Cosmos EVM Vulnerability Exploited for $5.72 Million in Cross-Chain Attacks
A critical vulnerability in Cosmos EVM was exploited across six blockchain networks between Aug. 20 and Aug. 25, resulting in $5.72 million in losses.
The attackers took advantage of an integer underflow flaw in the Ethereum-compatible framework built from the open-source Evmos codebase, which allowed them to drain large accounts and convert stolen tokens into other assets.
Cosmos Labs first received a report on the vulnerability in April but initially concluded that production networks were not at risk. The bug was later confirmed to affect all Cosmos EVM chains, leading to a silent public patch being merged in May without notifying network operators.