Back to News
深度分析By Mr.Xuan · 2026-08-27

Cosmos Ecosystem Security Disaster: 4 Chains Attacked, Tokens Crash 90%+ — Amateur Vulnerability Management

Cosmos Ecosystem Security Disaster: 4 Chains Attacked, Tokens Crash 90%+ — Amateur Vulnerability Management

Four chains, hacked simultaneously.

MANTRA, TAC, KiiChain, Nesa — four different projects, four different chains, all hit by the same type of attack on the same day. Token prices crashed over 90%, with Nesa dropping 94%.

Billions of dollars in market value evaporated.

What's even more absurd: the vulnerability wasn't "newly discovered." Cosmos Labs had already issued a patch. But after releasing it, they didn't notify downstream projects.

The managers of four chains didn't know their underlying infrastructure had a vulnerability — until attackers made them "aware."

This isn't a technical incident. This is an accountability failure.

"Amateur Hour" Vulnerability Management

Let's first understand the Cosmos ecosystem structure.

Cosmos is an "ecosystem of chains" — it provides the underlying framework (Cosmos SDK) that lets other projects build their own chains. MANTRA, TAC, KiiChain, and Nesa were all built using the Cosmos SDK.

What's this like? Imagine four houses built on the same foundation. The foundation company discovered cracks and issued a "repair guide" — but didn't tell the residents of those four houses.

The residents didn't know the foundation had cracks and kept living there. Until one day, someone exploited those cracks and demolished all four houses simultaneously.

What did Cosmos Labs do? They issued a patch. But "issuing a patch" and "ensuring all downstream projects receive and apply the patch" are two completely different things.

In the software industry, this is called "responsible vulnerability disclosure" — you don't just find the problem, you ensure all affected parties know about it and fix it. Cosmos Labs only did step one. They completely skipped step two.

The crypto community's verdict was blunt: "amateur hour."

"Someone Manages It" vs "No One Needs To"

The Cosmos incident exposes a fundamental contradiction: in a "managed" system, security depends on the manager's competence.

Cosmos Labs had the ability to discover the vulnerability — proving their technical team isn't bad. But they lacked the ability to ensure all downstream projects fixed it — proving their management system has serious flaws.

This is the essential problem with "someone managing it": humans can do one thing right and another thing wrong. You can't guarantee they'll always get it right.

FunDAO's design philosophy is completely different: from the start, it doesn't need "someone managing it."

FunDAO's contract is deployed on BSC using verified standards. After deployment, admin permissions are permanently discarded — no one can modify rules, pause the contract, or upgrade code.

What does this mean?

1. No "patches" to apply. Code was locked at deployment; there's no "fix after discovering vulnerability" scenario. Because no one can change the code.

2. No "notifications" needed. No downstream projects, no dependencies, no "ecosystem" — just a standalone contract with rules on-chain, verifiable by everyone.

3. No "management" to trust. No need to trust Cosmos Labs to notify you, no need to trust MANTRA's team to fix vulnerabilities, no need to trust anyone. Code is the rule.

Infrastructure's "Single Point of Failure"

The Cosmos incident isn't the first "infrastructure single point of failure."

In 2022, the Wormhole cross-chain bridge was hacked for $320 million — due to a signature verification vulnerability in the smart contract. All projects based on Wormhole were affected simultaneously.

In 2023, Pyth Network oracle malfunctioned — price data went wrong, and all DeFi protocols relying on Pyth were liquidated simultaneously.

In 2026, the Cosmos EVM vulnerability — patch issued but not communicated, four chains attacked simultaneously.

Every time it's the same story: one underlying component fails, and the entire ecosystem suffers.

Why? Because "infrastructure" means "many people depend on you." When you have a problem, it's not just your problem — it's everyone who depends on you.

FunDAO doesn't depend on any infrastructure. It runs on BSC, but BSC is just the "execution environment" — FunDAO doesn't rely on any BSC "services." After deployment, the contract is independent, needing no oracles, no cross-chain bridges, no third-party components.

No dependencies, no single point of failure.

Who's Responsible for Billions in Losses?

Cosmos Labs issued a patch but didn't notify downstream. The four chain managers didn't proactively check for underlying updates. Attackers exploited the information gap.

Who's responsible?

Legally, probably no one. The DeFi world has no "fiduciary duty," no "disclosure obligations," no "investor protection."

Morally, Cosmos Labs should at least ensure all downstream projects received patch notifications. You discovered a vulnerability — you have a responsibility to tell everyone, not just "post an announcement and call it done."

From a design perspective, the problem is that "managed" systems inherently have information asymmetry. What managers know, users don't necessarily know. This asymmetry isn't a problem during "normal times," but it's a disaster during "emergencies."

FunDAO's design eliminates this asymmetry — because there's no distinction between "managers" and "users." Everyone sees the same code, the same on-chain data. No "insider information," no "patch notifications," no "what you need to know."

Conclusion

Four chains hacked simultaneously, billions evaporated — not because "hackers are too strong," but because "management is too sloppy."

Cosmos Labs found the vulnerability but didn't ensure all affected parties knew. The four chain managers didn't proactively check for underlying updates. Attackers simply exploited this information gap.

This is the cost of "someone managing it" — managers can do 99 things right, but when they get the 100th thing wrong, all losses are borne by users.

FunDAO chose a different path: from the start, no "managers" needed. No patches to apply, no notifications to send, no information gaps to exploit.

Code is the rule. Once rules are deployed, no one needs to "manage" them anymore.

Disclaimer: This article is for informational and educational purposes only and does not constitute investment advice. Cryptocurrency investment carries high risk. Please do your own research and make cautious decisions.