Return to Threats

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

thehackernews.com 2026-08-29 AI supply chain High

What Happened

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are =

Why It Matters

Reportedly, Cosmos Labs disclosed that a critical balance-handling flaw in a shared Cosmos EVM module (GHSA-7g4w-cg88-2cq2) was exploited to drain funds from six blockchains between August 20 and August 25, 2026, and that the issue lacked a formal CVE, weakness classification, or CVSS score at publication time. The flaw affected all chains using that shared module, illustrating how a single upstream component vulnerability can propagate across multiple dependent systems. From RealGround’s perspective, this incident underscores AI-adjacent and broader software supply chain risk: when shared modules or libraries are reused across chains or AI-related infrastructure without complete vulnerability metadata and coordinated disclosure, downstream operators may underestimate or miss critical issues. Organizations integrating blockchain or similar shared components into AI agents or platforms should maintain detailed SBOMs, enforce dependency governance, and closely monitor upstream advisories to mitigate cascading exploitation.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html

Talk to AI CISO