Cosmos Labs acknowledges it missed a critical bug that enabled a $5.7M cross-chain exploit affecting six networks.
Security & Exploits ·
Cosmos Labs acknowledged a critical oversight in its security review process that allowed a vulnerability to go undetected. The bug, which the organization had incorrectly deemed safe during an earlier audit, became the vector for a cross-chain exploit resulting in $5.7 million in losses across six networks.
The vulnerability enabled attackers to move value across multiple blockchain environments before detection. Cosmos Labs' failure to catch the flaw during its own review represents a lapse in the initial evaluation phase rather than a discovery by external security researchers, suggesting the issue lay dormant through at least one layer of internal scrutiny.
It remains unclear whether Cosmos Labs has implemented process changes to prevent similar oversights, what specific technical weakness the bug exploited, or details on which six networks were affected and how the impact was distributed across them.