Critical Cosmos EVM Vulnerability Exploited Despite Known Risk
A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains despite Cosmos Labs being aware of the vulnerability since April 2026. The flaw allowed attackers to manipulate vesting account balances through unchecked subtractions, leading to supply overflow and chain halts, with delayed patching and public disclosure issues.
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026.
The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score.
Affected versions are < 0.6.2 and >=
*** END OF TRANSMISSION ***