en

Cosmos EVM chains told to halt after security incident

image
rubric logo Security
like 1

Cosmos Labs urged affected Cosmos EVM chains to request validator halts on Aug. 25 as its security and engineering teams responded to an incident that had already reached multiple networks.

The company did not identify the underlying vulnerability, affected chains or total losses in its initial statement. It said users of the Cosmos EVM module had been affected and promised an incident report after the situation was resolved.

Separate disclosures from MANTRA, TAC and KiiChain connect recent attacks to the Cosmos EVM software stack. However, Cosmos Labs has not publicly confirmed that these incidents share one exact vulnerability or named every chain asked to stop.

Cosmos EVM chains receive emergency halt advice

Cosmos EVM is a shared software stack that lets Cosmos SDK chains execute Ethereum-compatible smart contracts. A vulnerability in a common module can therefore expose independent networks running affected versions or configurations.

An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…

— Cosmos Labs (@cosmoslabs_io) August 24, 2026

Cosmos Labs said its teams were “proactively responding” and had contacted chains using the module. It asked those teams to coordinate with validators, which must collectively stop block production on decentralized proof-of-stake networks.

A halt prevents new transactions from settling while developers investigate and distribute a fix. It also temporarily blocks regular transfers, applications and withdrawals that depend on the affected chain.

Cosmos Labs directed other Cosmos EVM teams with questions to its security email. It did not publish a software version, mitigation instructions or a restart schedule, likely to avoid revealing exploitable details before chains are protected.

KiiChain and TAC disclose token drains

KiiChain said an attacker drained 148,326,583.15 KII from wallets on Aug. 22. Its incident report said the attacker repeated the technique 18 times before validators stopped the network at block 9,355,723.

The team linked the attack to a Cosmos EVM vulnerability involving vesting accounts, staking operations and balance handling. KiiChain said the attacker bridged part of the assets to BNB Smart Chain through Hyperlane. The team did not identify Hyperlane itself as the vulnerable component.

TAC separately said an attacker exploited a weakness in the Cosmos EVM precompile layer on Aug. 22 and drained one account. Validators halted TAC at block 24,671, according to its official update.

The projects’ disclosures establish that both networks suffered unauthorized asset movements. Cosmos Labs has not yet published an aggregate loss calculation or confirmed whether the same attacker controlled every address involved.

MANTRA restarted after a 30-hour halt

MANTRA stopped its network on Aug. 20 after detecting activity involving two project-managed wallets. The team isolated the incident to its Cosmos EVM module and deployed an updated release before coordinating a validator restart.

As previously reported, MANTRA resumed block production after a roughly 30-hour halt. It restarted from a snapshot at block 17,449,398 without rolling back the chain’s recorded state.

MANTRA said “no user funds were affected,” but its complete post-mortem and detailed asset accounting remain unpublished.

The team said balances were unchanged and the two affected addresses belonged to its internal wallet infrastructure. That statement does not establish whether project-controlled assets moved or quantify any attempted withdrawals.

The incidents follow an earlier Cosmos EVM flaw involving the ICS20 precompile. A March security advisory said incorrect state handling during nested execution allowed the same token balance to be used repeatedly within one transaction.

That earlier issue caused an estimated $7 million loss on SagaEVM in January. In related coverage, SagaEVM was paused after bridged assets were compromised. It remains unconfirmed whether the August attacks used that exact flaw, a related execution path or a separate vulnerability.

Cosmos Labs post-mortem will determine the scope

The immediate priorities are identifying every vulnerable deployment, distributing a tested patch and confirming that affected chains can restart safely. Validators will need coordinated upgrade instructions before resuming block production.

Cosmos Labs’ promised report should identify the faulty component, affected versions, exploitation timeline and total losses. It should also explain whether MANTRA, TAC and KiiChain were compromised through the same code path.

Until that report appears, other teams using Cosmos EVM may keep networks halted or disable affected functionality. Users should rely on official chain status pages and avoid transactions through unverified interfaces or purported recovery tools.