Cosmos Labs Admits Error in EVM Module Vulnerability Assessment
Cosmos Labs has admitted to underestimating the severity of a vulnerability in its EVM module, leading to attacks on six blockchains that resulted in total damages of $5.7 million.
The attacks occurred between August 20th and August 25th, with attackers exploiting the vulnerability to extract funds from multiple Cosmos-based blockchains.
The issue was reported through a bug bounty program on April 25, 2026, but the team concluded that production-configured networks were not at risk and released a public fix without warning operators.
However, in early August, independent researchers demonstrated that the vulnerability affected all networks on Cosmos EVM, prompting developers to mask the patch and include it in releases v0.6.2 and v0.7.2.