THE content discusses a significant cyber incident involving the Cosmos EVM, where an arithmetic overflow vulnerability allowed attackers to exploit several blockchain networks. Between August 20-25, malicious actors exploited a known vulnerability (GHSA-7g4w-cg88-2cq2) to extract around $2.87 million in assets from at least six networks. The core problem stemmed from discrepancies between the Cosmos SDK and the EVM StateDB regarding account balances.
Attackers successfully executed transactions that artificially inflated token balances, enabling them to steal genuine tokens. Despite prior knowledge of the issue, developers delayed patching, leading to the attacks. In response, Cosmos Labs has since begun improving their security protocols and contacting affected networks to implement necessary updates.