Bearish
Critical vulnerability in Cosmos EVM exploited, draining nearly $6 million.
A critical balance-handling flaw in the Cosmos EVM module was exploited between August 20 and August 25, 2026, leading to the theft of approximately $5.72 million across six blockchains. Despite being reported in April, the vulnerability was not addressed until August 19, allowing attackers to drain funds from decentralized and centralized exchanges.
Key points
- Cosmos Labs acknowledged the exploitation of a critical vulnerability in the Cosmos EVM module, resulting in the theft of nearly $6 million across six blockchains.
- The vulnerability, identified as GHSA-7g4w-cg88-2cq2, was reported in April but remained unaddressed until August 19, leading to significant financial losses.
- Cosmos Labs released patches for the vulnerability on August 19, urging operators to upgrade to versions 0.6.2 or 0.7.2 to mitigate the issue.
- The incident highlights the importance of timely vulnerability management and coordinated network upgrades within the Cosmos ecosystem.
Sources
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was VulnerableThe Hacker News · August 28, 2026
- Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chainsWEEX Crypto News · August 28, 2026
- Cosmos EVM Flaw Exploited After Silent Patch DelayXploitwire · August 28, 2026
AI-generated from public news sources. Not financial advice.