Threat Intelligence

Critical Flaw in Cosmos EVM Module Exploited to Drain Funds from Six Blockchains

The Hacker News · 29 Aug 2026
Key Takeaway If you use software with shared or third-party components, track vendor security disclosures and apply critical patches immediately rather than waiting for confirmation of active exploitation.

Cosmos Labs has disclosed that a critical vulnerability in its shared Cosmos EVM module was actively exploited between August 20 and August 25, 2026, resulting in funds being drained from six separate blockchains. The flaw, tracked as GHSA-7g4w-cg88-2cq2, relates to how the module handles balance calculations and was rated Critical, though it was published without a formal CVE identifier, weakness classification, or CVSS score.

What makes this incident particularly concerning is that Cosmos Labs reportedly knew every blockchain running the vulnerable module was exposed before the exploitation occurred. Affected versions include releases below 0.6.2, meaning any project that had not upgraded remained at risk during the exploitation window. While this incident targets blockchain infrastructure rather than typical small business systems, it highlights a recurring theme in cybersecurity: shared software components create shared risk, and delays in patching known flaws can have costly consequences.

For businesses that rely on third-party platforms, software libraries, or blockchain-based services, this case is a reminder to monitor vendor security advisories closely and confirm that critical patches are applied promptly, especially when a vulnerability has already been publicly flagged as high severity.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.