Cosmos Labs said attackers exploited a Cosmos EVM vulnerability between Aug. 20 and Aug. 25, draining funds from multiple Cosmos chains. The incident affected six networks, with about $2.87 million in assets bridged out and sold on decentralized exchanges, while another roughly $2.85 million was sold through centralized exchanges. The security response began after MANTRA raised the alarm, prompting the Cosmos security team to coordinate with about 40 chains to assess exposure and deploy mitigations. Cosmos Labs said 13 additional at-risk networks completed patches, halts, or other protections in time and did not record further losses. The company said the vulnerability had previously been reported through a bug bounty program on April 25. Because testers could not reproduce the issue in a production-network configuration at the time, the team concluded it did not affect real funds and fixed it without issuing a security advisory. Cosmos Labs said it will strengthen triage and remediation for critical bugs, expand security communications, and work with external experts to audit its security practices.