A Critical Flaw in Cosmos EVM Exposes Millions of Users to Potential Attacks
Cosmos Labs, a prominent blockchain development company, has revealed that it was aware of a critical vulnerability in its Ethereum Virtual Machine (EVM) implementation over a year ago. Despite this knowledge, the company failed to act promptly, leaving millions of users exposed to potential attacks. The flaw, which can be exploited for cross-domain privilege escalation, has already been used by attackers to compromise various blockchain systems.
The EVM is a software layer that enables smart contracts on top of the Cosmos blockchain. It’s designed to provide a seamless experience for developers and users by mimicking the Ethereum Virtual Machine environment. However, in this case, the Cosmos Labs team discovered a vulnerability that could allow attackers to jump from one domain to another, essentially creating a backdoor into the system.
According to sources, Cosmos Labs was aware of the flaw as early as July 2025 but chose not to disclose it publicly until August 2026. During this time, millions of users remained vulnerable to potential attacks. The company’s decision to keep quiet about the issue has raised concerns among experts and security professionals, who argue that transparency is crucial in maintaining trust within the blockchain ecosystem.
The exploit works by manipulating the EVM’s ability to handle cross-domain transactions. Essentially, an attacker can create a malicious smart contract that takes advantage of the vulnerability to escalate privileges from one domain to another. This allows them to gain unauthorized access to sensitive information and potentially execute malicious code on behalf of other users.
While Cosmos Labs has finally acknowledged the issue and promised to provide patches for affected systems, the incident highlights the importance of transparency in cybersecurity. Companies must prioritize disclosure over profit or reputation when it comes to vulnerabilities that could put their users at risk. In this case, the silence surrounding the EVM flaw not only compromised user security but also eroded trust within the Cosmos community.
In light of this incident, users and developers are advised to exercise caution when interacting with blockchain systems that utilize the Cosmos EVM implementation. It’s essential to stay informed about potential vulnerabilities and keep software up-to-date to minimize the risk of attacks. Moreover, companies must prioritize transparency in their cybersecurity practices to maintain trust within their user base.
Source: The Hacker News — 2026-08-28