Six blockchains running the Cosmos EVM module lost funds to attackers between August 20 and August 25. Cosmos Labs confirmed the drain in a post-mortem published August 28, tracing it to a critical flaw in how the shared module handles balances. The advisory, tracked as GHSA-7g4w-cg88-2cq2, carries no CVE identifier or CVSS score, but Cosmos Labs rates it Critical.
The bug affects versions below 0.6.2 and versions from 0.7.0 up to 0.7.2. Fixes shipped in v0.6.2 and v0.7.2 on August 19, and the change is state-breaking, meaning chain operators must coordinate a network upgrade to apply it. Cosmos Labs tells operators who cannot upgrade immediately to halt their chain rather than attempt a rushed governance upgrade.
The company concedes it fumbled the initial assessment. A bug-bounty report filed April 25 was judged at the time to pose no risk to funds on live networks; the team later admitted it could not reproduce the issue on 18-decimal networks and wrongly assumed only non-18-decimal chains were exposed. Whatever the decimal setting, every Cosmos EVM chain turned out to be exposed, a finding the team confirmed by August 13.
The patch was then routed through the same public silent-patch process the company reserves for issues that do not cause fund loss in production. That decision is now under scrutiny, since the company’s own policy calls for private distribution of patches that present an immediate or network-wide risk to user funds. Chain operators should treat this as a prompt to audit their upgrade paths and verify they are running v0.6.2 or v0.7.2 or later.
