logo

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

ID: 1d700010-9198-5384-902a-2f9c7bb2034e

STIX ID: report--1d700010-9198-5384-902a-2f9c7bb2034e

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-08-28

Date Updated: 2026-08-29

Author: [email protected] (The Hacker News)

...
...

Cosmos Labs disclosed a critical balance-reconciliation flaw (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module that was exploited to drain funds from six blockchains between August 20–25, 2026. The flaw arises when vesting account locked balances are mishandled during EVM↔SDK reconciliation, allowing underflow/wrapleading to large mints or burns; exploitation requires permissionless vesting-account creation. Fixes were released in v0.6.2 and v0.7.2 (state-breaking upgrades), operators are advised to upgrade or halt chains, and Cosmos reported roughly USD 2.87M sold on DEXs and USD 2.85M on CEXs tied to the incident; the report also criticizes the silent-patch handling and downstream patching gaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.