← Blog · · df00tech

Cosmos Labs Discloses Critical Cosmos EVM Vulnerability Exploited Across Six Chains

security-news breach

What Happened

Cosmos Labs disclosed a critical balance-handling flaw in the shared Cosmos EVM module, tracked as GHSA-7g4w-cg88-2cq2, after it was exploited to drain funds from six blockchains between August 20 and August 25, 2026. According to the report, the advisory was rated Critical by Cosmos Labs but was published without an assigned CVE identifier, a weakness classification (CWE), or a CVSS score. Affected versions are reported as prior to 0.6.2, though the full version range in the source is incomplete. Notably, the report indicates Cosmos Labs was aware the vulnerability affected every chain running the module before the exploitation occurred.

Why It Matters

The Cosmos EVM module is shared infrastructure used across multiple independent blockchains, so a single balance-handling defect in it can be leveraged repeatedly against any deployment running a vulnerable version — as demonstrated by the six affected chains. This is a systemic supply-chain-style risk pattern for blockchain ecosystems: a flaw in shared, forked, or vendored code can silently propagate critical exposure to every downstream project, and defenders in this space (exchanges, custodians, chain operators, and dApp teams building on Cosmos EVM) may not be aware they inherited the risk. The lack of a CVE, CWE, or CVSS score also makes this harder to track through standard vulnerability management tooling and feeds.

What Defenders Should Watch For

  • Chain operators and validators running Cosmos EVM should confirm their deployed module version against the advisory and prioritize patching to 0.6.2 or later once confirmed.
  • Treasury, bridge, and custody teams should review on-chain balance and withdrawal activity for the affected window (August 20–25, 2026) for anomalous large or rapid balance changes inconsistent with normal transaction patterns.
  • Monitor for irregular EVM-level balance manipulation transactions (e.g., unexpected mint/burn or transfer patterns that bypass normal accounting checks) rather than relying solely on standard transfer-event monitoring.
  • Track GHSA-7g4w-cg88-2cq2 directly, since the absence of a CVE means it will not surface in typical CVE-driven vulnerability scanning or feeds.
  • Any project that forked or vendored the Cosmos EVM module should independently verify exposure, since shared-module vulnerabilities often propagate beyond the officially tracked deployments.

Developing Story

Details on the root cause, full affected version range, and total funds impacted are still emerging, and Cosmos Labs' disclosure notably states it knew of the exposure across all chains running the module prior to exploitation. This is net-new intelligence without an associated CVE; for the latest details, see the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.