Infinite Money Glitch in Evmos Allows Double Supply of Evmos After Each Transaction
CVE-2024-37153
7.5HIGH
What is CVE-2024-37153?
Evmos, the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network, is affected by a vulnerability related to the liquid staking process using Safe contracts. This issue arises when a local state change occurs concurrently with an ICS20 transfer, leveraging the contract's balance by using the contract address as the sender parameter. This flaw can potentially create an 'infinite money glitch,' enabling malicious contracts to double the supply of Evmos after each transaction. The problem has been addressed in versions 18.1.0 and above, mitigating the risk of supply manipulation.
Affected Version(s)
evmos <= 18.0.0