The company has admitted it misjudged a critical vulnerability as non-exploitable and patched it quietly instead of warning the chains that use its software.
Cosmos Labs has confirmed that researchers reported a critical vulnerability in its Cosmos EVM software on , roughly four months before attackers used the same flaw to drain an estimated $5.7 million across six blockchains. The company said it initially assessed the bug as not exploitable on live networks and handled it through a silent public patch rather than a private patch distribution process.
The vulnerability was an integer underflow that allowed an attacker to delegate more tokens than an account actually held, pushing the recorded balance to a near-maximum value that could then be drained on transfer. Cosmos Labs concluded in April that the flaw was not a live risk.
Attackers began exploiting it on , roughly 20 hours after an unrelated patch release, and continued through . About $2.87 million moved out through decentralized exchanges and about $2.85 million through centralized exchanges. Six blockchains were affected. Four have been named publicly: MANTRA Chain, TAC, KiiChain, and Nesa. Cosmos Labs has said it does not maintain a complete registry of every chain in its ecosystem, which is why the remaining two have not been identified.
The four-month gap is what separates this from a routine exploit. Cosmos Labs was warned, made a documented judgment that the bug posed no live risk, and chose a quiet patch rather than a broad security advisory. That judgment proved wrong across multiple independently operated chains whose users had no way to know the exposure existed.
The larger question is whether this was an isolated triage error or a structural weakness in a shared-infrastructure model where dozens of chains depend on one team's disclosure decisions. The available evidence does not settle that question. It also remains unclear whether any of the $5.7 million has been recovered, frozen, or traced to a specific actor.
For users of Cosmos-SDK-based chains, the practical takeaway is narrower but important: the organization at the center of the ecosystem's shared infrastructure has acknowledged a case where its disclosure process failed to warn affected networks about a known critical bug for four months.
