Cosmos Labs' Misjudged EVM Bug Drained $5.72M From Six Cosmos (ATOM) Chains
Cosmos Labs admitted it wrongly cleared an EVM bug behind a $5.72M six-chain theft. Swift's blockchain ledger launches with HSBC and Standard Chartered.
AI SummaryAI
- Cosmos Labs wrongly cleared an EVM balance-handling bug first reported on April 25.
- Attackers drained about $5.72 million across six Cosmos EVM chains between August 20 and 25.
- Cosmos Labs shipped a security patch on August 19; the first attack began roughly 20 hours later.
- Swift's blockchain shared ledger went live in July; HSBC and Standard Chartered completed cross-border transactions.
Cosmos Labs Concedes Bug Misjudgment
Cosmos Labs has conceded that it wrongly cleared a balance-handling vulnerability in the shared Cosmos EVM module as harmless — a misjudgment that preceded an exploit which drained roughly $5.72 million across six Cosmos (ATOM) blockchain networks between August 20 and August 25. The timeline stretches back to April 25, when the team received its initial report of the bug. Engineers tested the flaw and concluded it could only affect networks that use 6-decimal token denominations, while every known production Cosmos EVM chain runs 18 decimals; on that reasoning, all deployed networks were judged unaffected.
Acting on that conclusion, Cosmos Labs merged a correction in May through a silent patch — a release process that ships fixed code without telling chain operators what was actually changed. The assumption held until early August, when independent researchers confirmed the flaw in fact affected every Cosmos EVM chain, the shared execution layer that also underpins Cosmos-SDK-based EVM networks such as Berachain. The decisive failure, though, was timing. Cosmos Labs released its patch on August 19 at 7:01 p.m. ET, with release notes that described the change only as an important security fix and offered no technical detail. The first attack wave began the following day at 3:06 p.m. — roughly 20 hours after the fix shipped. That gap is the silent-patch dilemma at its sharpest: withholding details is meant to deny attackers a roadmap while operators upgrade, but when a patch can be reverse-engineered faster than chains can push updates, the interval between disclosure and defense becomes the attacker's window. Because the vulnerable code was a shared module rather than chain-specific logic, a single flaw propagated simultaneously across six networks. The incident also shows the limits of post-hoc recovery on transparent chains: stolen funds move along traceable paths in real time — visibility that simply does not exist on privacy assets such as Monero, where flows are obscured by default.
Swift's Ledger Bets on Interoperability
Swift, the 53-year-old messaging network that relays payment instructions worth about $5 trillion every day, has responded to the blockchain challenge not by defending its old rails but by absorbing them. Its blockchain shared ledger went live in July, and HSBC and Standard Chartered have each completed real cross-border transactions over it, establishing tokenized payment infrastructure that runs around the clock. The scale Swift defends is vast: it processes more than 53 million financial messages a day for 11,500 financial institutions across more than 200 countries and territories, and 75% of payment instructions reach the destination bank within 10 minutes. McKinsey estimates cited in the program put the global payments market at roughly $2 quadrillion a year, with Swift handling on the order of $1.2-1.5 quadrillion annually.
One detail matters more than any headline figure: Swift never holds or transfers funds itself. It sends standardized instructions that let banks debit and credit accounts, while actual settlement crawls through correspondent-banking chains that can take one to five business days. That is precisely the layer blockchain rails attack. Stablecoins move wallet-to-wallet around the clock — a consumer-payments model long dominated by networks like PayPal — including designs such as the yield-bearing stablecoin, while tokenized deposits let banks settle account-to-account on-chain, bypassing correspondents altogether. Yellow Card CEO Chris Maurice argues that once these rails are laid, traditional Swift solutions stop being needed — and that a middle layer will struggle unless it changes a business model built on charging for money movement. Standard Chartered's digital payments head Naveen Mallela counters that most cross-border value still flows account-to-account, not wallet-to-wallet. Swift's digital asset strategy head Jack Pouderoyen frames the real problem as fragmentation — proprietary bank ledgers, issuers spread across multiple chains — and argues a shared interoperability layer, reachable through banks' existing Swift connections, is the answer. Citi, which moves $6 trillion daily, and UBS, one of 17 pilot banks, both expect a hybrid ecosystem rather than a single winner. Readers tracking the market in real time can follow live spot and futures prices on MEXC.
Middle Layers Under Pressure
Both stories are, at bottom, about what a middle layer is worth. Cosmos Labs' release notes for the August 19 patch disclosed only that the change was security-critical — the opacity that let one shared-module flaw hit six chains at once. Swift's answer is the opposite bet: publish the ledger, keep 11,500 banks connected, and become the interoperability layer rather than a toll booth on money movement. Our read: infrastructure that sits between users and settlement now has to prove either radical transparency or irreplaceable reach — ideally both — to survive the repricing now underway.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


