The exploit leveraged a flaw in the Ethereum-compatible framework built from the Evmos codebase. By manipulating account balances through token delegation and subtraction, attackers pushed recorded values past the 2^256-1 numerical ceiling. This caused the balance to wrap around, granting the attacker control over assets held in target accounts, including burn addresses and dormant multisignature wallets.
Cosmos Labs first received a report regarding the vulnerability on April 25 but initially concluded that production networks were safe, opting for a silent patch process in May without notifying operators. Following independent research in August, the team released a fix on Aug. 19. However, the lack of a specific security advisory left network operators with only 20 hours to coordinate complex upgrades across distributed validator sets. MANTRA, the hardest-hit network, lost 720.9 million tokens worth roughly $3.6 million, while TAC and KiiChain suffered losses of $950,000 and $1.6 million, respectively.

Comments (0)
No comments yet. Be the first!