Cosmos Labs said it wrongly cleared a Cosmos EVM bug before attackers stole $5.7 million across six blockchain networks. A researcher reported the flaw through the Cosmos bug bounty program on April 25, but testers could not reproduce it against configurations used by live chains. Cosmos Labs released a patch at 7:01 p.m. ET on Aug. 19, and the first attack began at 3:06 p.m. ET on Aug. 20.