Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Summary
Cosmos Labs has disclosed a critical vulnerability in the shared Cosmos EVM module that was exploited between August 20 and August 25, 2026, leading to the draining of funds from six blockchains. The flaw, identified as GHSA-7g4w-cg88-2cq2, has been rated Critical by Cosmos Labs, though it was released without a CVE or CVSS score.
IFF Assessment
The exploitation of a critical vulnerability leading to fund drainage is bad news for defenders.
Severity
The vulnerability allows for the exploitation of a balance-handling flaw in the shared Cosmos EVM module, which was actively exploited to drain funds. This indicates a high attack vector and significant impact, justifying a high CVSS score.
Defender Context
Defenders should be aware of critical vulnerabilities in cross-chain interoperability modules like the Cosmos EVM. Exploitation of such flaws can lead to significant financial losses, highlighting the need for robust auditing and rapid patching of shared infrastructure components. Monitoring for similar balance-handling vulnerabilities in other blockchain ecosystems is also advised.