CVE-2024-37153 is a high-severity vulnerability affecting Evmos, the EVM Hub on the Cosmos Network, specifically impacting liquid staking via Safe contracts. This "infinite money glitch" allows contracts to double the supply of Evmos after each transaction when a local state change and an ICS20 transfer occur within the same function, using the contract's balance as the sender. The vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector and high integrity impact, with no user interaction required. While patched in Evmos versions >=V18.1.0, there is currently no public exploit intelligence, Metasploit modules, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.1.0CPE matchmatch criteria | cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.