Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
thehackernews.com Aug 29, 2026

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

AI-summarised brief · reviewed before publication

Cosmos Labs confirmed that a critical balance-handling vulnerability in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The flaw, designated GHSA-7g4w-cg88-2cq2, affects versions prior to 0.6.2 and 0.7.2. Although reported via bug bounty on April 25, Cosmos Labs initially assessed it as low risk, incorrectly believing it only impacted non-18-decimal networks. By August 13, the team acknowledged all chains were vulnerable. Despite this, the fix was released publicly via a silent patch process rather than through secure, private channels reserved for immediate fund risks. The technical error involves unchecked subtraction when vesting accounts delegate funds, causing balance underflows that allow attackers to mint or burn tokens. Affected chains must perform state-breaking coordinated upgrades or halt operations immediately to prevent further exploitation.

💡 Why It Matters

  • · The incident exposes a dangerous disconnect between Cosmos Labs’ internal risk assessment and its own emergency response protocols.
  • · By treating a confirmed, active exploit as a low-severity issue, the organization prioritized procedural consistency over user asset protection, undermining trust in its security governance.