Patched but Not Whole: The Limitations of Blockchain Vulnerability Patching
The recent Cosmos EVM incident highlights the importance of patching blockchain vulnerabilities. However, it also shows that closing an exploit route does not necessarily restore token holders' prior economic position.
Attackers exploited a vulnerability in the Cosmos EVM, which allowed them to extract legitimate tokens from vesting accounts without increasing total token supply. The attackers exchanged approximately $2.87 million of stolen assets on decentralized exchanges and sold around $2.85 million through centralized exchanges.
The affected software was patched, but by that time, the transactions could not be reversed, and the token's prior liquidity conditions could not be restored. This means that holders still face sell-side flow, pooled-staking losses, exposure beyond realized theft, or the burden of moving to a replacement environment.
SubQuery Network reported that five transactions drained 382,433,441 SQT tokens worth approximately $134,000 from pooled staking balances and individual wallets. The project restored contract addresses and added onlyOwner controls to address the access-control weakness.