handled a recent security bug. The bug affected four blockchains that use the module: MANTRA, TAC, KiiChain, and Nesa. While the bug was patched last week, critics say the disclosure process was flawed, leading to chain halts and financial losses.
A blockchain is a digital ledger that records transactions across many computers. The Cosmos EVM module helps blockchains run smart contracts, which are self-executing agreements written in code.
Cosmos Labs eventually issued a public warning on X (formerly Twitter), advising validators—computers that verify transactions on a blockchain—to "halt their chains." However, the initial patch was released quietly, with no public announcement from Cosmos Labs’ official X account.
What went wrong with the patch
- The bug was fixed in a software update released last week, but no public warning was issued at the time.
- Cosmos Labs’ security policy follows a "silent patch model," meaning fixes are released without public disclosure to avoid tipping off attackers.
- Critics called the approach "negligent," arguing that the lack of communication left blockchains vulnerable.
- The release notes for the patch did state that it contained "important security fixes" and urged chains to upgrade "as soon as possible."
Four blockchains hit by the bug
Before Cosmos Labs issued its public warning, two of the affected blockchains—MANTRA and Nesa—had already announced chain halts. No user funds were lost in these cases.
However, two other blockchains, TAC and KiiChain, suffered financial losses:
- KiiChain: On August 22, attackers drained nearly 150 million KII tokens, worth over $9 million at the time. The tokens were sold for just $1.6 million in BUSD, a stablecoin pegged to the U.S. dollar, causing the token’s price to crash.
- TAC: On the same day, three billion TAC tokens, valued at around $7.5 million, were drained from its staking contract. Staking is a process where users lock up tokens to support the network and earn rewards.
KiiChain blames Cosmos Labs for losses
In a post-mortem report, KiiChain called the $9 million loss "avoidable" and directly blamed Cosmos Labs’ disclosure process. The report criticized several aspects of how the patch was handled:
- No private notice was given to blockchains before the fix was publicly released.
- The update was not flagged as critical, delaying responses from affected networks.
- Communication about the patch was slow, giving attackers time to exploit the bug.
KiiChain argued that releasing a security fix publicly before privately notifying affected chains effectively handed the vulnerability to attackers.
What is confirmed
- Cosmos Labs patched a bug in its Cosmos EVM module last week.
- Four blockchains—MANTRA, TAC, KiiChain, and Nesa—were affected by the bug.
- MANTRA and Nesa halted their chains without reported losses.
- KiiChain lost nearly $9 million in tokens, and TAC lost around $7.5 million.
- KiiChain publicly blamed Cosmos Labs’ disclosure process for the exploit.
- Cosmos Labs’ security policy follows a "silent patch model," which critics say contributed to the incidents.
What is still unclear
- Whether Cosmos Labs privately notified any of the affected blockchains before releasing the patch.
- Why the patch was not flagged as critical in the release notes, despite being labeled as containing "important security fixes."
- The total number of blockchains using the Cosmos EVM module that may still be at risk.
Why this matters for blockchain security
The incident highlights the challenges of balancing security and transparency in the crypto industry. While silent patches aim to prevent attackers from learning about vulnerabilities, they can also leave blockchains unprepared if the fix is not communicated effectively.
KiiChain’s report suggests that a more coordinated approach—such as privately notifying affected networks before releasing a public fix—could have prevented the exploit. The backlash against Cosmos Labs may prompt other developers to reconsider how they handle security disclosures.