Cosmos EVM Module Exploited Across Six Blockchains
A critical flaw in the Cosmos EVM module led to fund drains across six blockchains. The vulnerability was known prior to exploitation but lacked proper disclosure.
TL;DR
- Attackers exploited a critical Cosmos EVM balance-handling flaw between Aug 20–25, 2026.
- Six blockchains were drained before a fix could be deployed.
- Cosmos Labs knew of the vulnerability but did not assign a CVE or CVSS score.
- Affected versions include those below 0.6.2 and some above that.
- Organizations using Cosmos-based chains should audit their EVM implementations immediately.
In late August 2026, attackers targeted a critical vulnerability in the Cosmos EVM module, draining funds from at least six blockchain networks. The flaw, related to improper balance handling, had been previously identified by Cosmos Labs but was not properly disclosed or patched in time.
This incident highlights the risks of shared infrastructure in decentralized ecosystems and raises concerns over vulnerability coordination and transparency within the blockchain development community. Teams relying on Cosmos-based chains are now urged to verify their EVM module versions and apply necessary updates.
Vulnerability Details
- The flaw affects the Cosmos EVM module used across multiple blockchain networks.
- It allows malicious actors to manipulate account balances and drain funds.
- No CVE, weakness type, or CVSS score was assigned by Cosmos Labs at the time of disclosure.
- Versions prior to 0.6.2 are confirmed vulnerable; some later versions may also be affected.
Impact and Response
- Six blockchains reported fund losses between August 20 and 25, 2026.
- Cosmos Labs acknowledged awareness of the issue before exploitation occurred.
- Developers are advised to upgrade to patched versions and monitor for suspicious activity.
- Security researchers warn this could signal broader risks in cross-chain EVM compatibility layers.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.