In an attack that affected six chains and amounted to US$5.7 million, the most eye-catching detail was not the amount stolen, but the sentence "there was only 20 hours between the patch and the attack."
Cosmos Labs said that the company had previously misjudged the vulnerability behind the attack, which was equivalent to admitting that it had mistakenly considered the vulnerability to be cleared and safe to release. The attack across six chains caused a total loss of $5.7 million.
MANTRA Chain, which lost $3.6 million in the incident, questioned the patching process. The chain pointed out that the patch released by Cosmos Labs was only 20 hours after the attack occurred, and the patch content did not specify which vulnerability was repaired.
In other words, MANTRA Chain watched the attack occur less than a day after the patch was put online without knowing what was being patched or the content of the original vulnerability.
The current public information does not mention the technical details of the vulnerability, the exact time when the attack occurred, nor the losses of the remaining five affected chains.