securityonline.info 9/1/2026, 4:21:15 AM · external

Cosmos EVM Overflow Flaw Lets Hackers Drain $2.9M From Six Chains

Cosmos EVM Overflow Flaw Lets Hackers Drain $2.9M From Six Chains
Developing story vulnerability 2 articles tracked
Cosmos EVM balance flaw exploited to drain $2.9M from six chains
CyberSIXT Evidence Panel
Primary Source github.com

THE content discusses a significant cyber incident involving the Cosmos EVM, where an arithmetic overflow vulnerability allowed attackers to exploit several blockchain networks. Between August 20-25, malicious actors exploited a known vulnerability (GHSA-7g4w-cg88-2cq2) to extract around $2.87 million in assets from at least six networks. The core problem stemmed from discrepancies between the Cosmos SDK and the EVM StateDB regarding account balances.

Attackers successfully executed transactions that artificially inflated token balances, enabling them to steal genuine tokens. Despite prior knowledge of the issue, developers delayed patching, leading to the attacks. In response, Cosmos Labs has since begun improving their security protocols and contacting affected networks to implement necessary updates.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline