Paid says its value receipts pair evidence of completed agent work with a proposed price. (Image: Shutterstock)

Cosmos EVM Bug Hits Six Blockchains With $5.7M In Losses

Cosmos EVM flaw exploitation drained $5.7 million from six connected blockchains between Aug. 20 and Aug. 25, Cosmos Labs said Saturday, reversing an earlier claim that the bug had already been patched.

Key Takeaways

  • The Cosmos EVM flaw drained $5.7 million from six connected blockchains between Aug. 20 and Aug. 25
  • Cosmos Labs reversed an earlier claim that the vulnerability had already been patched before thefts continued
  • The Wormhole and Ronin bridge hacks together cost more than $775 million by exploiting cross-chain trust assumptions
  • Cosmos Labs has not said whether affected users will be reimbursed or published an audit timeline

Cosmos EVM Flaw Explained, Why One Bug Hit Six Chains

Cosmos Labs said the vulnerability allowed a second, previously unknown attack path days after engineers believed they had closed it. The Block reported that the company had told partner chains the issue was resolved, only to discover the deeper Cosmos EVM flaw as thefts continued through Aug. 25.

Cosmos Labs has not named all six affected networks or said how much of the $5.7 million has been recovered.

How A Shared Software Layer Turned Into A Shared Risk

Cosmos EVM lets blockchains built on the Cosmos SDK run smart contracts, small programs that execute automatically once preset conditions are met, using Ethereum (ETH)-style code. That shared layer sped up development across the wider Cosmos network, since teams did not need to rebuild compatibility tools from scratch.

It also meant the flaw could touch every chain that adopted the shared module, rather than staying contained to one network. Ethereum (ETH), whose smart-contract standard the module mimics, was not itself compromised.

Also Read: Tokenized Stocks Soar as Coinbase and Chainlink Strike Breakthrough Deal

A Pattern The Ecosystem Has Seen Before

Cross-chain infrastructure has produced some of the industry’s largest losses, including the Wormhole and Ronin bridge hacks, which together cost more than $775 million after attackers exploited trust assumptions between separate networks.

Cosmos (ATOM), the ecosystem’s native token, remains one of the more established proof-of-stake assets by market capitalization, with dozens of app-specific chains still relying on the shared module tied to this exploit.

Proof-of-stake is the consensus system that secures those chains by requiring validators to lock up tokens before processing transactions.

What Cosmos Labs Still Owes Users

Cosmos Labs has not published an audit timeline for the Cosmos EVM flaw, nor said whether affected users will be reimbursed. Independent auditors have not publicly confirmed the underlying code is now fully patched, leaving six chains exposed to further scrutiny.

Read Next: Judge Voids Pentagon Blacklist of Anthropic as Illegal Retaliation

Similar Posts