Cosmos EVM Hack Exposes Flaw in Shared Blockchain Software Module
A vulnerability in the Cosmos EVM software module was exploited on six blockchains between August 20 and 25, resulting in approximately $5.72 million being drained away.
Cosmos Labs has confirmed that the issue was caused by a flaw in the Cosmos EVM code that allowed attackers to manipulate balances on affected chains.
The vulnerability carried the identifier GHSA-7g4w-cg88-2cq2 and was classified as critical. It was fixed in versions 0.6.2 and 0.7.2, which were released on August 19.
Three of the affected chains - MANTRA, KiiChain, and TAC - halted operations to prevent further attacks. The team at Cosmos Labs recommended that validators halt their chains as an emergency measure to protect user balances.