Cosmos EVM Vulnerability Misjudgment Leads to $5.72 Million Exploit Across Six Chains
Cosmos Labs admitted to misjudging a balance-handling vulnerability in the shared Cosmos EVM module, which was reported on April 25 but incorrectly deemed low-risk. The team performed a silent patch in May, but independent researchers confirmed in early August that all Cosmos EVM chains were at risk. A vague security update released on August 19 triggered attacks within 20 hours, resulting in the theft of approximately $5.72 million across six chains between August 20 and 25. The incident highlights the systemic risks of shared underlying modules and the da
Not investment advice.