Cosmos Labs has disclosed details of a critical vulnerability in the shared Cosmos EVM module that was exploited to drain funds from six blockchain networks between August 20 and August 25, 2026. The security issue, tracked as GHSA 7g4w cg88 2cq2, has been rated Critical by Cosmos Labs, although it was published without a CVE identifier, a weakness classification, or a CVSS score. According to the advisory, affected versions include releases earlier than 0.6.2 and versions from 0.7.0 up to but not including 0.7.2. Security fixes were released in versions 0.6.2 and 0.7.2 on August 19, with Cosmos Labs advising all chain operators to upgrade immediately through a coordinated network upgrade because the fix introduces state breaking changes. Operators unable to upgrade immediately have been advised to halt their blockchain rather than attempt a governance based upgrade. In a post mortem published on August 28, Cosmos Labs revealed that the vulnerability had originally been reported through its bug bounty program on April 25. At the time, the issue was assessed as not posing a risk to funds on production networks after the team was unable to reproduce the behavior on 18 decimal networks. The company later confirmed on August 13 that all Cosmos EVM chains were affected regardless of decimal configuration, but the patch continued through its silent patch process because the code had already been publicly available without any known exploitation.
Cosmos Labs acknowledged that its handling of the issue differed from the process described in its own published silent patch policy. The policy states that vulnerabilities presenting an immediate or network wide risk should receive emergency mitigation measures, private patch distribution, or coordinated upgrades before public disclosure. However, because the patch had already appeared on the public repository without evidence of exploitation, the company determined it was acceptable to proceed with its existing silent patch process. The vulnerability exists in the code responsible for reconciling Ethereum Virtual Machine state with the Cosmos SDK x bank module. According to the technical explanation, the flaw affects how balances are handled for vesting accounts that contain both spendable and locked funds. Under certain conditions, an unchecked subtraction causes the account balance to wrap to an extremely large value. During reconciliation, this behavior can lead to the creation of excessive balances or the removal of legitimate funds from other accounts. On version 0.6.x, the resulting overflow can halt blockchain operations, while version 0.7.x directly modifies balances in the x bank module and accepts values that remain valid after integer conversion. Exploitation requires blockchain networks to permit permissionless creation of vesting accounts, allowing attackers to deploy contracts that trigger the vulnerable balance handling logic within a single transaction while maintaining a zero net supply change.
Alongside the advisory, Cosmos Labs recommended several mitigation measures for blockchain operators. The company advised upgrading to version 0.6.2 or 0.7.2 or later through a coordinated network upgrade because configuration changes alone cannot address the vulnerability. Operators unable to deploy the update immediately have been instructed to stop block production until the upgrade can be completed. Additional recommendations include rejecting requests that create new vesting accounts through the ante handler, verifying patched code paths on blockchain forks to ensure duplicate helper functions have not left vulnerable code active, applying supplementary balance related fixes that are not explicitly listed in the advisory, and registering security contacts with Cosmos Labs after the company discovered that eleven Cosmos EVM deployments were not connected to its security notification channels. The advisory also references multiple upstream code changes, including the SubBalance underflow protection introduced through pull request 1176, a separate locked balance reconstruction update added through pull request 1187, and an additional commit that prevents module account balances from being modified. Contributors from ZetaChain reported that simply applying one patch could leave duplicated helper functions unprotected in downstream forks, while Warden Protocol chose to disable permissionless vesting account creation entirely because no application on its network depended on the feature.
The disclosure also provides a detailed timeline of the incident. A public pull request in Push Chain fork of Cosmos EVM described the vulnerability and exploitation method on August 20, approximately eight hours after the patched releases became available. The first reported attack against MANTRA began less than twelve hours later. Cosmos Labs sent its first private security notification to affected operators on August 21 after learning that MANTRA had already experienced exploitation. According to the company, six blockchain networks were ultimately affected, with attackers selling approximately 2.87 million United States dollars worth of affected assets on decentralized exchanges based on August 19 prices. An additional 2.85 million United States dollars in assets were reportedly sold through centralized exchanges using estimates derived from publicly available trading volume data. Cosmos Labs noted that the figures were supplied by the affected blockchain networks and have not been independently audited. The company also highlighted that the Cosmos ecosystem consists of more than 115 known public blockchains and acknowledged that it does not maintain a complete registry of networks using its software. This limited visibility made it more challenging to notify every downstream operator during the incident. The release notes for versions 0.6.2 and 0.7.2 identify the updates as containing important security fixes requiring immediate installation, although the security backport itself was not listed in their published changelogs.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





