Cosmos EVM Bug Leads to $5.72M Six-Chain Hack
Cosmos Labs said it misjudged a balance-processing vulnerability in the shared Cosmos EVM module, initially believing it affected only chains using six decimal places. The vulnerability was reported through a bug bounty programme on 25 April, but a silent patch merged in May was not accompanied by a public advisory or detailed notice to chain operators. Independent researchers later found that all Cosmos EVM chains could be affected. Cosmos Labs issued a security patch at 19:01 Eastern Time on 19 August, leaving operators about 20 hours to respond before the first attack began at 15:06 on 20 August. Attackers exploited six Cosmos ecosystem networks between 20 and 25 August, causing about $5.72 million in losses. Around $2.87 million was bridged and sold on decentralised exchanges, while $2.85 million was sold through centralised exchanges. The related exchange accounts have been frozen. Following MANTRA’s disclosure, the Cosmos security team assessed roughly 40 networks. Thirteen potentially affected networks patched, halted or added safeguards without reporting losses. For traders, the Cosmos EVM incident increases near-term risks for affected-chain liquidity, bridge exposure, token volatility and further DeFi exploit disclosures. It also highlights the systemic risk of shared blockchain infrastructure and delayed security communication.
Bearish
The direct price impact is bearish for Cosmos-related assets, particularly ATOM and tokens linked to affected networks. The exploit created forced selling pressure, with millions of dollars in assets sold through decentralised and centralised exchanges. Traders may also reduce exposure to Cosmos ecosystem projects until operators confirm that patches are complete and no further losses have occurred. In the short term, affected-chain liquidity could weaken, spreads could widen and volatility could increase as the market assesses bridge and DeFi risks. The freezing of exchange accounts and the patching or shutdown of 13 potentially affected networks may limit additional selling and contain the damage. However, the initial misjudgment, limited security disclosure and shared-module design create continuing confidence risks. In the longer term, stronger audits, external reviews and improved incident communication could support recovery, but historical crypto exploits often leave a lasting risk premium. Overall, the immediate trading signal remains bearish rather than bullish or neutral.