CVE-2024-32873: Evmos

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.

Affected products

  • Evmos Evmos: before 18.0.0 (fixed in 18.0.0)

Published 2024-06-06. Last modified 2026-06-17.