Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A crucial balance-handling vulnerability in the shared Cosmos EVM module was used to drain money from six blockchains between August 20 and August 25, 2026, according to a warning from Cosmos Labs.

The vulnerability, identified as GHSA-7g4w-cg88-2cq2, was released without a CVSS score, a weakness categorization, or a CVE name. Cosmos Labs has classified it Critical.

Versions < 0.6.2 and >= 0.7.0 < 0.7.2 are impacted; the patch was released in v0.6.2 and v0.7.2 on August 19. Chain operators are instructed to update to one of those releases or later; this is a state-breaking modification that necessitates a coordinated network upgrade.

Instead of attempting a coordinated governance upgrade, operators who are unable to upgrade right away are instructed to stop the chain.

According to a post-mortem released on August 28, Cosmos Labs stated that the weakness was discovered on April 25 through its bug bounty program and was initially deemed to pose no danger to funds on active networks read more about Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *