Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026.
The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score.
Affected versions are < 0.6.2 and >= 0.7.0 < 0.7.2, and the fix shipped in v0.6.2 and v0.7.2 on August 19. Chain operators are told to upgrade to one of those releases or later, a change that is state-breaking and requires a coordinated network upgrade.
Operators who cannot upgrade immediately are told to halt the chain rather than attempt a coordinated governance upgrade.
In a post-mortem published August 28, Cosmos Labs said the flaw was reported through its bug bounty program on April 25 and was assessed at the time as posing no risk to funds on live networks.










