CYBERSECURITYTRACKER
TRACKING4,887 stories929 vuln stories
Permanent story citation

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 5345

As cited

Citation snapshot as of .

vulnerabilities

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A critical vulnerability in Cosmos Labs' shared EVM module allowed attackers to drain funds from six blockchains between August 20 and August 25, 2026. The flaw, tracked as GHSA-7g4w-cg88-2cq2, affects versions before 0.6.2 and was exploited despite Cosmos Labs having knowledge of the exposure. The advisory lacked a CVE identifier, weakness classification, and CVSS score.

Why it matters: Operators of Cosmos-based blockchains and users of affected chains face direct financial loss and must verify whether their deployments were targeted and update to patched versions immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs disclosed a critical balance-handling vulnerability (GHSA-7g4w-cg88-2cq2) in its shared EVM module that was exploited between August 20 and August 25, 2026 to drain funds from six blockchains. The advisory lacked a CVE identifier, weakness classification, or CVSS score. Affected versions are below 0.6.2.

Why it matters: Operators of any blockchain running the affected Cosmos EVM module versions must upgrade immediately to 0.6.2 or later to prevent fund drainage and further exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution