Cosmos EVM Bug Behind $5.7M Six-Chain Hack Was Cleared Too Early

NewsSun, 30 Aug 2026 08:01:10 UTC1 hour ago
Cosmos EVM Bug Behind $5.7M Six-Chain Hack Was Cleared Too Early

Cosmos Labs says a critical Cosmos EVM vulnerability reported through its bug bounty programme in April was incorrectly judged not to affect production networks. Attackers exploited the vulnerability across six chains between August 20 and August 25, 2026.

The activity moved about $2.87 million through decentralised exchanges and another $2.85 million through centralised exchanges, according to the Cosmos Security post-mortem.

The incident exposed a months-long gap between the initial report and releases reaching affected branches shortly before the first known attack. Cosmos Labs said it used its silent patch process because early testing found production chains were safe; the releases did not include a vulnerability-specific advisory.

April report was cleared after production testing

Cosmos Labs’ bug bounty programme received the flaw on April 25. The company said its testers initially concluded that production networks were not vulnerable; the exploit’s use in August later disproved that assessment.

… Continue reading the full article at the original source below.

Read from Source · cryptodaily.co.uk ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptodaily.co.uk).

Related