Critical Flaw in Cosmos EVM Module Exploited to Drain Funds from Six Blockchains
Cosmos Labs has disclosed that a critical vulnerability in its shared Cosmos EVM module was actively exploited between August 20 and August 25, 2026, resulting in funds being drained from six separate blockchains. The flaw, tracked as GHSA-7g4w-cg88-2cq2, relates to how the module handles balance calculations and was rated Critical, though it was published without a formal CVE identifier, weakness classification, or CVSS score.
What makes this incident particularly concerning is that Cosmos Labs reportedly knew every blockchain running the vulnerable module was exposed before the exploitation occurred. Affected versions include releases below 0.6.2, meaning any project that had not upgraded remained at risk during the exploitation window. While this incident targets blockchain infrastructure rather than typical small business systems, it highlights a recurring theme in cybersecurity: shared software components create shared risk, and delays in patching known flaws can have costly consequences.
For businesses that rely on third-party platforms, software libraries, or blockchain-based services, this case is a reminder to monitor vendor security advisories closely and confirm that critical patches are applied promptly, especially when a vulnerability has already been publicly flagged as high severity.