Cosmos Labs says a balance-underflow bug reported in April was wrongly cleared before attackers exploited six EVM networks in August.