Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected

Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected

Posted on August 28, 2026 By CWS

Cosmos Labs has issued a warning regarding a significant vulnerability in the Cosmos EVM module, leading to fund losses across six blockchains between August 20 and August 25, 2026. This flaw, identified as GHSA-7g4w-cg88-2cq2, was exploited shortly after the release of a public patch.

Details of the Cosmos EVM Flaw

The vulnerability, considered critical, affects specific versions of the Cosmos EVM module, prompting an urgent upgrade to versions v0.6.2 or v0.7.2 released on August 19. These updates require coordinated network upgrades due to state-breaking changes. Operators unable to upgrade immediately are advised to halt blockchain operations.

Cosmos Labs revealed in a post-mortem on August 28 that the flaw was initially reported in April through their bug bounty program. It was initially deemed non-threatening to active networks due to testing limitations. However, by August 13, it was clear that all Cosmos EVM chains were vulnerable, regardless of their decimal configuration.

Exploitation and Response

The vulnerability lies in the EVM’s state reconciliation process with the Cosmos SDK x/bank module, allowing attackers to manipulate balances. This flaw permits unauthorized delegation of vesting accounts, causing unchecked balance modifications that lead to fund exploitation.

Despite the availability of a public patch, Cosmos Labs adhered to their silent patch protocol, a decision that deviated from their policy for critical issues. The company typically uses secure channels to distribute fixes for vulnerabilities that threaten user funds, but the silent patch was deemed sufficient since exploitation was not immediately apparent.

Recommendations for Blockchain Operators

Operators using the Cosmos EVM are urged to upgrade to the latest versions to mitigate the risk. Those unable to upgrade should halt operations instead of attempting a governance upgrade. Disabling certain account creation messages and verifying code paths are also recommended steps.

Furthermore, Cosmos Labs advises registering security contacts to ensure timely notifications for future vulnerabilities. The incident highlighted the importance of coordinated responses to critical security threats in the blockchain ecosystem.

Impact and Future Outlook

The exploitation resulted in the sale of approximately USD 2.87 million in assets on decentralized exchanges, with an additional USD 2.85 million on centralized platforms. The Cosmos ecosystem, encompassing over 115 blockchains, faced significant security challenges, urging better coordination in handling vulnerabilities.

This incident underscores the need for robust security measures and transparent communication within the blockchain community. Cosmos Labs’ actions and future updates will be closely monitored by stakeholders to prevent similar occurrences.

The Hacker News Tags:blockchain breach, blockchain security, blockchain upgrade, Cosmos EVM, Cosmos Labs, crypto exploit, Cryptocurrency, EVM module, network upgrade, patch update, security flaw, Vulnerability

Post navigation

Previous Post: Hackers Use Evolving Phishing Code to Evade Detection
Next Post: Berlin Stands Firm Against Hackers in Data Breach Case

Related Posts

VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption The Hacker News
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials The Hacker News
ValleyRAT Malware Concealed in Trusted Adware ValleyRAT Malware Concealed in Trusted Adware The Hacker News
Mustang Panda Exploits Cloud Service in Indian Cyber Attacks Mustang Panda Exploits Cloud Service in Indian Cyber Attacks The Hacker News
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link The Hacker News
New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark