Why a Patched Blockchain Vulnerability Can Still Matter to Token Holders

The Cosmos EVM incident shows why closing an exploit route is not the same as restoring holders’ prior economic position. Attackers exchanged about $2.87 million of stolen assets on decentralised exchanges and sold an estimated $2.85 million through centralised exchanges, according to the Cosmos Security post-mortem.
By the time the affected software was patched, those transactions could not be reversed and the token’s prior liquidity conditions could not be restored. A patch may therefore succeed technically while holders still face sell-side flow, pooled-staking losses, exposure beyond realised theft, or the burden of moving to a replacement environment. That distinction does not establish that every exploit causes a measurable price move or that this patch failed.
Cosmos EVM’s flaw released vested tokens rather than minting new ones
The Cosmos EVM vulnerability affected production chains running versions below v0.6.2 or v0.7.2. It arose from inconsistent token-balance accounting between Cosmos EVM and the Cosmos SDK, allowing attackers to extract legitimate tokens from vesting accounts without increasing total token supply.
… Continue reading the full article at the original source below.

