Cosmos Labs said attackers stole funds across six blockchain networks between Aug. 20 and Aug. 25 using a flaw in Cosmos EVM, the shared software that lets Cosmos chains run Ethereum-style applications, according to a technical post-mortem published Friday.

Attackers exchanged the stolen tokens for about $2.87 million in other assets on decentralized exchanges and $2.85 million on centralized exchanges, per the report, which also states the attacker's centralized exchange accounts "have been frozen pending investigation by the relevant authorities."

Cosmos Labs notably disclosed that a researcher had identified the flaw and submitted a report through the Cosmos bug bounty program on April 25, according to the post-mortem. Cosmos Labs said its testers could not reproduce the attack against the configuration used by live Cosmos chains, including all known production Cosmos EVM networks, and therefore concluded that funds on those networks were not at risk.

"Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds," the report states.