Cosmos EVM Vulnerability Exploited Across Six Chains, Moving $5.7 Million
A critical vulnerability in Cosmos EVM was reported through its bug bounty program in April but initially cleared as not affecting production networks. However, attackers exploited this vulnerability across six chains between August 20 and August 25, 2026, moving about $5.7 million through exchanges. The incident highlighted a months-long gap between the initial report and releases reaching affected branches shortly before the first known attack.
Cosmos Labs used its silent patch process to remediate the issue because early testing found production chains were safe. However, this process allowed a patch to be available without operators knowing it addressed an urgent security exposure. As a result, no vulnerability-specific public warning was given before the attacks began.
The underlying defect sat in Cosmos EVM's StateDB, causing an unchecked subtraction that resulted in unauthorized balances. This balance-handling error enabled attackers to transfer funds from accounts that had not authorized those transactions. The exploit mechanism did not depend on an attacker obtaining administrative access, making it particularly concerning.