news.mlab.sh
Back to the feed
vulnerability

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

High
Summary

A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026. The vulnerability, initially missed due to a misunderstanding of how the system handled vesting accounts, allowed attackers to steal approximately $5.72 million in assets. Despite Cosmos Labs’ awareness of the issue and subsequent release of patches, the vulnerability was not proactively distributed privately to affected networks, leading to a prolonged exploitation period. The incident highlighted a gap in Cosmos Labs’ security practices, particularly regarding the lack of proactive private patch distribution and a limited registry of Cosmos EVM deployments.

A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, stemmed from a misunderstanding of how the system handled vesting accounts, specifically the interaction between Ethereum Virtual Machine (EVM) state and the Cosmos SDK x/bank module. The flaw allowed attackers to move a finite amount out of a wrapped account, or send a victim account 2^256 minus its balance, effectively burning the victim’s real holdings.

Initially, Cosmos Labs incorrectly assessed the vulnerability as only affecting non-18-decimal networks, failing to recognize that all Cosmos EVM chains were affected. The fix, v0.6.2 and v0.7.2, was released on August 19, but the patch was not proactively distributed privately to affected networks. The team only concluded that it was safe to proceed with a silent patch process, despite knowing that all chains were vulnerable.

Attackers exploited the vulnerability, starting on August 20, and sold approximately $5.72 million in affected assets on decentralized exchanges and $2.85 million on centralized exchanges based on August 19 prices. Cosmos Labs confirmed that six chains were impacted. The incident exposed a significant gap in Cosmos Labs’ security practices, including a lack of a complete registry of Cosmos EVM deployments and a failure to proactively distribute private patches to affected networks.

Several upstream changes were merged into the repository, including the SubBalance underflow guard (merged May 15) and the module-account guard (merged May 20), but these were not explicitly documented or communicated to downstream developers. A public pull request in Push Chain’s fork of Cosmos EVM described the vulnerability and its exploitation path in detail on August 20, eight hours and fifteen minutes after the releases went out. The first attack against MANTRA began eleven hours and fifty minutes later. Cosmos Labs sent its first private notification by secure email at 03:36 UTC on August 21, roughly two hours after MANTRA reported being exploited.

Despite the incident, Cosmos Labs has released patches for 37 vulnerabilities silently in the last 13 months without downstream developers precisely describing exploit paths in public. The Hacker News has reached out to Cosmos Labs for comment on why the patch was not distributed privately after the team confirmed that all chains were affected, and will update this story with any response.

Read the full article at The Hacker News