Bottom line: Six blockchains have been drained of funds due to a Critical balance-handling flaw in the Cosmos EVM module.
What's happening: Cosmos Labs warned of the vulnerability, which affects blockchains running the shared EVM module, on August 24, 2026, just two days before the exploits began. The flaw, GHSA-7g4w-cg88-2cq2, was rated Critical by Cosmos Labs and published without a CVE ID. The affected blockchains are Cosmos-3, Cosmos-6, Cosmos-7, Cosmos-9, Cosmos-10, and Cosmos-11.
What to do: Security leaders should immediately review and update their Cosmos EVM module configurations to prevent similar exploits. They should also monitor their blockchains for suspicious activity and implement additional security measures to protect against future vulnerabilities.