🔴 Critical: Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
-
Cosmos Labs has disclosed that a critical balance-handling flaw in the shared Cosmos EVM module was actively exploited to drain funds from six different blockchains between August 20 and August 25, 2026. The issue, tracked as GHSA-7g4w-cg88-2cq2, has been rated Critical by the team, though the advisory was published without a CVE identifier, a weakness classification, or a CVSS score.
The vulnerability impacts versions < 0.6.2 and >= 0.6.2 (with the patch applied in a later release). According to the advisory, the flaw resides in how the module handles balance adjustments, allowing an attacker to manipulate accounting logic under specific conditions.
- Affected versions: All releases prior to the patched 0.6.2 update.
- Exploitation window: August 20–25, 2026, across six unnamed chains.
- Impact: Unauthorized draining of funds due to incorrect balance state transitions.
Cosmos Labs has urged all operators running the EVM module to upgrade immediately, as the issue is known to be exploitable in the wild. No further technical specifics or indicators of compromise were shared in the public notice.
Source: The Hacker News
Is your team already running the patched 0.6.2 build, or are you still assessing exposure across your chain's validators?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login