Clawback Account Vulnerability Affects Evmos Ethereum Virtual Machine on Cosmos Network
CVE-2024-37158
What is CVE-2024-37158?
Evmos, serving as the Ethereum Virtual Machine hub within the Cosmos Network, has been found to contain a vulnerability that threatens the integrity of clawback vesting accounts. This flaw allows attackers to exploit differences in the ante handler checks for Ethereum and Cosmos transactions. Specifically, by sending an Ethereum transaction targeting a precompile used for interacting with a Cosmos SDK module, an attacker can bypass the necessary checks enforced by the Cosmos ante handler. The issue has been addressed in version 18.0.0, which effectively mitigates this vulnerability and enhances the security of transactions across both networks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
evmos < 18.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
