Cosmos Labs failed to properly identify a critical vulnerability that led to a $5.7M six-chain exploit, with MANTRA Chain losing $3.6M just 20 hours after an ineffective patch.
Security & Exploits ·
Cosmos Labs acknowledged that it failed to properly identify a critical vulnerability that was exploited across multiple chains, resulting in a $5.7 million loss. MANTRA Chain sustained $3.6 million of that total, and the chain reported that a patch addressing the flaw was deployed only 20 hours before the attack occurred, without disclosure of the underlying vulnerability.
The timeline and communication gap raise questions about the adequacy of the patching process. MANTRA Chain's claim that the patch arrived with insufficient context about what it fixed suggests a breakdown in how the fix was communicated to affected parties, potentially limiting their ability to assess risk exposure or implement additional protections in parallel.
What remains unclear is whether other affected chains had different patch timelines or warning periods, the full scope of the vulnerability's technical nature, and whether Cosmos Labs has issued a formal postmortem or identified systemic failures in its vulnerability disclosure practices.