Cosmos Labs botched the fix before a hack
Cosmos Labs said it wrongly cleared a bug that let hackers drain $5.7M across six chains, MANTRA got hit for $3.6M.

Cosmos Labs says it wrongly declared a critical bug fixed, and that mistake let attackers drain $5.7 million across six Cosmos chains. MANTRA Chain took the biggest hit at $3.6 million, and its team says the patch went live only 20 hours before the exploit began.
The patch and the timeline
Cosmos Labs shipped a fix, called it resolved, and moved on. MANTRA disputes that the disclosure gave chains enough time or enough detail to actually defend themselves.
The core complaint isn't that a bug existed. It's that the people responsible for closing it said it was closed when it wasn't.
What the numbers show
- Attackers pulled $5.7 million across six separate Cosmos-based chains, per The Block.
- MANTRA Chain alone lost $3.6 million, roughly 63% of the total haul.
- MANTRA says the patch was released just 20 hours before the attack started.
- Cosmos Labs has now admitted it incorrectly marked the vulnerability as resolved.
- The exploit hit six chains at once, pointing to a shared dependency rather than six isolated bugs.
The read
The obvious story here is "another bridge-adjacent Cosmos hack, six chains, add it to the pile." That framing misses the actual failure, which sits upstream of any single chain's code.
Cosmos runs on shared infrastructure. When one team clears a bug across that stack, every downstream chain inherits the assumption that it's safe. Cosmos Labs cleared this one wrongly, and six chains built on that false all-clear.
A 20-hour gap between patch and exploit is the tell. That's not enough time for chains to audit, test, and confirm a fix on their own. It's enough time for someone watching the patch closely, maybe reading the diff, to find what didn't actually get fixed and hit it first.
This is a governance failure dressed as a technical one. The bug mattered less than who signed off on it being gone. MANTRA didn't lose $3.6 million to a zero-day; it lost that money to a green light that shouldn't have been given.
Shared security models only work if the entity doing the clearing is right. When Cosmos Labs is wrong, the blast radius isn't one chain, it's every chain that trusted the sign-off.
What to watch
- Whether Cosmos Labs publishes the technical root-cause report and names the specific flaw the "fix" missed.
- Whether other Cosmos-chain teams disclose losses beyond the $5.7 million already reported, or confirm zero exposure.
- Whether Cosmos Labs changes its disclosure process, longer testing windows, independent verification, before declaring future bugs resolved.
