TL;DR
- The Cosmos EVM incident shows that a fix can stop an exploit without reversing its economic effects.
- Attackers moved about $5.72 million through decentralized and centralized exchanges.
- Recent incidents at SubQuery, Zilliqa and Hyperbridge show why recovery, disclosure and independent audits remain central to protecting token holders.
A patched blockchain exploit can still matter after developers close the technical weakness. The Cosmos EVM incident shows why stopping an attack is different from restoring holders’ prior economic conditions.
According to the Cosmos Security post-mortem, attackers exchanged about $2.87 million of stolen assets on decentralized exchanges and sold an estimated $2.85 million through centralized exchanges. The flaw made legitimate vesting tokens accessible earlier than intended.
Why A Patched Blockchain Exploit Can Outlast The Patch
Vesting restrictions are part of token design. Cosmos EVM’s bug did not create new units, but it changed when restricted tokens could enter the market. Once extracted assets reached trading venues, software updates could stop another exploit without reversing transactions or restoring the previous liquidity profile.
Other incidents show similar effects. SubQuery reported five transactions draining 382,433,441 SQT tokens, worth about $134,000 at the time, from pooled staking balances, stakers and delegators, deployment boosters and its treasury. The project said the contract configuration issue was resolved. Zilliqa’s 2026 incident records 683,130,969.66 ZIL in proven theft, 6,772 exposed accounts and 51 drained accounts. Its response includes retiring the legacy environment and migrating holders to Zilliqa EVM.
These cases show why holder impact cannot be reduced to price. Losses can involve staking, treasury resources, migration and trading activity. A protocol can become technically safer while some holders remain economically worse off.

Security Response Matters Beyond Closing The Code Gap
Hyperbridge offers a useful example of rapid containment. After an attacker exploited its MMR verifier and drained the Token Gateway, the gateway was paused within hours and a permanent patch was deployed in under 72 hours. A subsequent independent audit identified 14 vulnerabilities, including one critical issue, all of which the project says were remediated. Rapid containment and independent review can therefore remain important even after the immediate exploit is stopped.
The broader crypto lesson is constructive. Open-source infrastructure lets researchers and developers inspect failures, coordinate upgrades and improve defenses across the ecosystem. Ethereum’s bug-bounty program offers rewards of up to $1 million for qualifying protocol, client and compiler bugs, creating incentives to find serious flaws before attackers do.