CRITICAL🇵🇱 Wersja polska

CVE-2024-32644

CVSS 9.1v3.1pub. 2024-04-19upd. 2025-03-06

Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ethereum. Prior to 17.0.0, there is a way to mint arbitrary tokens due to the possibility to have two different states not in sync during the execution of a transaction. The exploit is based on the fact that to sync the Cosmos SDK state and the EVM one, we rely on the `stateDB.Commit()` method. When we call this method, we iterate though all the `dirtyStorage` and, **if and only if** it is different than the `originStorage`, we set the new state. Setting the new state means we update the Cosmos SDK KVStore. If a contract storage state that is the same before and after a transaction, but is changed during the transaction and can call an external contract after the change, it can be exploited to make the transaction similar to non-atomic. The vulnerability is **critical** since this could lead to drain of funds through creative SC interactions. The issue has been patched in versions >=V17.0.0.

🤖 AI Analysis
How it works

Cosmos SDK and EVM state synchronization occurs through the `stateDB.Commit()` method, which iterates over `dirtyStorage` and updates the KVStore only when the final state differs from the initial state (`originStorage`). An attacker can prepare a smart contract that changes a value in contract memory during a transaction, then restores it to the initial state before the transaction ends. Since the state before and after the transaction is identical, the `stateDB.Commit()` method does not save changes to the KVStore, but the side effects of the external contract invoked in the meantime remain active. This creates an effect similar to a non-atomic transaction, enabling divergence between the actual EVM state and the recorded Cosmos SDK state.

Impact

An attacker can mint any amount of tokens without backing, leading to complete drainage of funds from the protocol through creative interactions with smart contracts.

Mitigation & patch

Evmos should be updated to version 17.0.0 or later. Patch available in the project repository (commit 08982b5ee726b97bc50eaf58d1914829648b6a5f).

Who is affected

Evmos (Evmos blockchain) in all versions before 17.0.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Evmos

    APP
    Evmos
    < 17.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-39696HIGH8.8same product

Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user...

CVE-2024-37153HIGH7.5same product

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid st...

CVE-2022-35936HIGH8.2same product

Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` ...

CVE-2022-24738HIGH8.1same product

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 att...

CVE-2024-37154MEDIUM5.3same product

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that ...