# Cosmos EVM Vulnerability Leads to Blockchain Exploitation

*Published August 31, 2026*
*Source: [https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html](https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html)*

## Executive Summary

A critical vulnerability in the Cosmos EVM module led to the exploitation of six blockchains, allowing attackers to extract funds totaling approximately USD 5.72 million. Despite the vulnerability's risk, Cosmos Labs initially assessed it as non-threatening, delaying a secure patch distribution.

## Article

Cosmos Labs recently identified a critical vulnerability in the Cosmos EVM module that allowed attackers to exploit six blockchains, extracting significant funds between August 20 and August 25, 2026. The flaw, tagged as GHSA-7g4w-cg88-2cq2, was deemed critical but lacked a CVE identifier or a CVSS score. The vulnerability affects versions below 0.6.2 and between 0.7.0 and 0.7.2. Cosmos Labs issued a fix in versions 0.6.2 and 0.7.2 on August 19, urging operators to upgrade immediately, as the change is state-breaking and necessitates a coordinated network upgrade. Operators unable to upgrade promptly were advised to halt operations. Cosmos Labs' post-mortem reveals that the flaw was initially reported on April 25 through a bug bounty program but was incorrectly assessed as non-threatening to live networks. By August 13, it was confirmed that all Cosmos EVM chains were susceptible. The fix was released via a public silent patch process, which typically applies to non-fund-losing issues. However, when a vulnerability endangers user funds, secure channels are generally used to distribute patches privately. The vulnerability resides in the reconciliation code between the Ethereum Virtual Machine state and the Cosmos SDK bank module. This flaw allows attackers to manipulate account balances, leading to supply overflows and unauthorized fund transfers. Chains running the affected versions were exploited, resulting in an approximate loss of USD 5.72 million, with funds sold on both decentralized and centralized exchanges. Cosmos Labs disclosed that 37 vulnerabilities have been quietly patched in the past 13 months without public detailing of exploit paths. The company's decision not to distribute the patch privately after confirming widespread chain vulnerability has raised questions. The situation underscores the importance of timely and secure patch distribution in safeguarding blockchain ecosystems.
