Cosmos Labs disclosed in a post-mortem published August 28, 2026 that a critical balance-handling flaw in the shared Cosmos EVM module, used by more than 115 known public blockchains, was exploited on six chains between August 20 and August 25, 2026, draining roughly $5.72 million in assets, according to the company’s writeup and reporting by The Hacker News. The vulnerability allowed an attacker to manipulate token balances through a supply-overflow condition on older chain versions and a type-conversion issue on newer ones, both exploitable within a single transaction carrying a net supply change of zero.
According to The Hacker News, a fix for the flaw was made public in May 2026 but was not distributed as a security release until August 19, and the release notes for the patched versions did not disclose that they contained a security fix. Cosmos Labs has said it does not maintain a complete registry of the networks running its software, meaning some chain operators may not have known a security-relevant update was available. Attackers moved roughly $2.87 million of the stolen funds through decentralized exchanges and an estimated $2.85 million through centralized exchanges, whose accounts have reportedly been frozen pending investigation.
The incident highlights a recurring weakness in open-source infrastructure that underlies widely used platforms: a patch is only protective if downstream operators know it addresses a security issue, and shared modules used across dozens of independently operated networks can leave a long window of exposure when disclosure practices lag behind development timelines. Cosmos Labs has since urged all EVM chains running unpatched versions to halt operations until they upgrade.

Leave a Reply