Cosmos Labs said a critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The issue affected multiple Cosmos EVM versions, was patched in v0.6.2 and v0.7.2, and required coordinated network upgrades or chain halts to mitigate. #CosmosLabs #CosmosEVM #GHSA-7g4w-cg88-2cq2 #MANTRA #ZetaChain #WardenProtocol #PushChain
Keypoints
- A critical underflow flaw in Cosmos EVM let attackers drain funds from vesting accounts.
- The vulnerability affected versions below 0.6.2 and 0.7.0 through 0.7.1.
- Cosmos Labs said the bug was misjudged at first and patched publicly instead of privately.
- Operators were told to upgrade to v0.6.2 or v0.7.2, or halt chains if immediate upgrade was impossible.
- The exploit was used against six chains, with millions of dollars in assets sold afterward.
Read More: https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html