Cosmos EVM Module Exploited, Draining Millions After Vulnerability Disclosure
A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains, occurring after Cosmos Labs was aware of the widespread vulnerability.

A critical vulnerability in the shared Cosmos EVM module has been exploited, leading to the theft of funds from at least six different blockchains. The attacks, which occurred between August 20 and August 25, 2026, targeted a balance-handling flaw that allowed attackers to drain cryptocurrency assets. The vulnerability, identified as GHSA-7g4w-cg88-2cq2, was disclosed by Cosmos Labs, but notably lacked a formal CVE identifier, a weakness classification, or a CVSS score at the time of its public announcement.
Cosmos Labs has indicated that the flaw affects versions of the module prior to 0.6.2, as well as versions 0.6.2 and above, suggesting a broad impact across the ecosystem. The exploit's timing is particularly concerning, as it happened after Cosmos Labs had knowledge of the vulnerability's existence and its potential impact on multiple blockchains. This raises questions about the speed and effectiveness of communication and mitigation efforts following the disclosure.
The exploit specifically targets how the Cosmos EVM module handles balances, a fundamental component for any blockchain operating with Ethereum Virtual Machine compatibility. By manipulating balance checks, attackers were able to illicitly transfer funds out of the affected chains. The exact amount stolen has not been fully disclosed, but reports indicate significant losses across the six compromised blockchains.
This incident highlights a recurring challenge in the rapidly evolving blockchain space: the rapid exploitation of newly disclosed vulnerabilities, especially when they affect widely used shared modules. The Cosmos EVM module is a foundational piece of infrastructure for many blockchains seeking to leverage Ethereum's smart contract capabilities, making its security paramount.
Cosmos Labs has since released patches and urged all affected blockchains to update their modules immediately. However, the fact that the exploit occurred after the vulnerability was known underscores the race against time that often characterizes cybersecurity in the crypto world. Threat actors are frequently adept at reverse-engineering or quickly discovering disclosed vulnerabilities, making rapid patching and incident response critical.
The lack of a formal CVE and CVSS score for this vulnerability is also noteworthy. While not uncommon for certain types of software or in specific disclosure processes, it can sometimes lead to a delayed understanding of the severity and scope of a threat by the broader security community and affected parties.
This event serves as a stark reminder of the interconnectedness and shared risk within the blockchain ecosystem. A single vulnerability in a widely adopted module can have cascading effects, impacting numerous projects and their users. The incident is likely to prompt further scrutiny of security practices and disclosure protocols within the Cosmos network and beyond.