LIVE · cybersecurity feed
Live wire
cosmoscritical

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A critical vulnerability in the Cosmos EVM module allowed attackers to drain funds from six blockchains between August 20-25, 2026. The flaw, related to balance handling in vesting accounts, was known to Cosmos Labs but initially underestimated. Despite patches being released on August 19, the exploit was successful due to a delayed and improperly handled disclosure and patching process, leading to an estimated loss of nearly $5.7 million.

zeroday.news ·

A significant vulnerability within the Cosmos EVM module was reportedly exploited, leading to the draining of funds from six distinct blockchains. The attacks occurred between August 20 and August 25, 2026, targeting a flaw that Cosmos Labs was aware of prior to the incidents. The issue was specifically linked to the handling of balances within vesting accounts, a critical component for managing token distribution over time in many blockchain projects.

The mechanism of the exploit leveraged a weakness in how the Cosmos EVM module processed or validated balances associated with vesting accounts. Vesting accounts are designed to lock up tokens for a predetermined period, releasing them gradually to the recipient. A flaw in this system could potentially allow an attacker to bypass these restrictions, prematurely access locked funds, or manipulate balance checks to illicitly transfer assets. Such vulnerabilities often arise from improper input validation, logical errors in state transitions, or incorrect implementation of cryptographic primitives within smart contracts or core blockchain modules.

Cosmos Labs was reportedly aware of this critical vulnerability, though its severity was initially underestimated. This suggests that while the flaw was identified through internal audits or external reports, its potential for widespread exploitation and significant financial impact was not fully recognized. The affected product, the Cosmos EVM module, is a crucial component for blockchains within the Cosmos ecosystem that aim to be compatible with the Ethereum Virtual Machine (EVM), allowing them to run Ethereum-based smart contracts and dApps.

Patches for the vulnerability were reportedly released on August 19, 2026, just prior to the observed exploitation period. However, the effectiveness of these patches was undermined by what has been described as a delayed and improperly handled disclosure and patching process. This implies that either the information about the critical nature of the flaw and the urgency of applying the patch did not reach affected blockchain operators in a timely manner, or the instructions for implementation were unclear, leading to insufficient protection.

The scope of the incident extended to six different blockchains that were utilizing the vulnerable Cosmos EVM module. The cumulative financial loss attributed to these exploits is estimated to be nearly $5.7 million. For operators of blockchain networks, typical mitigation strategies for such critical vulnerabilities include immediate application of vendor-supplied patches, thorough security audits of all custom smart contracts and modules, and robust incident response plans to address active exploits.

This incident underscores the inherent challenges in securing complex blockchain ecosystems, particularly those built on modular frameworks like Cosmos. The interplay between core module development, EVM compatibility, and the independent operation of numerous sovereign blockchains creates a difficult environment for coordinated security responses. Effective vulnerability management, including timely and clear communication of critical patches, remains paramount to safeguarding decentralized assets and maintaining trust in the underlying infrastructure.

cosmosevmvulnerabilityexploitblockchain
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malwarehigh

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

A sophisticated cyber campaign dubbed TerminalFix, a variant of ClickFix, is targeting organizations by tricking users into executing malicious PowerShell commands via a fake Cloudflare CAPTCHA. This campaign deploys a multi-stage attack involving DLL sideloading, steganographic payload extraction from images, and extensive Active Directory reconnaissance. The ultimate goal is to establish a persistent reverse tunnel, granting attackers network-level proxy access to internal systems for further exploitation.

breach

McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]

aicritical

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

security

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment