Wiz Agents & Workflows are here

CVE-2024-37153
vulnerability analysis and mitigation

Overview

A critical vulnerability was discovered in Evmos, the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network, affecting versions up to 18.0.0. The vulnerability, identified as CVE-2024-37153, was discovered while testing liquid staking functionality using Safe contract. The issue manifests when there is a local state change combined with an ICS20 transfer in the same function that uses the contract's balance (Evmos Advisory).

Technical details

The vulnerability occurs specifically when using the contract address as the sender parameter in an ICS20 transfer via the ICS20 precompile. The bug appears only when there is a local state change together with an ICS20 transfer in the same function that uses the contract's balance. This implementation flaw allows contracts to manipulate token balances incorrectly during interchain transactions (Evmos Advisory).

Impact

The vulnerability has been classified as Critical according to the ImmuneFi Severity Classification System. It essentially creates an "infinite money glitch" that enables contracts to double the supply of Evmos tokens after each transaction, leading to direct loss of funds' value through artificial inflation of the token supply (Evmos Advisory).

Mitigation and workarounds

The vulnerability has been patched in Evmos version 18.1.0 and later releases. Users and developers are strongly advised to upgrade to the patched version to prevent potential exploitation (Evmos Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management