Cosmos EVM Bug Exploited Across Six Chains
A critical Cosmos EVM vulnerability was reported in April through the bug bounty programme but incorrectly deemed not to affect production networks. The flaw, a balance-underflow error, allowed unchecked subtractions in StateDB, enabling attackers to create unauthorised balances and transfer funds without permission.
The exploit mechanism didn't require administrative access, arising solely from the balance-handling error itself. The vulnerability was later exploited across six chains between August 20 and 25, 2026, moving approximately $5.72 million through exchanges: $2.87 million via decentralised exchanges and $2.85 million through centralised venues.
The patch for the issue existed on the main branch since May 15 but wasn't backported to affected release branches until August 19, just hours before the first attack. This narrow window made it difficult for operators to coordinate a state-breaking upgrade across their validator sets.