Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: blockchain (2 articles)Clear

Cosmos EVM flaw exploited across blockchains sharing the same vulnerable code

Cosmos Labs warned that attackers are actively exploiting a flaw in its Cosmos EVM module, the component that gives Cosmos blockchains Ethereum compatibility, and urged affected chains to halt their validators. The bug lies in how the module handles state during nested transactions, letting an attacker manipulate balance and ownership tracking to move funds without authorization. Because many independent chains share the same module code, the weakness is systemic: separate chains were hit in the days before the ecosystem-wide warning, suggesting attackers generalized one exploit across the shared codebase. A patch existed from earlier in the year, but new exploitation shows the risk persists. It echoes supply-chain risk applied to blockchain infrastructure.

Check
Operators of chains built on the Cosmos EVM module should follow Cosmos Labs' guidance, apply the latest patched module, and pause validators if advised until confirmed safe.
Affected
Blockchains built on the vulnerable Cosmos EVM module; incorrect state handling during nested execution lets attackers manipulate balances and ownership to steal funds, and shared code exposes many chains at once.
Fix
Update to the patched Cosmos EVM module, monitor for abnormal precompile calls and unauthorized transfers, coordinate with the ecosystem on halts, and recognize shared blockchain modules concentrate risk across every chain.

Litecoin's privacy layer was attacked using a vulnerability that had been patched in private 37 days earlier - cross-chain swaps lost ~$600,000

Litecoin's privacy add-on, called MWEB, was attacked over the weekend in a way that forced the network to rewind 13 blocks of history (about 32 minutes) to undo invalid transactions. The interesting part for non-crypto people: developers had quietly fixed the bug between March 19 and 26 but never required mining pools to actually deploy the fix. Some pools updated, some didn't. Attackers waited 37 days and exploited the gap between patched and unpatched nodes, draining roughly $600,000 from cross-chain swap protocols including NEAR Intents. The pattern - quiet fix followed by slow rollout - is the same coordination failure that bites every distributed system, not just blockchains.

Check
Audit your patch coordination process: when a critical vulnerability is privately fixed, do you require all affected operators to deploy it or just publish the fix and hope?
Affected
Distributed systems where some nodes can be patched while others continue running vulnerable code without breaking the network - blockchains, federated services, mesh networks, multi-tenant SaaS with on-prem agents. Cross-chain bridges and DEX protocols are exposed when one chain's nodes disagree about transaction validity.
Fix
When shipping a critical patch, treat 'we shipped the fix' and 'all affected operators deployed it' as separate milestones with separate metrics. For products you depend on, watch for vendor advisories that mention private fixes shipped earlier than the public disclosure. Monitor cross-chain exposure if your treasury or DeFi positions touch Litecoin or related protocols. Check that vendors have a process for requiring updates.