Interestana
Home/News/Cosmos EVM Flaw Exploited After Cosmos Labs Knew of Vulnerability
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Cosmos EVM Flaw Exploited After Cosmos Labs Knew of Vulnerability

Cosmos EVM Flaw Exploited After Cosmos Labs Knew of Vulnerability

Cosmos Labs disclosed on August 25, 2026, that a critical balance-handling flaw within the shared Cosmos EVM module was actively exploited, leading to the draining of funds from six distinct blockchains. The exploitation window occurred between August 20 and August 25, 2026. The vulnerability, identified by the identifier GHSA-7g4w-cg88-2cq2, was classified as Critical by Cosmos Labs. Notably, the disclosure was made without an assigned CVE identifier, a formal weakness classification, or a CVSS score, which are standard metrics for assessing the severity of security vulnerabilities. The affected versions of the Cosmos EVM module are those less than 0.6.2 and versions greater than or equal to 0.6.2, indicating a broad range of potential exposure. Cosmos Labs stated that they became aware of the vulnerability and its exploitation on August 20, 2026, but chose to disclose it publicly on August 25, 2026, after the exploitation period had concluded. This decision to delay public disclosure, despite knowing about the active exploitation, has raised concerns within the blockchain community regarding the timing and transparency of security advisories. The Cosmos EVM module is a crucial component that enables Ethereum Virtual Machine (EVM) compatibility within the Cosmos ecosystem, allowing developers to deploy smart contracts and applications written for Ethereum onto Cosmos-based blockchains. Its widespread use means that a vulnerability within this module can have significant implications for the security of numerous projects and their users. The specific mechanism of the exploit involved manipulating balance handling, which is a fundamental operation for any blockchain handling digital assets. The fact that six different blockchains were affected underscores the shared nature of the module and the potential for a single point of failure to impact multiple independent networks. The absence of a CVE and CVSS score means that external security researchers and automated systems have less readily available information to assess the precise risk and prioritize mitigation efforts. Cosmos Labs has indicated that they are working with the affected projects to help them recover from the exploits and to implement necessary security patches. The incident highlights the ongoing challenges in securing decentralized systems, where the interconnectedness of various components and the speed of exploitation can outpace traditional security response mechanisms. Further details regarding the exact methods used by attackers and the total amount of funds lost are expected to be released as investigations continue.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next