Cosmos EVM Flaw Fuels $5.7 Million Token Theft
Token thieves exploited a critical flaw in shared Cosmos software across six blockchains between August 20 and 25, netting approximately $5.7 million in stolen assets.
The vulnerability was an integer underflow in the Cosmos EVM framework that allows Cosmos-based blockchains to run Ethereum-compatible applications. The flaw affected versions before v0.6.2 and v0.7.2.
The exploit involved creating an account with locked tokens and delegating more tokens than the account could actually spend, allowing the attackers to manipulate another account and extract its tokens.
No new tokens were minted in the attack, meaning it exploited accounting logic rather than increasing the underlying token supply. The stolen assets were then exchanged for other cryptocurrencies on both decentralized and centralized exchanges.