Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Cosmos EVM-based blockchains
Incident: Exploitation of a balance-handling flaw in the Cosmos EVM module to drain funds.
Impact: Direct loss of user funds and potential network instability across six affected blockchains.
Attacker: Unidentified threat actors
Analysis: The vulnerability stems from an unchecked subtraction during the reconciliation of EVM state with the Cosmos SDK x/bank module. This allows attackers to trigger an integer overflow, effectively minting new tokens or burning existing holdings. The risk was exacerbated by a delayed response and a silent patch process that failed to alert affected operators in time.
Recommendations: Immediately upgrade to Cosmos EVM v0.6.2 or v0.7.2; Halt chains if a coordinated network upgrade cannot be performed instantly; Audit balance reconciliation logic in custom SDK modules for similar overflow risks
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source