
Cloud Vulnerability DB
A community-led vulnerabilities database
Status: Resolved. A patch is available and all known affected chains have either applied mitigations or upgraded.
| Field | Value |
|---|---|
| Severity | Critical |
| Affected Component | ICS20 Precompile |
| Affected Versions | Cosmos EVM implementations including the ICS20 precompile |
| Patched Version | v0.6.0 |
| First Reported | January 21, 2026 |
| Public Disclosure | March 2026 |
As an immediate mitigation, chains were advised to disable the ICS20 precompile through a coordinated upgrade. Cosmos Labs assisted ecosystem teams in verifying whether their chains were affected and in applying the mitigation where required.
Chains may be affected if they:
We would like to thank the teams and security partners who collaborated with us during the investigation and remediation process, including contributors from:
Following this incident, Cosmos Labs is implementing several improvements to further strengthen the security of the Cosmos EVM stack, including:
Cosmos Labs encourages responsible disclosure of potential vulnerabilities. Security researchers who discover a potential issue are encouraged to report it privately so it can be investigated and addressed responsibly. Reports can be submitted to: security@cosmoslabs.io Information about Cosmos Labs security programs and responsible disclosure practices, including bug bounty opportunities, will be made available through Cosmos Labs security channels, which can be signed up for here.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."